It has been announced that 50 million Facebook users have been subjected to their personal information being exposed to attackers. The hackers could obtain access tokens which can allow access and full control of user profiles and linked apps. It remains unclear what the attackers were able to gain and who was affected. Additionally, Facebook are still unable to confirm the exact method of the breach and the culprit.
The company advised users they had been logged out for protection and stated there is no need to change passwords:
“To protect your security, we may have recently logged you out of your Facebook account. On September 25th, 2018, we discovered an attack on our system where attackers stole Facebook access tokens. Access tokens are the equivalent of digital keys that attackers could then have used to take over other people’s accounts. By logging people out, we prevent attackers from using the tokens to access these accounts.
We don’t know yet if anyone’s Facebook information was accessed, but we wanted to let you know what we’re doing to protect your account. We’re continuing to investigate the situation and have informed law enforcement about the issue. If we find that more people have been affected, we’ll immediately log them out and then let them know what happened.
If you’ve been logged out, you will need to log back into your account to continue using Facebook or other apps you log into using Facebook. There’s no need for anyone to change their passwords. But if you’re having trouble logging back into your account, learn what you can do.”
Facebook was initially not forthcoming about this massive data breach and allegedly tried to conceal the news. Over the weekend, users were sent a notice regarding the breach, however this was titled “An Important Security Update”. It has been reported that Facebook may face a $1.63 billion dollar fine under the GDPR if it is shown that they “did not do enough to safeguard their users’ data”.
Announcements of this breach follows a privacy scandal investigation which found that advertisers can obtain phone numbers used in two-factor authentications (which claim to make accounts more secure). Several times this year in congressional hearings, lawmakers have suggested that the government will need to intervene if the social network is unable to get tighter control of its service.
Privacy scandals are becoming an increasing concern. This reminds us how vulnerable our personal information is on the internet. Civil liberties and digital rights groups are acting for tech companies to minimise the amount of data they store and argue for tighter laws and safeguards. Nonetheless, individuals should be aware of the risks and have a responsibility for the data they choose to share.
Read Facebook’s report here
