San Francisco, Sep 28 : In the biggest-ever security breach after Cambridge Analytica scandal, Facebook on Friday admitted hackers broke into nearly 50 million users' accounts by stealing their "access tokens" or digital keys.

This allowed them to steal Facebook access tokens which they could then use to take over people's accounts, Facebook said in a statement.

Access tokens are the equivalent of digital keys that keep people logged in to Facebook so they do not need to re-enter their password every time they use the app.

"Our investigation is still in its early stages. But it's clear that attackers exploited a vulnerability in Facebook's code that impacted 'View As', a feature that lets people see what their own profile looks like to someone else," said Guy Rosen, VP of Product Management.

Facebook security team discovered the security issue on September 25, and it has now fixed the vulnerability and informed the law enforcement.

"We have reset the access tokens of the almost 50 million accounts we know were affected to protect their security.

"We're also taking the precautionary step of resetting access tokens for another 40 million accounts that have been subject to a 'View As' look-up in the last year," Facebook said.

As a result, around 90 million people will now have to log back into Facebook, or any of their apps that use Facebook login.

After they have logged back in, people will get a notification at the top of their News Feed explaining what happened.

"We're temporarily turning off the 'View As' feature while we conduct a thorough security review," Facebook said.

This attack exploited the complex interaction of multiple issues in Facebook code.

"The attackers not only needed to find this vulnerability and use it to get an access token, they then had to pivot from that account to others to steal more tokens," it said.

Facebook said it does not know who is behind this massive security attack.

"We're working hard to better understand these details and "we will update this post when we have more information, or if the facts change," said the company.

In the Cambridge Analytica scandal, data of nearly 87 million people was breached upon.


Let the Truth be known. If you read VB and like VB, please be a VB Supporter and Help us deliver the Truth to one and all.



Karachi (PTI): A preliminary report over the recent explosion near Pakistan's busiest airport here has indicated that the attack was executed with the assistance of a foreign intelligence agency, a media report said on Saturday.

The report, submitted by the Counter-Terrorism Department (CTD) to the anti-terrorism court, stated that the suicide bombing targeted Chinese engineers as part of a conspiracy to damage Pakistan-China relations, The Express Tribune reported.

On Sunday, two Chinese nationals were killed and 17 people injured in the suicide attack by a Baloch insurgent group that targeted a convoy of Chinese workers.

The explosion near the Jinnah International Airport on Sunday night also killed the suspected suicide bomber.

The preliminary report identified the Balochistan Liberation Army (BLA) as being involved in the attack and indicated that the attack was executed with the assistance of a foreign intelligence agency, the Tribune said.

It suggested that an unidentified terrorist parked their vehicle close to a convoy of Chinese nationals before detonating the explosive, the report said.

Upon hearing the blast, police arrived at the scene and found injured individuals, including personnel from police and Rangers.

The Chinese nationals were working at the Port Qasim Electric Power Company on the outskirts of the city and were returning home when their convoy was attacked.

A case has been registered at the Airport police station under the supervision of the station house officer.

The CTD’s report includes charges of murder, attempted murder, assault, use of explosive materials, and terrorism, among other counts.

Earlier this week, an initial investigation report confirmed the tragic event involved 70 to 80 kg of explosives.

On Friday, China said it has dispatched an inter-agency working group to Pakistan following the deadly suicide bomb attack in Karachi.

Thousands of Chinese personnel are working in Pakistan on several projects under the aegis of the USD 60 billion China-Pakistan Economic Corridor (CPEC).

Balochistan, bordering Iran and Afghanistan, is home to a long-running violent insurgency. Baloch insurgent groups have previously carried out several attacks targeting CPEC projects.

The BLA accuses China and Islamabad of exploitation of the resource-rich province, a charge rejected by the authorities. It has fought a long-running insurgency for a separate homeland.

The group in the last two years carried out similar suicide bomb attacks in Karachi targeting foreign nationals.



All Stories