This data breach is different in nature. It is not same as Ashley Madison or Experian where someone got hold of root pwd or some other data storage (some form of hacking involved). This is about third party using Facebook's API to access user data and exploiting those API to retrieve hoards of information about a particular user. IN this case, Facebook most likely knew which third party developer was heavily hitting a certain API in a certain pattern but they decided to turn a blind eye.

