Facebook says 50M user accounts affected by security breach

Facebook reported a major security breach in which 50 million user accounts were accessed by unknown attackers.

Posted: Sep 28, 2018 3:38 PM

NEW YORK (AP) — Facebook reported a major security breach in which 50 million user accounts were accessed by unknown attackers.

The stolen data allowed the attackers to "seize control" of those user accounts, Facebook said. Facebook has logged out the 50 million breached users — plus another 40 million who were vulnerable to the attack. Users don't need to change their Facebook passwords, it said.

Facebook says it doesn't know who is behind the attacks or where they're based. In a call with reporters on Friday, CEO Mark Zuckerberg said that the company doesn't know yet if any of the accounts that were hacked were misused.

The hack is the latest setback for Facebook during a tumultuous year of security problems and privacy issues . So far, though, none have significantly shaken the confidence of the company's 2 billion global users.

This latest hack involved a bug in Facebook's "View As" feature, the company said in a blog post . That feature lets people see how their profiles appear to others. The attackers used that vulnerability to steal "access tokens," which are digital keys that Facebook uses to keep people logged in. Possession of those tokens would allow attackers to control those accounts.

Specifically, from the "View As" feature, a bug somehow allowed a video uploader to appear for sending "happy birthday" messages, said Guy Rosen, Facebook's vice president of product management. Another bug then created an access token that made Facebook think the hacker had legitimately signed in with the account being viewed.

"We haven't yet been able to determine if there was specific targeting" of particular accounts, Rosen said in a call with reporters. "It does seem broad. And we don't yet know who was behind these attacks and where they might be based."

Facebook says it has alerted law enforcement.

Jake Williams, a security expert at Rendition Infosec, said the stolen access tokens would have likely allowed attackers to view private posts and probably to post status updates or shared posts as the compromised user, but not passwords.

"The bigger concern (and something we don't know yet) is whether third party applications were impacted," Williams said in a text exchange. He noted that the company's "Facebook Login" feature lets users log into other apps and websites with their Facebook credentials. "These access tokens that were stolen show when a user is logged into Facebook and that may be enough to access a user's account on a third party site," he said.

News broke early this year that a data analytics firm once employed by the Trump campaign, Cambridge Analytica, had improperly gained access to personal data from millions of user profiles. Then a congressional investigation found that agents from Russia and other countries have been posting fake political ads since at least 2016. Facebook CEO Mark Zuckerberg appeared at a Congressional hearing over Facebook's privacy policies in April.

The Facebook bug is reminiscent of a much larger attack on Yahoo in 2013 in which attackers compromised 3 billion accounts — enough for half of the world's entire population. In the case of Yahoo, information stolen included names, email addresses, phone numbers, birthdates and security questions and answers.

Ed Mierzwinski, the senior director of consumer advocacy group U.S. PIRG, said the breach was "very troubling."

"It's yet another warning that Congress must not enact any national data security or data breach legislation that weakens current state privacy laws, pre-empts the rights of states to pass new laws that protect their consumers better, or denies their attorneys general rights to investigate violations of or enforce those laws," he said in a statement.

Wedbush analyst Michael Pachter said "the most important point is that we found out from them," meaning Facebook, as opposed to a third party.

"As a user, I want Facebook to proactively protect my data and let me know when it's compromised," he said. "Shareholders should ultimately approve of Facebook's handling of the issue."

West Lafayette
Cloudy
48° wxIcon
Hi: 59° Lo: 35°
Feels Like: 42°
Kokomo
Cloudy
45° wxIcon
Hi: 56° Lo: 34°
Feels Like: 40°
Rensselaer
Cloudy
° wxIcon
Hi: 56° Lo: 33°
Feels Like: °
Fowler
Cloudy
48° wxIcon
Hi: 57° Lo: 33°
Feels Like: 42°
Williamsport
Cloudy
45° wxIcon
Hi: 58° Lo: 34°
Feels Like: 38°
Crawfordsville
Cloudy
45° wxIcon
Hi: 58° Lo: 33°
Feels Like: 37°
Frankfort
Cloudy
45° wxIcon
Hi: 56° Lo: 33°
Feels Like: 37°
Delphi
Cloudy
43° wxIcon
Hi: 58° Lo: 33°
Feels Like: 38°
Monticello
Cloudy
43° wxIcon
Hi: 60° Lo: 35°
Feels Like: 38°
Logansport
Cloudy
43° wxIcon
Hi: 56° Lo: 33°
Feels Like: 39°
Spotty Showers/Storms to Frost & Some Fog
WLFI Radar
WLFI Temps
WLFI Planner

Indiana Coronavirus Cases

Data is updated nightly.

Cases: 727764

Reported Deaths: 13397
CountyCasesDeaths
Marion995211738
Lake53461965
Allen40457675
St. Joseph35506550
Hamilton35489408
Elkhart28433441
Tippecanoe22359218
Vanderburgh22284396
Porter18668307
Johnson17905377
Hendricks17180315
Clark12930191
Madison12592339
Vigo12431246
Monroe11858170
LaPorte11821210
Delaware10648185
Howard9865216
Kosciusko9378117
Hancock8251140
Bartholomew8052155
Warrick7771155
Floyd7649177
Grant7027174
Wayne7026199
Boone6679101
Morgan6555139
Dubois6150117
Marshall6005111
Dearborn579277
Cass5788105
Henry5688103
Noble558883
Jackson500872
Shelby490296
Lawrence4505120
Harrison434772
Gibson434692
Clinton427053
DeKalb426484
Montgomery423588
Whitley394739
Huntington389080
Steuben383857
Miami380666
Knox371890
Jasper363847
Putnam358860
Wabash353379
Adams340654
Ripley339170
Jefferson328881
White313254
Daviess295899
Wells291081
Decatur284292
Fayette279262
Greene277385
Posey271033
Scott265453
LaGrange265370
Clay259146
Washington240032
Randolph239781
Spencer232031
Jennings229549
Starke215453
Fountain212046
Sullivan211142
Owen198156
Fulton194740
Jay192530
Carroll188320
Orange182654
Perry182637
Rush172925
Vermillion168543
Franklin167735
Tipton162445
Parke145916
Blackford134632
Pike133234
Pulaski116445
Newton107234
Brown101641
Crawford99314
Benton98414
Martin88315
Warren81715
Switzerland7848
Union70810
Ohio56411
Unassigned0414

COVID-19 Important links and resources

As the spread of COVID-19, or as it's more commonly known as the coronavirus continues, this page will serve as your one-stop for the resources you need to stay informed and to keep you and your family safe. CLICK HERE

Closings related to the prevention of the COVID-19 can be found on our Closings page.

Community Events