Earlier quoted context omitted.
Apparently Facebook is claiming that the functionality came from a separate "import contacts" feature that used to exist. But I agree; the idea that the import logic could have slipped into the login process accidentally is ludicrous. Or at least it indicates an outrageous lack of care on Facebook's part.
It requires just one developer and a couple of reviewers to make poor choices. Which begs the question, how do you structure your organisation such that a foolish developer that only barely understands the change that they are making can't write code that makes arbitrary queries to particular data sets in unapproved contexts?
To access the user's data, your developers should have to intentionally crack the user's password. And if they attempt to do that they should be fired.
Obviously this is not how Facebook works, but ideally it's how the thing that replaces Facebook will work.