Secure Aggregation in Federated Learning is not Private: Leaking User Data at Large Scale through Model Modification