San Francisco, Sep 28 : In the biggest-ever security breach after Cambridge Analytica scandal, Facebook on Friday admitted hackers broke into nearly 50 million users' accounts by stealing their "access tokens" or digital keys.
This allowed them to steal Facebook access tokens which they could then use to take over people's accounts, Facebook said in a statement.
Access tokens are the equivalent of digital keys that keep people logged in to Facebook so they do not need to re-enter their password every time they use the app.
"Our investigation is still in its early stages. But it's clear that attackers exploited a vulnerability in Facebook's code that impacted 'View As', a feature that lets people see what their own profile looks like to someone else," said Guy Rosen, VP of Product Management.
Facebook security team discovered the security issue on September 25, and it has now fixed the vulnerability and informed the law enforcement.
"We have reset the access tokens of the almost 50 million accounts we know were affected to protect their security.
"We're also taking the precautionary step of resetting access tokens for another 40 million accounts that have been subject to a 'View As' look-up in the last year," Facebook said.
As a result, around 90 million people will now have to log back into Facebook, or any of their apps that use Facebook login.
After they have logged back in, people will get a notification at the top of their News Feed explaining what happened.
"We're temporarily turning off the 'View As' feature while we conduct a thorough security review," Facebook said.
This attack exploited the complex interaction of multiple issues in Facebook code.
"The attackers not only needed to find this vulnerability and use it to get an access token, they then had to pivot from that account to others to steal more tokens," it said.
Facebook said it does not know who is behind this massive security attack.
"We're working hard to better understand these details and "we will update this post when we have more information, or if the facts change," said the company.
In the Cambridge Analytica scandal, data of nearly 87 million people was breached upon.
Let the Truth be known. If you read VB and like VB, please be a VB Supporter and Help us deliver the Truth to one and all.
Bengaluru (PTI): Minister Priyank Kharge on Wednesday highlighted the state’s leadership in AI and deep technology while engaging with global industry leaders and startups at a four-day summit held in New Delhi, officials said.
During the event, Priyank witnessed the signing of a strategic MoU between H Company and St John’s Medical College & Research Institute, Bengaluru, to pilot advanced enterprise AI for hospital operations and workflow automation, strengthening responsible AI in healthcare, the minister’s office said in a statement here.
Speaking on the sidelines of the India AI Impact Summit, the minister said Karnataka is ahead of the curve in AI.
“We are already home to leading global AI players such as Harvey AI and Anthropic, and The Walt Disney Company is expanding its AI network in Bengaluru,” he added.
Noting Bengaluru’s position among the top global cities for AI talent, he added, “Under our DeepTech Decade, we are supporting startups with grants of up to Rs 1 crore. We are engaging with global leaders and innovators to ensure responsible AI use, build the right skill sets, create strong incubators, and establish Centres of Excellence that can foster startups and strengthen e-governance.”
The minister also attended a roundtable organised by the US-India Business Council (USIBC), where discussions focused on strengthening technology collaboration, investment partnerships, and innovation-led growth between Karnataka and global enterprises.
He met Timo Harakka, Member of Parliament of Finland, to explore possibilities for collaboration between Karnataka and Finland in AI and deep-tech sectors, including joint research, innovation partnerships, and startup exchanges.
The Karnataka IT Minister also visited the Indian Army showcase at the summit, which featured advanced AI-driven defence and strategic technology applications, highlighting the role of AI in national security and modernisation efforts.
He toured the Karnataka Pavilion and the ArtPark Pavilion, interacting with founders and teams from Karnataka’s innovation ecosystem and reviewing emerging AI and deep-tech solutions, the statement added.
