The Deactivated Friend Attack: How Your "Gone" Friends Might Be Cloaking Spies
Your Facebook deactivated friend or a cloaked spy
This paper identifies a zero-day privacy vulnerability in Facebook termed the "Deactivated Friend Attack." By exploiting the temporary nature of account deactivation, an attacker can remain invisible ("cloaked") on a victim's friend list to avoid detection while periodically "uncloaking" to harvest private data.
TL;DR
Researchers have uncovered a "zero-day" privacy loophole on Facebook that allows attackers to remain on a victim's friend list indefinitely without being seen. By abusing the deactivation feature, an attacker can "cloak" themselves, becoming invisible and un-unfriendable, only to "uncloak" briefly to steal private updates. In an extensive field test, the researchers maintained access to over 4,300 profiles for nearly nine months with a 0% detection rate.
Background: The Illusion of Social Privacy
In the traditional social graph, the relationship between friends is mutual and visible. If you no longer trust someone, you unfriend them. This paper shatters that assumption by introducing the Deactivated Friend Attack. It positions this vulnerability as a "Cloaked Channel"—a concept borrowed from science fiction (specifically Star Trek) where an enemy ship becomes invisible to scanners but can still observe and eventually strike.
The Problem: The One-Way Mirror of Deactivation
Most social networks view account deactivation as a "pause" button for the user. However, the authors point out a critical oversight:
- Invisibility: While deactivated, your name disappears from your friends' lists.
- Invulnerability: Because you aren't on the list, the victim cannot click "Unfriend" or move you to a "Restricted" list.
- Persistent Access: The friendship bond remains in the database. When the attacker reactivates, they instantly regain access to all "Friends-only" data.
The "Why" is simple: Facebook's design prioritizes a seamless return for users who leave the platform, but it ignores the security implications of "ghost" friends who can return at will to harvest data.
Methodology: The Art of Cloaking
The researchers modeled the attack probability using several behavioral factors ( to ), such as the likelihood of a victim checking their friend list vs. the timing of the attacker's "uncloaking."

The Attack Cycle:
- Infiltration: Send a targeted friend request (often using social engineering or a "legend" profile).
- Cloaking: Immediately deactivate upon acceptance.
- Surveillance: Periodically reactivate for short bursts (e.g., 10 minutes) during the victim's "silent hours" (late night) to crawl their profile.
- Re-cloaking: Deactivate again before the victim logs in.
Experimental Evidence: 4,300+ Victims, 0 Detection
To prove the viability, the authors ran a three-phase experiment over 606 days.

Phase 1: Gaining Trust
By using targeted requests, they achieved a 62% acceptance rate. This is significantly higher than random bot attacks (which usually hover around 35%), proving that "targeted" social engineering is highly effective.
Phase 2: The Cloak
For 261 days, the researchers cycled between deactivation and brief reactivation. Despite having thousands of "friends," not a single user unfriended them during this phase. The invisibility was 100% effective.
Phase 3: The Reality Check
When the account was finally left "uncloaked" (permanently active) for 60 days, only 5.5% of users eventually removed the account. This suggests that even when visible, users are slow to prune their friend lists, making the "cloaked" invisibility even more powerful for long-term spying.
Critical Insight & Solutions
The core of this problem is the State of Non-Existence. When a friend deactivates, they shouldn't just vanish; they should remain visible in a "Deactivated" state so the user can still manage the relationship.
The Authors' Proposed Fixes:
- Notifications: Notify users when a friend reactivates an account.
- Visible Deactivation: Show deactivated friends as "blurred" entries in the list, allowing them to be unfriended.
- Rate Limiting: Flag accounts that toggle activation status frequently (a clear sign of automated crawling).
Conclusion
This paper serves as a stark reminder that features designed for "user convenience" (like easy deactivation) often create massive security debt. The "Deactivated Friend Attack" is a silent, persistent backdoor that turns a momentary lapse in judgment—accepting one wrong friend request—into a lifetime of surveillance. As social networks evolve, they must recognize that a user's right to manage their social circle must extend even to those who have temporarily "gone dark."
