Since March, when news broke that the political consulting firm Cambridge Analytica used a Facebook app to amass data on as many as 87 million people without their consent, the social network operator has been forced to repeatedly answer for how it has given away user data and who it has given that data to.
Facebook also rushed to defend itself, saying that in 2014, it changed an element of its API to prevent apps from collecting data on their users' friends, as the Cambridge Analytica app did, according to the Wired.
Facebook has since clarified that while it announced this change in 2014, apps that already had access to people's friends' data continued to have access until May 2015.
The company also acknowledged that some apps had this access for up to six months longer, to allow them to "come into compliance" with the new rules. There were dozens of companies on the list, one of which may raise more than a few eyebrows in Washington: the Russian internet giant Mail.ru.
According to Facebook, Mail.ru was given a two-week extension to wind down a feature on two messaging apps that enabled users to see their Facebook friend lists and message with people who also had the Mail.ru apps. During the extension, at least, the app only had access to people's friend lists, not any information about those friends' likes or interests. And yet, long before that extension was in place, Facebook says Mail.ru ran hundreds of apps on the platform, all of which operated under Facebook's old rules, which did allow app developers to collect their users' friends' data. Some of those apps began operating as early as 2009.
"Some apps were built prior to the platform change in 2015, so they did have access to the earlier version of our platform," a Facebook spokesperson said. "That made it possible for users to consent to sharing information about themselves, as well as their friends."
Facebook says the majority of Mail.ru's apps were test apps that remained private and that only a handful actually launched publicly. It did not share details on how many users may have had their information exposed to Mail.ru apps without their consent.
Facebook is now investigating Mail.ru, along with all other apps that had access to large quantities of user data prior to the changes. But, the spokesperson says the investigation is not itself a condemnation. "We found no indication of misuse with Mail.ru.
Recent concern over Russia's manipulation of social networks in the run-up to the 2016 election may cast the relationship between the two companies in a new light.
The fact that Facebook would have brokered an extension with Mail.ru may not come as a surprise to people who are familiar with Facebook CEO Mark Zuckerberg's relationship with Yuri Milner. The Russian billionaire and Mail.ru founder was also a major investor in Facebook.
Over the last year, reports have also surfaced about Milner's ties to the Kremlin. In November 2017, following the so-called Paradise Papers leak of 13.4 million confidential documents related to offshore payments, The New York Times reported that Milner had received hundreds of millions of dollars in Russian state funding, which he used in part to invest in both Facebook and Twitter through his international investment firm, DST Global.
While nothing in the reports suggested that the investments were part of Russian influence operations, the news broke after the U.S. launched federal investigations into Russian interference in the election. Milner defended his reputation in an open letter last fall, saying the suggestion that he tried to infiltrate American tech companies to help Russia was "far-fetched" and a "fairy tale."
Democratic senator Mark Warner, who has been investigating Russia's manipulation of social media platforms as vice chairman of the Senate Intelligence Committee, said in a statement, "We need to determine what user information was shared with Mail.ru and what may have been done with the captured data.” Warner expressed particular concern that current Mail.ru executives including Ali Usmanov "boast close ties to Vladimir Putin."
At the very least, the fact that Facebook is only now coming forward with this bit of information, nearly a year after investigations into Russian actors' manipulation of Facebook began, indicates a glaring lack of transparency on Facebook's part. Throughout its thousands of responses to the House committee, Facebook was asked repeatedly about what access Russian state agencies had to Facebook user data. Facebook responded saying that it received 34 requests for data from the Russian government between 2013 and 2017 and didn't provide data in response to any of them. But experts say the Mail.ru deal, viewed alongside the news that Facebook gave data to device manufacturers including Chinese companies like Huawei, reflects naïveté on Facebook's part about the power that international regimes have over businesses within their borders.
"If you are a Russian businessperson of a certain scale, you can’t escape the requirements Russian intelligence services are going to put on you," says Brett Bruen, a U.S. diplomat who served as director of global engagement under President Obama and now runs the consulting firm Global Situation Room. "This is the reality of doing business in Russia today."