← Case Files · The Breach Files
Cambridge Analytica, 2018: the breach that was not a breach
- People affected
- Up to 87 million Facebook users
- When it happened
- 2013 – 2015, disclosed publicly in March 2018
- Made public
- 17 March 2018
- How they got in
- Legitimate use of Facebook's Graph API by a third-party app, then onward transfer of the data in breach of platform terms
- Attributed to
- Aleksandr Kogan's app, data subsequently transferred to SCL Elections and Cambridge Analytica
- What it cost
- $5 billion FTC penalty against Facebook, a $100 million SEC settlement, a £500,000 ICO fine, and the closure of Cambridge Analytica
What was exposed: Profile data · Page likes · Locations · Friend lists · Some private messages for a small subset
Nothing was hacked. No password was stolen, no server was compromised, no vulnerability was exploited. Data on up to 87 million people moved from a social network to a political consultancy through a documented feature, used as documented, by an app that had been approved. This is a case file about a platform working correctly and that being the problem.
What happened
In 2013, Aleksandr Kogan, a researcher at Cambridge University, built a Facebook app called thisisyourdigitallife — a personality quiz. Around 270,000 people installed it and consented to it collecting their data for research purposes.
Facebook's Graph API at the time permitted an app to request information about the installing user's friends as well: profile details, page likes, locations. So each of those 270,000 installations delivered a slice of that person's entire social graph. The friends had not installed anything, had not consented to anything, and had no mechanism to discover that it had happened.
The total reached, by Facebook's own later estimate, up to 87 million people, the majority in the United States.
The data was then transferred to SCL Elections and its affiliate Cambridge Analytica, which used it to build voter profiles marketed as psychographic — modelling personality traits in order to target political messaging. That transfer breached Facebook's platform policies. Facebook learned of it in 2015, demanded certification that the data had been deleted, received assurances, and did not verify them or tell the affected users.
Consent that scales past the person giving it. The 270,000 installers consented. The 87 million did not, and could not have, because consent in a social graph is not an individual act — accepting a friend request in 2011 turned out to be the operative decision. Every platform that lets one user share data about another inherits this structure: address book uploads, photo tagging, contact syncing, shared genetic relatives. It is the same shape every time, and it is why the case still gets cited in privacy law arguments that have nothing to do with Facebook.
Why it took five years to surface
The collection happened in 2013 and 2014. Facebook restricted friend data access in 2014 and removed it in 2015. Reporting in late 2015 described the arrangement and drew limited attention.
What changed in March 2018 was a person. Christopher Wylie, who had worked at SCL, went on the record with documents. The story landed in The Observer, The Guardian and The New York Times simultaneously, and this time it went everywhere.
The distance between the events and the reckoning is not incidental. Data misuse of this kind leaves no alarm to trigger. There is no intrusion detection system for a permitted API call, no anomaly in the logs, no forensic artefact. It surfaces when a person decides to talk, which is a discovery mechanism no organisation can plan around and no regulator can rely on.
The timeline
- 2013 – 2014 — thisisyourdigitallife collects data from around 270,000 installers and their friends.
- 2014 – 2015 — Facebook restricts and then removes friend data access for new apps.
- December 2015 — Initial reporting describes the transfer to Cambridge Analytica; Facebook seeks deletion certifications.
- 17 March 2018 — Coordinated reporting based on Christopher Wylie's account breaks internationally.
- March 2018 — Facebook's share price falls sharply; #DeleteFacebook trends; the UK ICO raids Cambridge Analytica's offices.
- April 2018 — Mark Zuckerberg testifies before the US Congress over two days.
- May 2018 — Cambridge Analytica and SCL Elections enter insolvency. GDPR takes effect three weeks later.
- October 2018 — The ICO fines Facebook £500,000, the maximum under the earlier regime.
- July 2019 — The FTC imposes a $5 billion penalty; the SEC settles for $100 million.
What it changed
Platform APIs were rebuilt around data minimisation. Facebook, and every comparable platform, cut the data available to third-party apps, introduced app review, added expiring permissions and built user-facing dashboards showing which apps hold what. The era in which an app could ask for the social graph and receive it ended here.
Privacy regulation acquired political urgency. GDPR was already law when the story broke, but the scandal gave it a public narrative at the exact moment it came into force. California's Consumer Privacy Act passed in June 2018, three months later. Legislators who had found data protection abstract suddenly had a case involving elections.
"We asked them to delete it and they said they had" stopped being an answer. Facebook's reliance on certification without verification became a textbook example of inadequate third-party oversight, and contractual assurance without audit is now treated sceptically by regulators as a matter of course.
It permanently blurred the meaning of "data breach" in public use. Security professionals still object that this was not one. The public settled the question the other way, and the practical effect is that organisations are now judged on where data ends up rather than on whether a control failed — which is, on balance, the more useful standard for the people in the data.
What to take from it
- Audit which apps have access to your accounts. Every major platform now exposes this list. Most people find services they used once, years ago, still connected.
- Assume anything a friend can see about you can leave with them. Their app permissions, their screenshots, their account compromise. Privacy settings govern visibility, not what happens afterwards.
- Quizzes and personality tests remain a collection method, not a pastime. The format survived the scandal because it works, and the permissions it requests are the entire product.
- Page likes are more revealing than you would guess. The research underpinning this case showed that a modest set of likes predicts attributes people consider private. The data does not need to be sensitive to produce a sensitive inference.
Questions people ask
Was Cambridge Analytica a data breach?
Facebook argued strenuously that it was not, and on a narrow technical reading it was right: no system was compromised and no access control failed. The data was collected through an API doing precisely what it was built to do. The term still stuck, because from the perspective of the 87 million people involved, information about them ended up somewhere they had never agreed to and could not have prevented. That gap between what is technically a breach and what is experienced as one is the whole reason this case matters.
How did 270,000 quiz takers become 87 million people?
Facebook's Graph API in that era let an app request not only the installing user's data but data about their friends. So one person taking a personality quiz handed over their own profile and a slice of everyone they were connected to. The friends were never asked, never notified, and had no way to find out. Facebook restricted this in 2014 and removed it in 2015, but apps that had already collected data kept what they had.
Did Cambridge Analytica actually swing an election?
This is genuinely disputed and worth stating as such. The company marketed psychographic targeting as decisively effective; academic researchers have been consistently sceptical that the technique performs meaningfully better than conventional demographic targeting. What is not disputed is that the data was obtained, transferred and used. Whether it worked is a separate question from whether it was permissible.
What happened to the companies involved?
Cambridge Analytica and SCL Elections entered insolvency proceedings in May 2018. Facebook paid a $5 billion penalty to the FTC in 2019 — the largest privacy penalty in US history at that point — settled with the SEC for $100 million over its disclosures to investors, and was fined £500,000 by the UK ICO, the maximum available under the pre-GDPR regime that applied to the conduct.
Sources
- Federal Trade Commission — FTC imposes $5 billion penalty on Facebook, July 2019
- Information Commissioner's Office — Investigation into the use of data analytics in political campaigns, final report to Parliament, November 2018
- UK Digital, Culture, Media and Sport Committee — Disinformation and fake news, final report, February 2019
- Securities and Exchange Commission settlement with Facebook Inc., July 2019 — $100 million over risk disclosures
Read next
Case files are written from the public record: regulatory findings, court filings, company disclosures and contemporaneous reporting, cited above. Figures are the ones the organisation or its regulator finally settled on, which is often not the number first reported — where that differs, the page says so. Disputed accounts are marked as disputed rather than resolved in either direction.