Black Friday Sale! 50% Off All Access

Facebook Discloses Hack Affecting 50 Million Accounts The attackers stole Facebook access tokens, which keep you logged in so you don't have to enter your password every time you visit. In total, around 90 million people will have to log back in the next time they try to access the platform.

By Angela Moscaritolo Edited by Dan Bova

This story originally appeared on PCMag

via PC Mag

Facebook on Friday disclosed a security breach affecting nearly 50 million accounts.

The social network discovered the breach on Tuesday and is still investigating the issue, Guy Rosen, VP of product management, wrote in the announcement.

The hackers exploited a vulnerability in Facebook's code impacting the "View As" feature, which lets you see what your profile looks like to the public or a specific individual. For now, Facebook is turning off the "View As" feature while it investigates the incident.

The attackers stole Facebook access tokens -- aka "digital keys that keep people logged in to Facebook so they don't need to re-enter their password every time they use the app," Rosen explained. With your access token, an attacker could take over your account and use it as if they were you.

The flaw that attackers exploited stemmed from a video-uploading feature change Facebook made in July 2017, but it did not elaborate.

Facebook has patched that bug, notified law enforcement about the breach, and reset the access tokens of all impacted accounts. As a precaution, Facebook is resetting the tokens for another 40 million accounts "that have been subject to a 'View As' look-up in the last year." The company said there's no evidence those other 40 million accounts have been compromised.

In total, around 90 million people will have to log back in the next time they try to access the platform. On a call with reporters Friday, Facebook executives said no actual passwords were taken, so a password reset is not necessary. No credit card information was affected, they added.

At this point, many questions remain: "Since we've only just started our investigation, we have yet to determine whether these accounts were misused or any information accessed," Rosen wrote. "We also don't know who's behind these attacks or where they're based."

Angela Moscaritolo has been a PCMag reporter since January 2012. 

Want to be an Entrepreneur Leadership Network contributor? Apply now to join.

Business News

DOGE Leaders Elon Musk and Vivek Ramaswamy Say Mandating In-Person Work Would Make 'a Wave' of Federal Employees Quit

The two published an op-ed outlining their goals for their new department, including workforce reductions.

Living

These Are the 'Wealthiest and Safest' Places to Retire in the U.S. None of Them Are in Florida — and 2 States Swept the List.

More than 338,000 U.S. residents retired to a new home in 2023 — a 44% increase year over year.

Business Solutions

How Entrepreneurs Automate Time-Consuming Tasks With the Latest AI

Get Midjourney, Gemini, ChatGPT, and more at your disposal.

Marketing

Want To Be a Great Marketer? Stop Thinking Like One

In an age of AI-fueled content overload, consumers crave genuine connection and meaningful marketing.

Starting a Business

This Sommelier's 'Laughable' Idea Is Disrupting the $385 Billion Wine Industry

Kristin Olszewski, founder of Nomadica, is bringing premium wine to aluminum cans, and major retailers are taking note.

Business News

These Are the Highest Paying Jobs Available Without a College Degree, According to a New Report

The median salaries for these positions go up to $102,420 per year.