Hackers appear to have compromised and published private messages from at least 81,000 Facebook users' accounts.
The perpetrators told the BBC Russian Service that they had details from a total of 120 million accounts, which they were attempting to sell, although there are reasons to be sceptical about that figure.
Facebook said its security had not been compromised.
And the data had probably been obtained through malicious browser extensions.
Facebook added it had taken steps to prevent further accounts being affected.
The BBC understands many of the users whose details have been compromised are based in Ukraine and Russia. However, some are from the UK, US, Brazil and elsewhere.
The hackers offered to sell access for 10 cents (8p) per account. However, their advert has since been taken offline.
"We have contacted browser-makers to ensure that known malicious extensions are no longer available to download in their stores," said Facebook executive Guy Rosen.
"We have also contacted law enforcement and have worked with local authorities to remove the website that displayed information from Facebook accounts."
The breach first came to light in September, when a post from a user nicknamed FBSaler appeared on an English-language internet forum.
"We sell personal information of Facebook users. Our database includes 120 million accounts," the user wrote.
- Facebook fined £500,000 for Cambridge Analytica scandal
- Facebook hack victims will not get ID theft protection
- Is Facebook's News Feed fading?
The cyber-security company Digital Shadows examined the claim on behalf of the BBC and confirmed that more than 81,000 of the profiles posted online as a sample contained private messages.
Data from a further 176,000 accounts was also made available, although some of the information – including email addresses and phone numbers – could have been scraped from members who had not hidden it.
The BBC Russian Service contacted five Russian Facebook users whose private messages had been uploaded and confirmed the posts were theirs.
One example included photographs of a recent holiday, another was a chat about a recent Depeche Mode concert, and a third included complaints about a son-in-law.
Image captionSamples of the data were posted online to attract interest
There was also an intimate correspondence between two lovers.
One of the websites where the data had been published appeared to have been set up in St Petersburg.
Its IP address has also been flagged by the Cybercrime Tracker service. It says the address had been used to spread the LokiBot Trojan, which allows attackers to gain access to user passwords.
Who should be blamed?
Personal shopping assistants, bookmarking applications and even mini-puzzle games are all on offer from various browsers such as Chrome, Opera and Firefox as third-party extensions.
The little icons sit alongside your URL address bar patiently waiting for you to click on them.
According to Facebook, it was one such extension that quietly monitored victims' activity on the platform and sent personal details and private conversations back to the hackers.
Facebook has not named the extensions it believes were involved but says the leak was not its fault.
Independent cyber-experts have told the BBC that if rogue extensions were indeed the cause, the browsers' developers might share some responsibility for failing to vet the programs, assuming they were distributed via their marketplaces.
But the hack is still bad news for Facebook.
The embattled network has had a terrible year for data security and questions will be asked about whether it is proactive enough in responding to situations like this that affect large numbers of people.
The BBC Russian Service emailed the address listed alongside the hacked details, posing as a buyer interested in buying two million accounts' details.
The advertiser was asked whether the breached accounts were the same as those involved in either the Cambridge Analytica scandal or the subsequent security breach revealed in September.
Image captionThe BBC contacted five people who confirmed the private messages were theirs
A reply in English came from someone calling themself John Smith.
He said that the information had nothing to do with either data leak.
He claimed that his hacking group could offer data from 120 million users, of whom 2.7 million were Russians.
But Digital Shadows told the BBC that this claim was doubtful because it was unlikely Facebook would have missed such a large breach.
John Smith did not explain why he had not advertised his services more widely.
And when asked whether the leaks were linked to the Russian state or to the Internet Research Agency – a group of hackers linked to the Kremlin – he replied: "No."
- Kohwe was not my brother – George Laing clarifies
- Takoradi woman was never pregnant, 3 others arrested for alleged conspiracy – Police
- Final year student of Tweneboa Kodua SHS jumps to his death
- Mahama’s brother exploiting government’s fertiliser scheme when he doesn’t qualify – Agric Minister
- ‘Vaccines as a tool for immigration control is retrogressive’ – Akufo-Addo
- There are still more women in Ghana than men – 2021 PHC by GSS
- 2 arrested for WASSCE fraud
- Angry Takoradi residents reject police’s fake pregnancy claim
- Police arrest 3, declare Takoradi woman as a suspect in self-kidnapping probe
- Why shouldn’t I be interested in running for president? – Afriyie Akoto
Cocoa Farmers in Western North Region decry unfair implementation of cocoa rehabilitation programme
Tano River clearing up following efforts to halt illegal mining activities – Lands Ministry
Foundervine launches Ghana Science and Technology Challenge prize competition
Woman allegedly clubs husband to death
Ghana is recording more prostate diseases; screening crucial – Urological Association
Ghana gets third Public Health Emergency Operations Center
How to detect cables that can burn your house – Ghana Standards Authority
Angry Takoradi residents reject police’s fake pregnancy claim
PDA Ghana to establish oil processing mill at Kunsu for jobs and value-addition
South African Airlines resume flights to Accra, others from today
Policy rate to remain at 13.5% but high-lending problem to persist – IEA
Kunsu Film Village to revive, preserve Ghanaian culture and heritage
Why shouldn’t I be interested in running for president? – Afriyie Akoto
Covid-19: We’re hoping to vaccinate 20 million Ghanaians by end of 2021 – Akufo-Addo
We expect food prices to stabilise by January 2022 – Agric Minister