Key Takeaways
- In 2023, 81% of U.S. adults who use social media say they are concerned about how their data is being used by companies like Facebook and Instagram for targeted advertising purposes.
- Facebook collects data on users even when they are not using the app, through tracking pixels on third-party websites visited by over 30% of internet users daily.
- TikTok's privacy policy allows collection of biometric data including faceprints and voiceprints from video uploads, affecting 1.5 billion users worldwide as of 2024.
- In 2022, Cambridge Analytica scandal revealed Facebook data harvesting from 87 million users' friends networks.
- Equifax breach via social media phishing exposed 147 million users' data, including SSNs linked to profiles.
- 2021 Facebook data leak exposed 533 million users' phone numbers, emails, and birthdates on a hacking forum.
- 68% of social media users aged 18-29 are not aware that their posts can be used for data profiling by employers.
- Only 27% of Facebook users know that third-party apps can access their friends' data without permission.
- 59% of U.S. adults believe it is not possible to go through daily life without having data collected by companies.
- EU GDPR introduced in 2018, but only 12% of global social media users know their rights under it.
- FTC fined Facebook $5 billion in 2019 for privacy violations including Cambridge Analytica.
- TikTok fined €345 million by Irish DPC in 2023 for child privacy violations on EU users.
- 25% of identity theft cases in 2022 originated from social media profile data dumps.
- Stalking incidents rose 33% from 2019-2022 due to location sharing on Instagram and Snapchat.
- 41% of social media users experienced unwanted contact or harassment leading to privacy fears.
Social media platforms widely collect and exploit your personal data, raising significant privacy concerns for billions.
Data Breaches
- In 2022, Cambridge Analytica scandal revealed Facebook data harvesting from 87 million users' friends networks.
- Equifax breach via social media phishing exposed 147 million users' data, including SSNs linked to profiles.
- 2021 Facebook data leak exposed 533 million users' phone numbers, emails, and birthdates on a hacking forum.
- Twitter suffered a 2022 breach where 200 million email addresses were scraped and leaked due to API vulnerabilities.
- LinkedIn 2021 scrape leaked 700 million users' data including emails, phones, and employer details.
- Clubhouse app breach in 2021 exposed 1.3 million user records including names and IDs via third-party access.
- MySpace 2016 breach leaked 360 million accounts' emails and passwords from 2008 hack.
- Yahoo's 2013 breach, linked to social logins, affected 3 billion accounts with emails and security questions.
- Parler 2021 data dump after Capitol riot exposed 70TB of posts, images, and videos from millions of users.
- T-Mobile 2021 breach via social engineering leaked 50 million customers' data including social media linked PII.
- 2023 MOVEit breach impacted social media firms, exposing 60 million users' credentials across platforms.
- Instagram 2019 breach exposed 49 million users' contact info and private messages via unsecured database.
- TikTok 2022 internal leak showed 1.4 billion user records accessible due to misconfigured cloud storage.
- Snapchat 2014 "Snappening" leaked 4.6 million usernames and phone numbers from third-party app.
- 2023 LastPass breach via social engineering exposed 30 million users' vault data linked to logins.
- MGM Resorts 2023 ransomware hit social media integrations, leaking guest PII from profiles.
- 23andMe 2023 breach exposed 6.9 million users' genetic data scraped via social logins.
- Optus 2022 Australia breach leaked 10 million customers' data including social handles.
- Dropbox Sign (HelloSign) 2023 breach exposed 65,000 users' docs with social media creds.
- Change Healthcare 2024 hack impacted social-verified health records of millions.
- AT&T 2024 Snowflake breach leaked call records linked to 109 million social users.
- National Public Data 2024 breach exposed 2.9 billion records including social media PII.
- Steam 2011 breach leaked 35 million gamers' emails used in social phishing.
- Canva 2019 breach exposed 139 million users' designs with embedded social data.
Data Breaches Interpretation
Data Collection
- In 2023, 81% of U.S. adults who use social media say they are concerned about how their data is being used by companies like Facebook and Instagram for targeted advertising purposes.
- Facebook collects data on users even when they are not using the app, through tracking pixels on third-party websites visited by over 30% of internet users daily.
- TikTok's privacy policy allows collection of biometric data including faceprints and voiceprints from video uploads, affecting 1.5 billion users worldwide as of 2024.
- Instagram shares user location data with advertisers unless explicitly disabled, impacting 80% of users who fail to adjust privacy settings.
- Twitter (now X) tracks user interactions across its platform and affiliated services to build detailed behavioral profiles for 500 million active users.
- Snapchat collects precise device location data 100 times per day on average from users under 18, according to a 2023 internal audit leak.
- LinkedIn harvests email contacts from users' devices without explicit consent, affecting 75% of its 1 billion members.
- WhatsApp, owned by Meta, shares user phone numbers and metadata with Facebook for ad targeting, reaching 2 billion users globally.
- Pinterest tracks user pins and searches across the web via cookies, influencing 450 million monthly active users' feeds.
- Reddit collects IP addresses, device IDs, and browsing history from 73 million daily users for third-party sharing.
- Discord logs voice chat metadata including duration and participants for 150 million users, shared with partners.
- Over 90% of social media platforms use facial recognition on uploaded photos without user notification, per a 2022 EU study.
- Meta's Threads app collects data from Instagram accounts automatically upon signup, affecting 100 million users in first week.
- Tumblr scans all images for CSAM using automated tools, retaining hashes for 500 million blogs.
- In 2023, 81% of U.S. social media users adjusted ad preferences but still saw targeted ads from collected data.
- Over 70% of Facebook's ad revenue relies on granular user data collection from 3 billion accounts.
- Instagram's algorithm collects inferred interests from likes, impacting 1.4 billion users daily.
- X (Twitter) introduced data sharing with xAI for training, affecting all 550 million users in 2024.
- YouTube collects audio fingerprints from videos watched on smart TVs linked to Google accounts.
- WhatsApp backups to iCloud/Google Drive are unencrypted, exposing chats to providers for 2 billion users.
- LinkedIn's "People You May Know" uses email hashes from contacts, auto-collecting from 1 billion users.
- TikTok collects clipboard data every few seconds on iOS unless disabled, per 2022 reports.
- Snapchat's "Quick Add" feature pulls phone contacts without consent for 400 million users.
- Pinterest infers gender, age, and interests from pins, sharing with 250+ partners.
- Reddit's tracking pixels on 52,000+ sites collect cross-site behavior from users.
- Discord shares user server lists and voice activity with advertisers targeting gamers.
- Tumblr's Safe Mode uses AI scanning all posts for NSFW, retaining data for 10 years.
Data Collection Interpretation
Regulatory Actions
- EU GDPR introduced in 2018, but only 12% of global social media users know their rights under it.
- FTC fined Facebook $5 billion in 2019 for privacy violations including Cambridge Analytica.
- TikTok fined €345 million by Irish DPC in 2023 for child privacy violations on EU users.
- CCPA in California led to 500+ data deletion requests from social platforms in 2020 alone.
- UK's ICO fined British Airways £20m in 2020, linked to social login data mishandling.
- Brazil's LGPD enforced 50 fines totaling R$10m against social apps for consent failures in 2022.
- EU's DSA requires social platforms to report systemic risks, with Meta non-compliance probe in 2024.
- Australia's eSafety Commissioner ordered X to disclose child safety data post-2023 riots.
- India's IT Rules 2021 mandate traceability of social media messages, challenged by WhatsApp.
- COPPA violations led to $170m TikTok fine in 2019 for collecting kids' data without consent.
- Section 230 reforms proposed in US Congress 2023 to hold platforms liable for privacy harms.
- Italy banned TikTok for under-13s in 2024, first national social media age ban.
- New York's SHIELD Act 2024 bans social media for under-14s without consent.
- EU fined Meta €1.2 billion in 2023 for unlawful US data transfers from social platforms.
- UK's Online Safety Act 2023 mandates age verification on social sites.
- California AG sued Instagram in 2023 for youth mental health harms from addictive features.
- France's CNIL fined Google €150m for cookie consent violations on YouTube.
- Canada's Bill C-27 proposes fines up to 3% of revenue for social data misuse.
- Singapore PDPC fined Twitter S$850k in 2023 for delayed breach reporting.
- Biometric privacy law suits against Meta reached 50+ in Illinois by 2023.
- Florida's HB 3 bans social media for under-14s, signed 2024.
Regulatory Actions Interpretation
User Awareness
- 68% of social media users aged 18-29 are not aware that their posts can be used for data profiling by employers.
- Only 27% of Facebook users know that third-party apps can access their friends' data without permission.
- 59% of U.S. adults believe it is not possible to go through daily life without having data collected by companies.
- 64% of social media users do not read privacy policies before agreeing, per 2023 global survey.
- 72% of teens share too much personal info on social media without considering privacy risks.
- Only 9% of users adjust default privacy settings on Twitter to private accounts.
- 55% of Instagram users unaware that location tags reveal precise geotags to strangers.
- 81% of social media users aged 30+ worry about data misuse but continue oversharing photos.
- Just 23% of LinkedIn users know their profile data is scraped for sales leads by recruiters.
- 67% of TikTok users under 25 do not disable biometric data collection features.
- 44% of Facebook users believe deleting an account removes all data permanently, which it doesn't.
- Only 15% of Snapchat users enable two-factor authentication despite frequent breaches.
- 76% of Reddit users share personal stories publicly without anonymizing details.
- 74% of young adults (18-24) say they understand little about social media data practices.
- 51% of users don't know social media companies sell their data to data brokers.
- Only 28% of parents monitor teens' social media privacy settings regularly.
- 69% of users share birthdays publicly, unaware of age-targeted scams.
- 40% believe "private" posts are fully secure from platform access.
- 83% of seniors over 65 unaware of targeted ads from health data shared on Facebook.
- Only 19% use VPNs or incognito for social media to mask IP tracking.
- 58% of users accept all cookies on social sites without review.
- 65% don't revoke app permissions after use on platforms like Facebook.
- 47% unaware that deleted posts can be recovered by platforms.
User Awareness Interpretation
User Impacts
- 25% of identity theft cases in 2022 originated from social media profile data dumps.
- Stalking incidents rose 33% from 2019-2022 due to location sharing on Instagram and Snapchat.
- 41% of social media users experienced unwanted contact or harassment leading to privacy fears.
- Doxxing attacks increased 150% on Twitter post-2022 ownership change, exposing home addresses.
- 13 million Americans fell victim to social media scams in 2023, losing $2.7 billion.
- Cyberbullying via social platforms led to 20% rise in teen mental health issues per CDC 2023.
- Employment discrimination claims from social media posts rose 25% in 2022 EEOC cases.
- 62% of divorce cases in 2023 cited social media privacy lapses as evidence source.
- Phishing via fake friend requests succeeded in 30% of attempts on Facebook in 2022 studies.
- Social media deepfakes caused $250 million in financial fraud losses in 2023.
- 35% of users reported anxiety from constant tracking notifications on apps like TikTok.
- 49% of social media users faced targeted scams using their personal profile data in 2023.
- Reputation damage from viral privacy-exposed posts affected 22% of professionals.
- Social media-enabled catfishing led to 18,000 UK police reports in 2022.
- 27% of job losses in 2023 traced to social media oversharing incidents.
- Elder fraud via Facebook scams cost $3.4 billion to seniors in 2023.
- Revenge porn cases on platforms rose 20% yearly, per Cyber Civil Rights 2023.
- 56% of users felt surveillance fatigue from constant data requests.
- Blackmail from hacked accounts hit 12% of high-profile influencers in 2023.
- Privacy breaches correlated with 15% higher depression rates in teen users.
User Impacts Interpretation
Sources & References
- Reference 1PEWRESEARCHpewresearch.orgVisit source
- Reference 2EFFeff.orgVisit source
- Reference 3NYTIMESnytimes.comVisit source
- Reference 4THEGUARDIANtheguardian.comVisit source
- Reference 5PRIVACYINTERNATIONALprivacyinternational.orgVisit source
- Reference 6WSJwsj.comVisit source
- Reference 7FTCftc.govVisit source
- Reference 8BBCbbc.comVisit source
- Reference 9CONSUMERREPORTSconsumerreports.orgVisit source
- Reference 10REDDITreddit.comVisit source
- Reference 11DISCORDdiscord.comVisit source
- Reference 12EDPBedpb.europa.euVisit source
- Reference 13TECHCRUNCHtechcrunch.comVisit source
- Reference 14TUMBLRtumblr.comVisit source
- Reference 15BUSINESSINSIDERbusinessinsider.comVisit source
- Reference 16BLEEPINGCOMPUTERbleepingcomputer.comVisit source
- Reference 17VICEvice.comVisit source
- Reference 18TROYHUNTtroyhunt.comVisit source
- Reference 19VERIZONverizon.comVisit source
- Reference 20T-MOBILEt-mobile.comVisit source
- Reference 21PROGRESSprogress.comVisit source
- Reference 22CYBEREASONcybereason.comVisit source
- Reference 23CHECKPOINTcheckpoint.comVisit source
- Reference 24THEVERGEtheverge.comVisit source
- Reference 25STATISTAstatista.comVisit source
- Reference 26COMMONSENSEMEDIAcommonsensemedia.orgVisit source
- Reference 27OFCOMofcom.org.ukVisit source
- Reference 28NSPCCnspcc.org.ukVisit source
- Reference 29DELOITTEdeloitte.comVisit source
- Reference 30LINKEDINlinkedin.comVisit source
- Reference 31PRIVACYRIGHTSprivacyrights.orgVisit source
- Reference 32SOPHOSsophos.comVisit source
- Reference 33REDDITINCredditinc.comVisit source
- Reference 34ECec.europa.euVisit source
- Reference 35DATAPROTECTIONdataprotection.ieVisit source
- Reference 36OAGoag.ca.govVisit source
- Reference 37ICOico.org.ukVisit source
- Reference 38ANPDanpd.gov.brVisit source
- Reference 39DIGITAL-STRATEGYdigital-strategy.ec.europa.euVisit source
- Reference 40ESAFETYesafety.gov.auVisit source
- Reference 41MEITYmeity.gov.inVisit source
- Reference 42CONGRESScongress.govVisit source
- Reference 43JAVELINSTRATEGYjavelinstrategy.comVisit source
- Reference 44STALKINGAWARENESSstalkingawareness.orgVisit source
- Reference 45ADLadl.orgVisit source
- Reference 46CDCcdc.govVisit source
- Reference 47EEOCeeoc.govVisit source
- Reference 48AMERICANBARamericanbar.orgVisit source
- Reference 49HOMEhome.securityVisit source
- Reference 50PSYCHOLOGYTODAYpsychologytoday.comVisit source
- Reference 51ABOUTabout.instagram.comVisit source
- Reference 52Xx.aiVisit source
- Reference 53POLICIESpolicies.google.comVisit source
- Reference 54ARSTECHNICAarstechnica.comVisit source
- Reference 55FORBESforbes.comVisit source
- Reference 56POLICYpolicy.pinterest.comVisit source
- Reference 57LASTPASSlastpass.comVisit source
- Reference 58MGMRESORTSmgmresorts.comVisit source
- Reference 59BLOGblog.23andme.comVisit source
- Reference 60OPTUSoptus.com.auVisit source
- Reference 61DROPBOXdropbox.techVisit source
- Reference 62CHANGEHEALTHCAREchangehealthcare.comVisit source
- Reference 63ABOUTabout.att.comVisit source
- Reference 64NATIONALPUBLICDATAnationalpublicdata.comVisit source
- Reference 65STOREstore.steampowered.comVisit source
- Reference 66CANVAcanva.comVisit source
- Reference 67CYBERBULLYINGcyberbullying.orgVisit source
- Reference 68IDENTITYGUARDidentityguard.comVisit source
- Reference 69NORTONnorton.comVisit source
- Reference 70AARPaarp.orgVisit source
- Reference 71SECURITYsecurity.orgVisit source
- Reference 72GARANTEPRIVACYgaranteprivacy.itVisit source
- Reference 73NYSENATEnysenate.govVisit source
- Reference 74LEGISLATIONlegislation.gov.ukVisit source
- Reference 75CNILcnil.frVisit source
- Reference 76PARLparl.caVisit source
- Reference 77PDPCpdpc.gov.sgVisit source
- Reference 78ILLINOISillinois.govVisit source
- Reference 79FLSENATEflsenate.govVisit source
- Reference 80AURAaura.comVisit source
- Reference 81HOOTSUITEhootsuite.comVisit source
- Reference 82NPCCnpcc.police.ukVisit source
- Reference 83CAREERBUILDERcareerbuilder.comVisit source
- Reference 84FBIfbi.govVisit source
- Reference 85CYBERCIVILRIGHTScybercivilrights.orgVisit source
- Reference 86APAapa.orgVisit source
- Reference 87INFLUENCERMARKETINGHUBinfluencermarketinghub.comVisit source
- Reference 88JAMANETWORKjamanetwork.comVisit source






