Facebook says 50M user accounts affected by security breach

<p>Facebook reported a major security breach in which 50 million user accounts were accessed by unknown attackers.</p>

News 12 Staff

Sep 28, 2018, 5:04 PM

Updated 2,036 days ago

Share:

NEW YORK (AP) - Facebook reported a major security breach in which 50 million user accounts were accessed by unknown attackers.
The attackers gained the ability to "seize control" of those user accounts, Facebook said, by stealing digital keys the company users to keep users logged in. Facebook has logged out the 50 million breached users - plus another 40 million who were vulnerable to the attack. Users don't need to change their Facebook passwords, it said.
Facebook said it doesn't know who was behind the attacks or where they're based. In a call with reporters on Friday, CEO Mark Zuckerberg said that attackers would have had the ability to view private messages or post on someone's account, but there's no sign that they did.
"We do not yet know if any of the accounts were actually misused," Zuckerberg said.
The hack is the latest setback for Facebook during a tumultuous year of security problems and privacy issues . So far, though, none have significantly shaken the confidence of the company's 2 billion global users.
This latest hack involved a bug in Facebook's "View As" feature, the company said in a blog post . That feature lets people see how their profiles appear to others. The attackers used that vulnerability to steal those digital keys, known as "access tokens." Possession of those tokens would allow attackers to control those accounts.
"We haven't yet been able to determine if there was specific targeting" of particular accounts, Guy Rosen, Facebook's vice president of product management, said in a call with reporters. "It does seem broad. And we don't yet know who was behind these attacks and where they might be based."
Neither passwords nor credit card data was stolen, Rosen said. He said the company has alerted the FBI and regulators in the United States and Europe.
Jake Williams, a security expert at Rendition Infosec, said he is concerned about whether third party applications were affected.
Williams noted that the company's "Facebook Login" feature lets users log into other apps and websites with their Facebook credentials. "These access tokens that were stolen show when a user is logged into Facebook and that may be enough to access a user's account on a third party site," he said.
Facebook didn't immediately respond to follow-up questions about whether third party apps were affected.
News broke early this year that a data analytics firm once employed by the Trump campaign, Cambridge Analytica, had improperly gained access to personal data from millions of user profiles. Then a congressional investigation found that agents from Russia and other countries have been posting fake political ads since at least 2016. Zuckerberg appeared at a congressional hearing focused on Facebook's privacy practices in April.
The Facebook bug is reminiscent of a much larger attack on Yahoo in which attackers compromised 3 billion accounts - enough for half of the world's entire population. In the case of Yahoo, information stolen included names, email addresses, phone numbers, birthdates and security questions and answers. It was among a series of Yahoo hacks over several years.
U.S. prosecutors later blamed Russian agents for using the information they stole from Yahoo to spy on Russian journalists, U.S. and Russian government officials and employees of financial services and other private businesses.
In Facebook's case, it may be too early to know how sophisticated the attackers were and if they were connected to a nation state, said Thomas Rid, a professor at the Johns Hopkins University. Rid said it could also be spammers or criminals.
"Nothing we've seen here is so sophisticated that it requires a state actor," Rid said. "Fifty million random Facebook accounts are not interesting for any intelligence agency."
Ed Mierzwinski, the senior director of consumer advocacy group U.S. PIRG, said the breach was "very troubling."
"It's yet another warning that Congress must not enact any national data security or data breach legislation that weakens current state privacy laws, pre-empts the rights of states to pass new laws that protect their consumers better, or denies their attorneys general rights to investigate violations of or enforce those laws," he said in a statement.
Wedbush analyst Michael Pachter said "the most important point is that we found out from them," meaning Facebook, as opposed to a third party.
"As a user, I want Facebook to proactively protect my data and let me know when it's compromised," he said.
(Copyright 2018 The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.)


More from News 12
0:49
Nassau County says it will rework its lease approval process in effort to build resort and casino

Nassau County says it will rework its lease approval process in effort to build resort and casino

1:51
Sunny and cool today; spotty showers possible this weekend

Sunny and cool today; spotty showers possible this weekend

0:18
Police: East Northport man killed in motorcycle cash in East Farmingdale

Police: East Northport man killed in motorcycle cash in East Farmingdale

0:25
Man accused of illegally selling THC, cannabis products in Valley Stream

Man accused of illegally selling THC, cannabis products in Valley Stream

2:01
Nassau/Suffolk Autism Society of America hosts special event at Cradle of Aviation Museum

Nassau/Suffolk Autism Society of America hosts special event at Cradle of Aviation Museum

1:53
Shop Mother’s Day Gifts – Exclusive Offers Up to 75% OFF!

Shop Mother’s Day Gifts – Exclusive Offers Up to 75% OFF!

1:48
Ducks posthumously honor co-owner during Opening Day

Ducks posthumously honor co-owner during Opening Day

2:01
Students take part in pro-Palestinian protest at Hofstra University

Students take part in pro-Palestinian protest at Hofstra University

1:56
Superintendent: Person accused of making threats to Islip School District in custody

Superintendent: Person accused of making threats to Islip School District in custody

1:54
South Setauket father charged for allegedly abusing infant son

South Setauket father charged for allegedly abusing infant son

1:27
East Meadow School District: Nesconset man accused of lewd act worked as social worker

East Meadow School District: Nesconset man accused of lewd act worked as social worker

2:35
Law enforcement resumes search in Manorville in connection with Gilgo Beach case

Law enforcement resumes search in Manorville in connection with Gilgo Beach case

0:36
11 LIRR employees suspended without pay, accused of submitting fake COVID-19 vaccine cards

11 LIRR employees suspended without pay, accused of submitting fake COVID-19 vaccine cards

0:27
Brent Burns, Dmitry Orlov help Hurricanes hold on to beat Islanders 3-2 for 3-0 series lead

Brent Burns, Dmitry Orlov help Hurricanes hold on to beat Islanders 3-2 for 3-0 series lead

1:13
The East End: Shou Sugi Ban House in Watermill

The East End: Shou Sugi Ban House in Watermill

Ready to explore the great outdoors? These 14 tips can help you stay safe while hiking

Ready to explore the great outdoors? These 14 tips can help you stay safe while hiking

Is your mom awesome? Long Island tell us why your Mom Rocks!

Is your mom awesome? Long Island tell us why your Mom Rocks!

2:01
Police: 21-year-old woman fled fatal Massapequa DWI crash in stolen town patrol car

Police: 21-year-old woman fled fatal Massapequa DWI crash in stolen town patrol car

0:20
Police: Hempstead man killed in 3-car crash on Meadowbrook Parkway

Police: Hempstead man killed in 3-car crash on Meadowbrook Parkway

0:21
UBS Arena to host 2024 MTV VMAs in September

UBS Arena to host 2024 MTV VMAs in September