Facebook says 50M user accounts affected by security breach

<p>Facebook says it recently discovered a security breach affecting nearly 50 million user accounts.</p>

News 12 Staff

Sep 28, 2018, 4:59 PM

Updated 2,128 days ago

Share:

By MATT O'BRIEN AND MAE ANDERSON
AP Technology Writers
NEW YORK (AP) - Facebook reported a major security breach in which 50 million user accounts were accessed by unknown attackers.
The stolen data allowed the attackers to "seize control" of those user accounts, Facebook said. Facebook has logged out the 50 million breached users - plus another 40 million who were vulnerable to the attack. Users don't need to change their Facebook passwords, it said.
Facebook says it doesn't know who is behind the attacks or where they're based. In a call with reporters on Friday, CEO Mark Zuckerberg said that the company doesn't know yet if any of the accounts that were hacked were misused.
The hack is the latest setback for Facebook during a tumultuous year of security problems and privacy issues . So far, though, none have significantly shaken the confidence of the company's 2 billion global users.
This latest hack involved a bug in Facebook's "View As" feature, the company said in a blog post . That feature lets people see how their profiles appear to others. The attackers used that vulnerability to steal "access tokens," which are digital keys that Facebook uses to keep people logged in. Possession of those tokens would allow attackers to control those accounts.
Specifically, from the "View As" feature, a bug somehow allowed a video uploader to appear for sending "happy birthday" messages, said Guy Rosen, Facebook's vice president of product management. Another bug then created an access token that made Facebook think the hacker had legitimately signed in with the account being viewed.
"We haven't yet been able to determine if there was specific targeting" of particular accounts, Rosen said in a call with reporters. "It does seem broad. And we don't yet know who was behind these attacks and where they might be based."
Facebook says it has alerted law enforcement.
Jake Williams, a security expert at Rendition Infosec, said the stolen access tokens would have likely allowed attackers to view private posts and probably to post status updates or shared posts as the compromised user, but not passwords.
"The bigger concern (and something we don't know yet) is whether third party applications were impacted," Williams said in a text exchange. He noted that the company's "Facebook Login" feature lets users log into other apps and websites with their Facebook credentials. "These access tokens that were stolen show when a user is logged into Facebook and that may be enough to access a user's account on a third party site," he said.
News broke early this year that a data analytics firm once employed by the Trump campaign, Cambridge Analytica, had improperly gained access to personal data from millions of user profiles. Then a congressional investigation found that agents from Russia and other countries have been posting fake political ads since at least 2016. Facebook CEO Mark Zuckerberg appeared at a Congressional hearing over Facebook's privacy policies in April.
The Facebook bug is reminiscent of a much larger attack on Yahoo in 2013 in which attackers compromised 3 billion accounts - enough for half of the world's entire population. In the case of Yahoo, information stolen included names, email addresses, phone numbers, birthdates and security questions and answers.
Ed Mierzwinski, the senior director of consumer advocacy group U.S. PIRG, said the breach was "very troubling."
"It's yet another warning that Congress must not enact any national data security or data breach legislation that weakens current state privacy laws, pre-empts the rights of states to pass new laws that protect their consumers better, or denies their attorneys general rights to investigate violations of or enforce those laws," he said in a statement.
Wedbush analyst Michael Pachter said "the most important point is that we found out from them," meaning Facebook, as opposed to a third party.
"As a user, I want Facebook to proactively protect my data and let me know when it's compromised," he said. "Shareholders should ultimately approve of Facebook's handling of the issue."
___
An earlier version of this article incorrectly stated the day of Mark Zuckerberg's call with reporters.
___
O'Brien reported from Providence, Rhode Island. Frank Bajak in Boston contributed to this report.
Copyright 2018 The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.


More from News 12
2:16
Fire at Fair Lawn strip mall destroys multiple businesses, including popular Zadies Bakery

Fire at Fair Lawn strip mall destroys multiple businesses, including popular Zadies Bakery

2:42
Beautiful weekend ahead for New Jersey with sunny skies and warm temperatures

Beautiful weekend ahead for New Jersey with sunny skies and warm temperatures

1:54
Boar’s Head deli meat recalled for potential listeria contamination

Boar’s Head deli meat recalled for potential listeria contamination

0:46
New Jersey to receive more than $72M to help coastal communities prevent flooding

New Jersey to receive more than $72M to help coastal communities prevent flooding

1:43
Officials: Lead found on Keyport beach not ‘urgent risk’ to public health, no need to close beach

Officials: Lead found on Keyport beach not ‘urgent risk’ to public health, no need to close beach

0:44
Jersey Proud: Goya Gives Day collects 100,000 pounds of food donations

Jersey Proud: Goya Gives Day collects 100,000 pounds of food donations

1:01
‘It’s a beautiful sport.’ New pickleball courts open in Howell Township

‘It’s a beautiful sport.’ New pickleball courts open in Howell Township

0:29
Man who pleaded guilty to attacking Jewish men sentenced to 30 years on terror charges

Man who pleaded guilty to attacking Jewish men sentenced to 30 years on terror charges

0:55
EPA completes Phase 1 of Superfund site cleanup at Unimatic Manufacturing site in Fairfield

EPA completes Phase 1 of Superfund site cleanup at Unimatic Manufacturing site in Fairfield

0:20
West New York school named for Sen. Menendez to revert to original name

West New York school named for Sen. Menendez to revert to original name

0:30
Attorney general: NJ state trooper ‘inexcusably crossed the line,’ admits to punching handcuffed woman in the face in 2022

Attorney general: NJ state trooper ‘inexcusably crossed the line,’ admits to punching handcuffed woman in the face in 2022

0:15
East Brunswick police: Bicyclist killed in Route 18 crash

East Brunswick police: Bicyclist killed in Route 18 crash

0:30
No one injured in Kenilworth house fire

No one injured in Kenilworth house fire

1:04
Attorney general releases body camera footage of fatal Hamilton police-involved shooting

Attorney general releases body camera footage of fatal Hamilton police-involved shooting

0:15
Part of Manchester’s Harry Wright Lake closed due to high levels of fecal bacteria

Part of Manchester’s Harry Wright Lake closed due to high levels of fecal bacteria

0:23
2 dead in Maine plane crash after leaving New Jersey airport

2 dead in Maine plane crash after leaving New Jersey airport

0:18
$1 million lottery ticket won from $20 scratch-off at North Wildwood Wawa

$1 million lottery ticket won from $20 scratch-off at North Wildwood Wawa

1:59
Paws & Pals: Felicity now up for adoption at Associated Humane Societies

Paws & Pals: Felicity now up for adoption at Associated Humane Societies

1:17
Gov. Murphy discusses potential Menendez replacement on ‘Ask Gov. Murphy’

Gov. Murphy discusses potential Menendez replacement on ‘Ask Gov. Murphy’

0:40
State, federal lawmakers introduce legislation to shorten funding gap for World Trade Center Health Program

State, federal lawmakers introduce legislation to shorten funding gap for World Trade Center Health Program