Can we not let this become framed as a "breach"? No systems were compromised. Nothing of Facebook's was accessed that wasn't supposed to be accessed. This was data intentionally exposed by Facebook , just exfiltrated and given to an entity whom Facebook hadn't authorized. This is simply the extent to which we've permitted these Internet giants to collect information about us. It's business as usual. Edit: To clarify,…
Was this a security breach in the sense that the company with the data got “hacked”? No. Was this a breach in trust to Facebook users? I think undoubtedly yes. And was there a breach of a the Terms of Service by companies taking all this data and using it for non-academic purposes? Yes there was. So the type of breach seems to be a worthwhile distinction to make.
What's interesting about this is the fact that the same data is shared with many third-parties, with proper "consent", and users not understanding what's really happening. Calling this a "breach" has the slight unintended side-effect in the public by promoting the idea that this company received a different dataset than other partners, which is not the case.