Close Menu
    Facebook X (Twitter) Instagram
    Trending
    • 5 Active Malware Campaigns in Early 2025: What You Need to Know
    • 10 Critical Network Pentest Findings IT Teams Overlook
    • Report Phishing Instantly with PhishAlarm
    • Password Reuse Epidemic: Nearly Half of User Logins Compromised
    • Women in Cybersecurity: Interest, Exposure, or Just Stereotypes??
    • Stay Ahead of Scammers in 2025
    • Cybersecurity Alert: Risks of Abandoned Websites
    • DHS Unveils Playbook for the Deployment of Artificial Intelligence for the Public Sector
    Fordham University Information Security and Assurance
    • Information Security and Assurance Homepage
    • Privacy Blog
    • About
    Fordham University Information Security and Assurance
    You are at:Home»Alerts»Alert: Facebook discloses network breach affecting 50 million user accounts
    Alerts

    Alert: Facebook discloses network breach affecting 50 million user accounts

    By Gerald Johnson Jr.September 28, 2018Updated:November 9, 20183 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Copy Link

    Via: ZDNet

    “Facebook said attackers exploited a vulnerability in its code that let them steal access tokens when users switched over to a public profile view via the “View As” feature.

    Facebook on Friday disclosed a breach of its network that affected almost 50 million user accounts. The social networking giant said that attackers exploited a vulnerability in Facebook’s code that let them steal access tokens — digital keys that are used to keep users logged in when they enter their username and password — when users switched over to a public profile view via the “View As” feature.

    The access tokens allowed the attackers to take over user accounts, however it’s still unclear whether user data was accessed and misused.

    Here is a step-by-step guide to reducing your digital footprint online, whether you want to lock down data or vanish entirely.

    Facebook said it has secured its network and affected user accounts since engineering discovered the attack on September 25. The bug was fixed and Facebook said it has notified law enforcement.

    Meantime, the company has reset the access tokens on all of the affected user accounts, as well as on another 40 million accounts that were subject to a “View As” look-up in the last year.

    Anyone impacted by the reset will need to log back in to Facebook and on any apps that use Facebook Login. Once logged back in, affected users will see a notification at the top of News Feed alerting them to the incident.

    Facebook has also disabled the “View As” feature while it conducts a security review.

    “Since we’ve only just started our investigation, we have yet to determine whether these accounts were misused or any information accessed,” Facebook said in a blog post. “We also don’t know who’s behind these attacks or where they’re based. We’re working hard to better understand these details — and we will update this post when we have more information, or if the facts change. In addition, if we find more affected accounts, we will immediately reset their access tokens.”

    On a call with media, chief executive Mark Zuckerberg said the initial investigation does not suggest that these access tokens were used to access any private messages, posts, or to post anything to user accounts.

    “I’m glad that we that we found this and that we were able to fix the vulnerability and secure accounts,” Zuckerberg said. “But it definitely is an issue that this happened in the first place. And I think this underscores the attacks that that our community and our service face, and the need to keep on investing heavily in security and being more proactive about protecting our community. And we’re certainly committed to doing that.”

     

    Source: https://www.zdnet.com/article/facebook-discloses-network-breach-affecting-50-million-user-accounts/?ftag=TREc64629f&bhid=22897651806331074555632548278564

    Share this:

    • Click to share on X (Opens in new window) X
    • Click to share on Facebook (Opens in new window) Facebook
    • Click to share on LinkedIn (Opens in new window) LinkedIn

    Like this:

    Like Loading...
    Previous ArticleScam Email ALERT: “BETTER PART TIME JOB OFFER FOR STUDENT AND STAFF”
    Next Article What is Phishing and how do I avoid getting hooked?

    Related Posts

    10 Critical Network Pentest Findings IT Teams Overlook

    Cybersecurity Alert: Risks of Abandoned Websites

    What You Need to Know About Emerging Data Privacy Trends in 2025

    Follow Us on Twitter!
    Follow @FordhamSecureIT
    My Tweets
    Archives
    Categories
    • AI (1)
    • Alerts (384)
    • CISO (19)
    • Cyber Security Awareness Month Tip (150)
    • Data Privacy Week (2)
    • Executive Director (1)
    • Exploits and Vulnerabilities (35)
    • General Information (34)
    • Identity and Access Management (12)
    • Identity Theft (26)
    • Jason Benedict (19)
    • Legitimate Email (14)
    • Malicious Email (24)
    • Mobile (25)
    • Network Security (2)
    • News and Events (143)
    • Newsletter (13)
    • Password (17)
    • Phishing (333)
    • Phishing Email (340)
    • Privacy (10)
    • Ransomware (9)
    • Scam (104)
    • Security Awareness (262)
    • Security Guides (34)
    • Social Engineering (12)
    • SPAM (40)
    • Suspicious (6)
    • Telework (2)
    • Teleworking (3)
    • Trojan (7)
    • Uncategorized (9)
    • Virtual Meeting (4)
    • Virus (28)
    • Viruses (8)
    • World Backup Day (1)
    • Zoom (6)
    Tag Cloud
    Alerts Artificial Intelligence Backups cell phones CISO Cybersecurity Awareness Month Tip Cybersecurity Month Data Privacy Device email Exploits and Vulnerabilities fordham fraud Identity and Access Management Identity Theft Information Security Guides Jason Benedict Legitimate Email malicious email Mobile Multi-Factor Authentication networks Network Security News and Events Newsletter online safety Online Shopping Password Phishing Phishing Email Privacy ransomware scam scams Security Awareness social engineering Social Media spam trojan Virus Viruses Wireless wire transfer scam World Backup Day zoom
    About
    About

    Founded in 1841, Fordham is the Jesuit University of New York, offering exceptional education distinguished by the Jesuit tradition to more than 15,100 students in its four undergraduate colleges and its six graduate and professional schools.

    Copyright © Fordham University
    Facebook X (Twitter) Instagram YouTube LinkedIn
    © 2025 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.

    %d