Man, your distrust seems toxic to me. The simplest explanation is they goofed as they admitted, if they were malicious, they'd upload those file names from their server straight to FB's, not through your god damned browser.
And of course they only addressed it after they "got caught", they didn't know about their fuck up before that, if you want to sneer at them, sneer at them for not being careful enough to let this happen, not what you wrote.
I'm not trying to defend them, more like I want to protest against ungrounded casual insulting bashes like yours that seems way too freaking common nowadays. I do think they care about customer privacy, because it affects their income. (Admiteddly they were too casual about it, they were still partnering with Facebook...).
The smug tone in this joke of a response to the issue proves this.