San Francisco, Sep 28 : In the biggest-ever security breach after Cambridge Analytica scandal, Facebook on Friday admitted hackers broke into nearly 50 million users' accounts by stealing their "access tokens" or digital keys.

This allowed them to steal Facebook access tokens which they could then use to take over people's accounts, Facebook said in a statement.

Access tokens are the equivalent of digital keys that keep people logged in to Facebook so they do not need to re-enter their password every time they use the app.

"Our investigation is still in its early stages. But it's clear that attackers exploited a vulnerability in Facebook's code that impacted 'View As', a feature that lets people see what their own profile looks like to someone else," said Guy Rosen, VP of Product Management.

Facebook security team discovered the security issue on September 25, and it has now fixed the vulnerability and informed the law enforcement.

"We have reset the access tokens of the almost 50 million accounts we know were affected to protect their security.

"We're also taking the precautionary step of resetting access tokens for another 40 million accounts that have been subject to a 'View As' look-up in the last year," Facebook said.

As a result, around 90 million people will now have to log back into Facebook, or any of their apps that use Facebook login.

After they have logged back in, people will get a notification at the top of their News Feed explaining what happened.

"We're temporarily turning off the 'View As' feature while we conduct a thorough security review," Facebook said.

This attack exploited the complex interaction of multiple issues in Facebook code.

"The attackers not only needed to find this vulnerability and use it to get an access token, they then had to pivot from that account to others to steal more tokens," it said.

Facebook said it does not know who is behind this massive security attack.

"We're working hard to better understand these details and "we will update this post when we have more information, or if the facts change," said the company.

In the Cambridge Analytica scandal, data of nearly 87 million people was breached upon.


Let the Truth be known. If you read VB and like VB, please be a VB Supporter and Help us deliver the Truth to one and all.



Madikeri (Karnataka) (PTI): Four people were arrested for allegedly assaulting, illegally confining and attempting to extort money from a 39-year-old businessman who was lured through a honeytrap set up on social media, police said on Monday.

The accused have been identified as Rachana, Malati, Darshan and Ravi.

Police said efforts are underway to nab the remaining suspects involved in the incident, which occurred on December 12 in Madikeri, the district headquarters of Kodagu.

According to the complaint, the victim, a resident of Maddur taluk in Mandya district, was befriended by a woman identified as Rachana through Facebook, who later sought financial assistance and received Rs 5,000 from him via PhonePe on November 28.

When he asked her to return the money, the woman allegedly asked him to travel to Mysuru or Kushalnagar, promising to meet him.

The police said the woman later called the victim to Madikeri on December 12 and took him to a house near the market area, where they spent some time and consumed alcohol in the evening.

ALSO READ: Private bus from Kerala gutted on the streets in South Kodagu; no fatality reported

Later that night, citing an emergency, the woman left the house. After her departure, three men allegedly broke into the house and attacked the victim, assaulting him with a stick and the handle of a sword, causing injuries to his face, mouth, chest and leg, the FIR stated.

The complainant alleged that he was forcibly confined, stripped and a nude video of him was recorded. The accused also allegedly threatened him with a toy gun, demanding Rs 50 lakh and warning that the video would be uploaded on social media if the money was not paid.

Police said the victim was held captive and somehow managed to escape in the early hours of December 13. However, after he escaped, the accused allegedly attempted to kidnap him in an autorickshaw, an incident that was captured on CCTV cameras.

Based on his complaint at the Madikeri Town police station, a case was registered under Sections 310(2) (dacoity), 127(2) (wrongful confinement), 118(1) (voluntarily causing hurt or grievous hurt by dangerous weapons or means) and 3(5) (common intention) of the Bharatiya Nyaya Sanhita, a senior police officer said.

“Four accused, including two women, have been arrested. Efforts are on to nab two more absconding accused. Further investigation is on,” he added.