Facebook logs out 90 million people after security breach

Hackers stole information that could have allowed them to take over 50 million user accounts.

By Brian Fung / The Washington Post

Facebook said Friday that hackers had stolen information that could have allowed them to take over 50 million user accounts, in the latest mishap for the social media company, which has spent months struggling to regain the confidence of policymakers and the public.

The company said that as many as 90 million Facebook users — out of a total of 2.2 billion — will have to log back into their accounts as a result of the breach. Notifications will appear at the top of the Facebook news feed for the 50 million users who were directly affected, executives said on a call with reporters.

The hackers were able to gain access to profile information, such as users’ names, hometowns and genders, Facebook said. It is possible they could have had access to more information, but Facebook said its investigation is in the early stages. No credit card information was exposed, Facebook executives said, and so far there is no evidence the attackers sought to access private messages or post fraudulent messages from the accounts.

“This is a serious issue and we’re committed to addressing it,” said Facebook chief executive Mark Zuckerberg. “This underscores that there are constant attacks from people who are trying to take over accounts or steal information from people in our community.”

Facebook discovered the breach on Tuesday after noticing a spike in user activity on Sept. 16., which prompted engineers to investigate further. They soon found three interlocking bugs on Facebook’s website that attackers had been using to gain access to accounts.

The attackers exploited Facebook’s systems through a flaw in the company’s “View As” feature, the company said, which allows a Facebook user to view his or her own profile as somebody else might see it.

Embedded in the “View As” feature was a video uploader that was incorrectly generating security tokens – pieces of code that, under normal circumstances, are designed to let a user remain logged in even after navigating away from Facebook’s website.

The incident prompted Facebook to disable the “View As” feature for the time being, and users are not being asked to change their passwords. The company has not determined who is responsible for the attack.

“People’s privacy and security is incredibly important, and we’re sorry this happened,” Facebook said in a blog post. It’s why we’ve taken immediate action to secure these accounts and let users know what happened.”

The company said that the security issue was patched Thursday night. Facebook’s stock dropped more than 3 percent following the news.

The disclosure adds to a brutal year for Facebook, which is still grappling with the fallout from its Cambridge Analytica fiasco and the prospect of new regulations or legislation in Washington that could target tech companies. Zuckerberg and his top lieutenants have been summoned repeatedly to Capitol Hill to answer for their company’s role in spreading misinformation and hate speech online.

Sen. Mark Warner, D-Va., the ranking member of the Senate Intelligence Committee, called the breach “deeply concerning” and called for a full investigation.

“This is another sobering indicator that Congress needs to step up and take action to protect the privacy and security of social media users,” said Warner. “As I’ve said before – the era of the Wild West in social media is over.”

Other lawmakers on Wednesday grilled representatives from Google, Twitter and a number of telecom companies on their approach to user privacy, in some cases demanding commitments to concrete proposals such as a requirement that companies disclose data breaches within 72 hours of discovery. The companies largely balked at discussing specifics, instead pledging to work with the Senate Commerce Committee to craft a comprehensive national privacy law.

Meanwhile, tech companies such as Facebook face growing scrutiny by state and federal law enforcement who are exploring whether to invoke antitrust law against some of the industry’s practices. The Federal Trade Commission has held a series of hearings on the issue, and the Justice Department this week met with numerous state attorneys general to discuss Silicon Valley’s handling of user data.

The meeting opened the door to a possible multi-state probe into the tech industry even as federal officials weigh whether they have the resources to mount an antitrust effort. On Friday, the Justice Department’s antitrust chief, Makan Delrahim, said he was receptive to complaints about tech companies but that regulators lack “credible evidence” to build an antitrust case. In the United States, antitrust lawsuits typically require regulators to marshal enough economic data to persuade a judge that competition has been harmed by a company’s actions.

Facebook on Wednesday notified federal authorities as well as European data security officials of the security incident, but on Friday the company declined to say whether it has reached out to other law enforcement agencies.

Ireland’s Data Protection Commission — the watchdog charged with monitoring compliance with GDPR, the European Union’s new data privacy law — said in a statement Friday that Facebook’s disclosure “lacks detail” and that it was pushing the company to reveal more as a “matter of urgency.” Violations of GDPR can carry enormous penalties: Up to 4 percent of a company’s annual revenue.

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Business

Everett
Red Robin to pay $600K for harassment at Everett location

A consent decree approved Friday settles sexual harassment and retaliation claims by four victims against the restaurant chain.

magniX employees and staff have moved into the company's new 40,000 square foot office on Seaway Boulevard on Monday, Jan. 18, 2020 in Everett, Washington. magniX consolidated all of its Australia and Redmond operations under one roof to be home to the global headquarters, engineering, manufacturing and testing of its electric propulsion systems.  (Andy Bronson / The Herald)
Harbour Air plans to buy 50 electric motors from Everett company magniX

One of the largest seaplane airlines in the world plans to retrofit its fleet with the Everett-built electric propulsion system.

Simreet Dhaliwal speaks after winning during the 2024 Snohomish County Emerging Leaders Awards Presentation on Wednesday, April 17, 2024, in Everett, Washington. (Ryan Berry / The Herald)
Simreet Dhaliwal wins The Herald’s 2024 Emerging Leaders Award

Dhaliwal, an economic development and tourism specialist, was one of 12 finalists for the award celebrating young leaders in Snohomish County.

Lynnwood
New Jersey company acquires Lynnwood Land Rover dealership

Land Rover Seattle, now Land Rover Lynnwood, has been purchased by Holman, a 100-year-old company.

Szabella Psaztor is an Emerging Leader. (Olivia Vanni / The Herald)
Szabella Pasztor: Change begins at a grassroots level

As development director at Farmer Frog, Pasztor supports social justice, equity and community empowerment.

Simreet Dhaliwal is an Emerging Leader. (Olivia Vanni / The Herald)
Simreet Dhaliwal: A deep-seated commitment to justice

The Snohomish County tourism and economic specialist is determined to steer change and make a meaningful impact.

Nathanael Engen, founder of Black Forest Mushrooms, an Everett gourmet mushroom growing operation is an Emerging Leader. (Olivia Vanni / The Herald)
Nathanael Engen: Growing and sharing gourmet mushrooms

More than just providing nutritious food, the owner of Black Forest Mushrooms aims to uplift and educate the community.

Owner and founder of Moe's Coffee in Arlington Kaitlyn Davis poses for a photo at the Everett Herald on March 22, 2024 in Everett, Washington. (Annie Barker / The Herald)
Kaitlyn Davis: Bringing economic vitality to Arlington

More than just coffee, Davis has created community gathering spaces where all can feel welcome.

Emerging Leader John Michael Graves. (Ryan Berry / The Herald)
John Michael Graves: Champion for diversity and inclusion

Graves leads training sessions on Israel, Jewish history and the Holocaust and identifying antisemitic hate crimes.

Gracelynn Shibayama, the events coordinator at the Edmonds Center for the Arts, is an Emerging Leader. (Olivia Vanni / The Herald)
Gracelynn Shibayama: Connecting people through the arts and culture

The Edmonds Center for the Arts coordinator strives to create a more connected and empathetic community.

Eric Jimenez, a supervisor at Cocoon House, is an Emerging Leader. (Olivia Vanni / The Herald)
Eric Jimenez: Team player and advocate for youth

As an advocate for the Latino community, sharing and preserving its traditions is central to Jimenez’ identity.

Molbak's Garden + Home in Woodinville, Washington closed on Jan. 28 2024. (Photo courtesy of Molbak's)
Molbak’s, former Woodinville garden store, hopes for a comeback

Molbak’s wants to create a “hub” for retailers and community groups at its former Woodinville store. But first it must raise $2.5 million.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.