Black Friday Sale! 50% Off All Access

Facebook Stored Up to 600 Million User Passwords in Plain Text Facebook engineers built applications that stored unencrypted passwords on internal servers which could be searched by over 20,000 employees.

By Matthew Humphries

This story originally appeared on PCMag

via PC Mag

It looks as though Facebook is in hot water once again today as it has been revealed up to 600 million Facebook users had their passwords stored in plain text on the social network's internal servers as far back as 2012.

As KrebsonSecurity reports, a Facebook source who asked for anonymity confirmed that between 200 and 600 million users had their passwords stored free of encryption on the company's servers. The data was being collected by a number of applications, leaving them available to view in plain text. The internal servers are accessible by over 20,000 employees, meaning any of them could have searched the list and potentially abused the data.

Facebook is thought to be carrying out an internal investigation to see how this managed to happen. What's of most concern is around 2,000 Facebook engineers are thought to have queried the password data over nine million times.

Scott Renfro, an engineer at Facebook, has confirmed to Krebs that Facebook users will be informed of what happened today, but that, "We've not found any cases so far in our investigations where someone was looking intentionally for passwords, nor have we found signs of misuse of this data." Before that happens, Facebook has been looking to see which, if any of the passwords have, "signs of abuse" because it's only those users that will need to be told to change their password. As it currently stands, no resets are expected to be necessary.

Facebook has known about the plain text passwords since January when a review carried out by security engineers noticed the passwords being logged. A task force was then created to review the situation and an investigation carried out so as to instigate, "long-term infrastructure changes to prevent this going forward."

A written statement from Facebook sent to Krebs states that notifications will be sent to, "hundreds of millions of Facebook light users, tens of millions of other Facebook users, and tens of thousands of Instagram users."

Matthew Humphries

Senior Editor

Want to be an Entrepreneur Leadership Network contributor? Apply now to join.

Living

These Are the 'Wealthiest and Safest' Places to Retire in the U.S. None of Them Are in Florida — and 2 States Swept the List.

More than 338,000 U.S. residents retired to a new home in 2023 — a 44% increase year over year.

Starting a Business

This Sommelier's 'Laughable' Idea Is Disrupting the $385 Billion Wine Industry

Kristin Olszewski, founder of Nomadica, is bringing premium wine to aluminum cans, and major retailers are taking note.

Starting a Business

He Started a Business That Surpassed $100 Million in Under 3 Years: 'Consistent Revenue Right Out of the Gate'

Ryan Close, founder and CEO of Bartesian, had run a few small businesses on the side — but none of them excited him as much as the idea for a home cocktail machine.

Business News

DOGE Leaders Elon Musk and Vivek Ramaswamy Say Mandating In-Person Work Would Make 'a Wave' of Federal Employees Quit

The two published an op-ed outlining their goals for their new department, including workforce reductions.

Business News

These Are the Highest Paying Jobs Available Without a College Degree, According to a New Report

The median salaries for these positions go up to $102,420 per year.

Side Hustle

20 Ways to Make Money from Home in 2023

Making money from home doesn't have to be complicated. Check out these 20 smart ways to make cash from the comfort of your computer desk.