Facebook confirms security breach impacted 30M user accounts

Posted:
in General Discussion edited October 2018
Facebook has issued an update for September's security breach, advising the breach affected 30 million users, 20 million fewer than first thought, as well as revealing the kinds of data the attackers had access to during the incident.




The update on the original notification provided by the social network in September, which advised of a vulnerability where attackers could acquire access tokens used to authenticate a user's token, advises the breach in fact affected just 30 million people, with the effects of the breach split roughly in half across the group.

Approximately 15 million people had their name and contact details, including phone number and email, accessible by the attackers. For 14 million people, the attackers were able to access a considerable amount of other data on top, all listed in their profiles.

The list of extra data includes usernames, genders, locale and language, relationship status, religion, hometown, self-reported current city, date of birth, device types used to access Facebook, education, work, the last 10 places the user was checked into or tagged in, website address, people or pages they follow, and the last 15 recent searches on the service.

For the remaining 1 million users whose tokens were acquired, the attackers apparently did not access the accounts at all.

Examples of customized messages Facebook will send out to affected users
Examples of customized messages Facebook will send out to affected users


Facebook is now advising concerned users to check the site's Help Center to see if they were affected. In the coming days, users within the 30 million people identified by Facebook will be sent a customized message advising of what the attackers could have accessed, as well as ways to protect themselves.

The company notes the attack did not affect its other services, including Messenger, Messenger Kids, Instagram, WhatsApp, Oculus, Workplace, Pages, payments, third-party apps, or advertising or developer accounts. Facebook also advises it will be looking for other ways the attackers used Facebook, along as watching out for smaller-scale attacks, and will continue to cooperate with the FBI, U.S. FTC, the Irish Data Protection Commission, and other authorities.

According to Facebook, the attackers exploited a vulnerability in the social network's code that existed between July 2017 and September 2018, which was the result of a "complex interaction of three distinct software bugs" that impacted the "View As" feature, which allowed users to see how their profile appears to other people.

The bug allowed attackers to steal Facebook access tokens, which could then be used to take over other accounts.

The attack itself was first spotted on September 14, 2018, after the site saw an unusual spike of activity, prompting an investigation that confirmed it was an attack on September 25. The vulnerability was closed within two days, with the attack also halted and user accounts secured by "restoring the access tokens for people who were potentially exposed." Facebook also disabled View As at the same time.

Facebook believes the attackers had already gained control of a set of accounts, then set up an automated process to move between accounts and acquire the access tokens of friends connected to the accounts, as well as friends of those friends. Eventually amassing tokens for around 400,000 people, the process also loaded up the Facebook profiles of each account and any connected data, including posts, friend lists, group memberships, recent Messenger conversation contacts, and the contents of messages in groups where the user was a Page admin.

A subset of these 400,000 accounts was used to steal the access tokens for the aforementioned 30 million accounts.

Comments

  • Reply 1 of 6
    Approximately 15 million people had their name and contact details, including phone number and email, accessible by the attackers. For 14 million people, the attackers were able to access a considerable amount of other data on top, all listed in their profiles. 

    The list of extra data includes usernames, genders, locale and language, relationship status, religion, hometown, self-reported current city, date of birth, device types used to access Facebook, education, work, the last 10 places the user was checked into or tagged in, website address, people or pages they follow, and the last 15 recent searches on the service.
    15 million, while a large number, is a small portion of Facebook’s user base. So, overall, not that many affected. 

    Still, I don’t understand why so many don’t care that such information is out there about them. The not caring seems odd. But, as I’ve mentioned before, I have yet to hear about anything nefarious happening when this sort of data is leaked. Doesn’t mean it hasn’t, I just haven’t heard. 
    edited October 2018 watto_cobra
  • Reply 2 of 6
    sflocalsflocal Posts: 6,093member
    Approximately 15 million people had their name and contact details, including phone number and email, accessible by the attackers. For 14 million people, the attackers were able to access a considerable amount of other data on top, all listed in their profiles. 

    The list of extra data includes usernames, genders, locale and language, relationship status, religion, hometown, self-reported current city, date of birth, device types used to access Facebook, education, work, the last 10 places the user was checked into or tagged in, website address, people or pages they follow, and the last 15 recent searches on the service.
    15 million, while a large number, is a small portion of Facebook’s user base. So, overall, not that many affected. 

    Still, I don’t understand why so many don’t care that such information is out there about them. The not caring seems odd. But, as I’ve mentioned before, I have yet to hear about anything nefarious happening when this sort of data is leaked. Doesn’t mean it hasn’t, I just haven’t heard. 
    Stupid... my email address, including burner-addresses for junk is out there in the world WAY before this FB debacle.  If they want to know that people watch cute kitten videos, go right ahead.  If you use the Internet, you're already putting much out there anyways.  No info that could do me actual harm was available.  I'm looking at you EQUIFAX!
    watto_cobra
  • Reply 3 of 6
    And now facebook wants to 3D map your face. What could possibly go wrong?!
    watto_cobra
  • Reply 4 of 6
    22july201322july2013 Posts: 3,571member
    gutengel said:
    And now facebook wants to 3D map your face. What could possibly go wrong?!
    If Facebook could 3D map your brain, and sell the data, would they?
    watto_cobra
  • Reply 5 of 6
    gutengel said:
    And now facebook wants to 3D map your face. What could possibly go wrong?!
    If Facebook could 3D map your brain, and sell the data, would they?
    This is a rhetorical question, right?
  • Reply 6 of 6
    MacProMacPro Posts: 19,727member
    I deleted my FB a year or more ago from FB settings and got the 'You have 30 days to change your mind' message.  I assumed if I did nothing after 30 days it was gone.  On a hunch, I just checked and blow me down it was still there dormant but all my info still there.  So, I deleted the account again! The same '30 days' message came up.
    watto_cobramuthuk_vanalingam
Sign In or Register to comment.