• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

My TechDecisions

  • Best of Tech Decisions
  • Topics
    • Video
    • Audio
    • Mobility
    • Unified Communications
    • IT Infrastructure
    • Network Security
    • Physical Security
    • Facility
    • Compliance
  • RFP Resources
  • Resources
  • Podcasts
  • Subscribe
  • Project of the Week
  • About Us
    SEARCH
Network Security

Facebook Announces Severe Security Breach

The Facebook security breach attack targeted the “access tokens” of 50 million users.

October 18, 2018 Sam Harton Leave a Comment

Facebook Photos

50 million Facebook accounts were compromised on September 25th in what is likely the companies most severe data breach. Facebook made the breach public with an announcement last week, claiming that the company will notify all users who were affected, who will be logged out of their account and have to log back in. Facebook engineers were able to patch the breach two days after they discovered it.

“I’m glad we found this and fixed the vulnerability,” Mark Zuckerberg told The Guardian. “But it definitely is an issue that this happened in the first place. I think this underscores the attacks that our community and our services face.”

Hackers stole users’ “access tokens,” which allow users to stay logged into the site over multiple browsing sessions. This means that the attacker has complete control over whatever account they stole the token from, making it a particularly worrisome breach.

This breach comes not long after a massive scandal involving Cambridge Analytica and the alleged tampering with the 2016 presidential election by, for which Zuckerberg issued a public apology, stating “We have a responsibility to protect your data, and if we can’t then we don’t deserve to serve you.”

Facebook has since championed a new, less cavalier approach to privacy, but an attacker was still able to exploit three bugs involving the site’s “view as” feature, which was introduced in July 2017 to allow users to see how their profile looks to other people. Facebook has also made everyone who has used that feature since July 2017 to log out, effectively resetting their access tokens, protecting their accounts.

Guy Rosen, vice-president of product management at Facebook, explained that they have been in contact with law enforcement and are working with the FBI. “The investigation is early, and it’s hard to discover who is behind this,” Rosen said. “We may never know,” noting that such a large and complex hack required a high-level of expertise. Dr Lukasz Olejnik, an independent cybersecurity and privacy researcher, corroborated this claim, saying “Anyone involved in this hack knew what he was doing.”

The investigation is looking into how the access tokens have been used by the attacker, claiming that there has been no evidence of them accessing users’ private messages or posting as the user on their account.

The location of the breach is also a mystery as of right now as the attack was so broad. Facebook notified the Irish Data Protection Commission (DPC) and the newly implemented General Data Protection Regulation (GDPR) in the EU requires the social media company to disclose any breaches within 72 hours of its discovery.

“Today’s disclosure is a reminder about the dangers posed when a small number of companies like Facebook or the credit bureau Equifax are able to accumulate so much personal data about individual Americans without adequate security measures,” said the US senator Mark Warner in a statement. “This is another sobering indicator that Congress needs to step up and take action to protect the privacy and security of social media users.”

Articles published in trusted news sources like the Guardian and the Associated Press that covered the data breach were flagged as spam on Facebook, preventing users from sharing such articles on the platform. The company apologized for censoring news of the breach, blaming it on “automated systems.”

Tagged With: Cyber Attacks

Related Content:

  • CISA Ransomware CISA Wants You To Report Anything You Know…
  • Cybersecurity Consolidation, cyber readiness Cyber Readiness Institute Launches Free Cyber Readiness Program…
  • Security Awareness Training Security Awareness Training Needs to Change. Here’s Why.
  • Microsoft Defender for IoT Microsoft Launches Defender for IoT Cloud-Managed Platform

Free downloadable guide you may like:

  • Four IT Trends That Will Define 2023Expert Series: Four IT Trends That Will Define 2023

    Learn about four key technologies we identified as critical to your IT organization’s success in 2023, as well as how to invest in new innovations emerging from each.

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Get the FREE Tech Decisions eNewsletter

Sign up Today!

Latest Downloads

Four IT Trends That Will Define 2023
Expert Series: Four IT Trends That Will Define 2023

Learn about four key technologies we identified as critical to your IT organization’s success in 2023, as well as how to invest in new innovations ...

Harnessing the Power of Digital Signage
Harnessing the Power of Digital Signage

Choosing the best solutions for messaging, branding, and communicating in today’s content-everywhere landscape

Blueprint Series Cover: What works for hybrid work
Blueprint Series: What Works for Hybrid Work

Download this free resource to learn about how IT leaders can effectively manage and implement a hybrid work model.

View All Downloads

Would you like your latest project featured on TechDecisions as Project of the Week?

Apply Today!
Sharp Microsoft Collaboration HQ Logo

Learn More About the
Windows Collaboration Display

More from Our Sister Publications

Get the latest news about AV integrators and Security installers from our sister publications:

Commercial IntegratorSecurity Sales

AV-iQ

Footer

TechDecisions

  • Home
  • Welcome to TechDecisions
  • Subscribe to the Newsletter
  • Contact Us
  • Media Solutions & Advertising
  • Comment Guidelines
  • RSS Feeds
  • Twitter
  • Facebook
  • Linkedin

Free Technology Guides

FREE Downloadable resources from TechDecisions provide timely insight into the issues that IT, A/V, and Security end-users, managers, and decision makers are facing in commercial, corporate, education, institutional, and other vertical markets

View all Guides
TD Project of the Week

Get your latest project featured on TechDecisions Project of the Week. Submit your work once and it will be eligible for all upcoming weeks.

Enter Today!
Emerald Logo
ABOUTCAREERSAUTHORIZED SERVICE PROVIDERSTERMS OF USEPRIVACY POLICY

© 2023 Emerald X, LLC. All rights reserved.