Facebook believes the data of up to 87 million people was improperly shared with the political consultancy Cambridge Analytica -- far more than previously disclosed and interestingly, 1.1 million of them are based out of the United Kingdom.
Analytica said it received only info about 30 million users and not 87 as claimed by Facebook.
The overall figure had been previously quoted as being 50 million by the whistleblower Christopher Wylie, BBC reported on Wednesday. Facebook chief Mark Zuckerberg said, "clearly we should have done more, and we will going forward".
During a press conference he said that he had previously assumed that if Facebook gave people tools, it was largely their responsibility to decide how to use them. But he added that it was "wrong in retrospect" to have had such a limited view.
"Today, given what we know... I think we understand that we need to take a broader view of our responsibility," he said. "That we're not just building tools, but that we need to take full responsibility for the outcomes of how people use those tools as well."
Zuckerberg also announced an internal audit had uncovered a fresh problem. Malicious actors had been abusing a feature that let users search for one another by typing in email addresses or phone numbers into Facebook's search box.
As a result, many people's public profile information had been "scraped" and matched to the contact details, which had been obtained from elsewhere.
Facebook has blocked now blocked the facility. "It is reasonable to expect that if you had that (default) setting turned on, that in the last several years someone has probably accessed your public information in this way," Zuckerberg said.
The estimates of how many people's data had been exposed were revealed in a blog by the tech firm's chief technology officer, Mike Schroepfer.
BBC has also learned that Facebook now estimates that about 305,000 people had installed the This Is Your Digital Life quiz that had made the data-harvesting possible. The previously suggested figure had been 270,000.
About 97 per cent of the installations occurred within the US. However, just over 16 million of the total number of users affected are thought to be from other countries.
A spokeswoman for the UK's Information Commissioner's Office told the BBC that it was continuing to assess and consider the evidence before deciding what steps to take.
Facebook has faced intense criticism after it emerged that it had known for years that Cambridge Analytica had collected data from millions of its users, but had relied on the London-based firm to self-certify that it had deleted the information.
Cambridge Analytica said it had bought the information from the creator of the This Is Your Digital Life app without knowing that it had been obtained improperly.
During Zuckerberg's press conference, Cambridge Analytica tweeted it had only obtained data for 30 million individuals -- not 87 million -- from the app's creator, and again insisted it had deleted all records.