-
Advertisement
Facebook
WorldUnited States & Canada

Facebook’s worst ever security breach exposed 50 million accounts to hackers

Latest hack involved bugs in Facebook’s ‘View As’ feature which lets people see how their profiles appear to others

Reading Time:3 minutes
Why you can trust SCMP
File photo of Facebook CEO Mark Zuckerberg. Photo: AP
Associated Press

Facebook has reported a major security breach in which 50 million user accounts – including company CEO Mark Zuckerberg – were accessed by unknown attackers.

The culprits could “seize control” of the accounts, the company said, by stealing digital keys the company uses to keep users logged in. They did so by exploiting three bugs in Facebook’s code.

The company said it fixed the bugs and logged out the 50 million breached users – plus another 40 million who were vulnerable to the attack – to reset the digital keys. Users do not need to change their Facebook passwords, it insisted.

Facebook said it does not know who was behind the attacks or where they’re based. In a call with reporters on Friday, Zuckerberg said the attackers could have seen private messages or posted on someone’s account, but there were no signs they did.

Advertisement

“We do not yet know if any of the accounts were actually misused,” he said.

The hack is the latest setback for Facebook during a tumultuous year of security problems and privacy issues.

Advertisement

This latest hack involved bugs in Facebook’s “View As” feature, which lets people see how their profiles appear to others. The attackers used that vulnerability to steal the digital keys, known as “access tokens”, from the accounts of people whose profiles were searched for using the “View As” feature. The attack then moved along from one user’s Facebook friend to another. Possession of those tokens would allow attackers to control those accounts.

A hacker – or hackers, as Facebook does not know the number – exploited several software bugs at once to obtain login access to as many as 50 million accounts. Photo: Reuters
A hacker – or hackers, as Facebook does not know the number – exploited several software bugs at once to obtain login access to as many as 50 million accounts. Photo: Reuters
Advertisement
Select Voice
Choose your listening speed
Get through articles 2x faster
1.25x
250 WPM
Slow
Average
Fast
1.25x