Facebook says 50M user accounts affected by security breach

FILE- In this May 1, 2018, file photo, Facebook CEO Mark Zuckerberg makes the keynote speech at F8, Facebook's developer conference in San Jose, Calif. Facebook says it recently discovered a security breach affecting nearly 50 million user accounts. In a blog post, Friday, Sept. 28, the company says hackers exploited its "View As" feature, which lets people see what their profiles look like to someone else. Facebook says it has taken steps to fix the security problem and alerted law enforcement. (AP Photo/Marcio Jose Sanchez, File)

FILE- In this May 1, 2018, file photo, Facebook CEO Mark Zuckerberg makes the keynote speech at F8, Facebook's developer conference in San Jose, Calif. Facebook says it recently discovered a security breach affecting nearly 50 million user accounts. In a blog post, Friday, Sept. 28, the company says hackers exploited its "View As" feature, which lets people see what their profiles look like to someone else. Facebook says it has taken steps to fix the security problem and alerted law enforcement. (AP Photo/Marcio Jose Sanchez, File)

Saturday, September 29, 2018

NEW YORK -- Facebook reported a major security breach in which 50 million user accounts were accessed by unknown attackers.

The attackers gained the ability to "seize control" of those user accounts, Facebook said, by stealing digital keys the company uses to keep users logged in. Facebook has logged out the 50 million breached users -- plus another 40 million who were vulnerable to the attack. Users don't need to change their Facebook passwords, it said.

Facebook said it doesn't know who was behind the attacks or where they're based. In a call with reporters on Friday, CEO Mark Zuckerberg said that attackers would have had the ability to view private messages or post on someone's account, but there's no sign that they did.

"We do not yet know if any of the accounts were actually misused," Zuckerberg said.

The hack is the latest setback for Facebook during a tumultuous year of security problems and privacy issues . So far, though, none have significantly shaken the confidence of the company's 2 billion global users.

This latest hack involved bugs in Facebook's "View As" feature, the company said in a blog post . That feature lets people see how their profiles appear to others. The attackers used that vulnerability to steal those digital keys, known as "access tokens." Possession of those tokens would allow attackers to control those accounts.

The attackers were able to discover and exploit bugs in how the "View As" feature interacted with Facebook's video uploading feature for posting "happy birthday" messages, said Guy Rosen, Facebook's vice president of product management.

"We haven't yet been able to determine if there was specific targeting" of particular accounts, Rosen said in a call with reporters. "It does seem broad. And we don't yet know who was behind these attacks and where they might be based."

Neither passwords nor credit card data was stolen, Rosen said. He said the company has alerted the FBI and regulators in the United States and Europe.

Jake Williams, a security expert at Rendition Infosec, said he is concerned about whether third party applications were affected.

Williams noted that the company's "Facebook Login" feature lets users log into other apps and websites with their Facebook credentials. "These access tokens that were stolen show when a user is logged into Facebook and that may be enough to access a user's account on a third party site," he said.

Facebook didn't immediately respond to follow-up questions about whether third party apps were affected.

News broke early this year that a data analytics firm once employed by the Trump campaign, Cambridge Analytica, had improperly gained access to personal data from millions of user profiles. Then a congressional investigation found that agents from Russia and other countries have been posting fake political ads since at least 2016. In April, Zuckerberg appeared at a congressional hearing focused on Facebook's privacy practices.

The Facebook bug is reminiscent of a much larger attack on Yahoo in which attackers compromised 3 billion accounts -- enough for half of the world's entire population. In the case of Yahoo, information stolen included names, email addresses, phone numbers, birthdates and security questions and answers. It was among a series of Yahoo hacks over several years.

U.S. prosecutors later blamed Russian agents for using the information they stole from Yahoo to spy on Russian journalists, U.S. and Russian government officials and employees of financial services and other private businesses.

National on 09/29/2018