Skip to content
Search

Latest Stories

Up to 50 million Facebook accounts breached in attack

Facebook revealed on Friday (28) that up to 50 million accounts were breached by hackers, dealing a blow to the social network's effort to convince users to trust it with their data.

The social network is investigating the extent of harm done when hackers exploited a trio of software flaws to steal "access tokens," the equivalent of digital keys that enable people to automatically log back into the social network.


Facebook chief executive Mark Zuckerberg said engineers discovered the breach on Tuesday(25), and patched it on Thursday (27) night.

"We don't know if any accounts were actually misused," Zuckerberg said. "This is a serious issue."

As a precaution, Facebook is temporarily taking down the "view as" feature - described as a privacy tool to let users see how their profiles look to other people.

"It's clear that attackers exploited a vulnerability in Facebook's code," said vice president of product management Guy Rosen.

"We've fixed the vulnerability and informed law enforcement."

Facebook reset the 50 million breached accounts, meaning users will need to sign back in using passwords.

Democratic US Senator Mark Warner cited the breach as further proof of the privacy danger of companies such as Facebook and Equifax not adequately protecting the massive amounts of information they gather about people.

"This is another sobering indicator that Congress needs to step up and take action to protect the privacy and security of social media users," Warner said in a statement.

"As I've said before - the era of the Wild West in social media is over."

The breach is the latest privacy embarrassment for Facebook, which earlier this year acknowledged that tens of millions of users had personal data hijacked by Cambridge Analytica, a political firm working for Donald Trump in 2016.

"We face constant attacks from people who want to take over accounts or steal information around the world," Zuckerberg said on his Facebook page.

"While I'm glad we found this, fixed the vulnerability, and secured the accounts that may be at risk, the reality is we need to continue developing new tools to prevent this from happening in the first place."

Facebook said it took a precautionary step of resetting "access tokens" for another 40 million accounts where the "view as" was used. This will require those users to log back into Facebook.

"People's privacy and security is incredibly important, and we're sorry this happened," Rosen said.

- Sophisticated hack -

No passwords were taken in the breach, only "tokens," according to Rosen.

Information hackers appeared interested in included names, genders, and home towns, but it was not clear for what purposes, the executives said in a telephone briefing.

The stolen tokens gave hackers complete control of accounts. Facebook is trying to determine whether hackers tampered with posts or messages.

Hackers could have also gotten into third-party applications linked to Facebook accounts, but it was too early to determine whether that happened, according to the social network.

Attackers would have been able to meddle with Instagram accounts lined to Facebook, but could not have tampered with the social network's WhatsApp messaging service, according to executives.

Facebook said that it noticed an unusual spike in activity on September 16 and determined nine days later that it was malicious.

Hackers took advantage of a "complex interaction" between three software bugs, which required a degree of sophistication, according to Rosen. The vulnerability was created by a change to a video uploading feature in July of 2017.

"We may never know who is behind this," Rosen said. "This is not an easy investigation."

The 50 million figure was the total number of accounts Facebook determined were breached by the attack since July of last year, but the social network did not disclose the earliest incursion.

Facebook is working with data privacy regulators as well as law enforcement, according to Rosen.

Facebook this year is doubling to 20,000 the number of workers devoted to safety and security.

When asked why people should still trust Facebook with their personal information, Zuckerberg outlined anew ways the social network is ramping up defenses.

"As I've said a number of times, security is an arms race," Zuckerberg said.

But Facebook may have deeper problems, said Jonathan Zittrain, a Harvard law professor and co-founder of university's Berkman Klein Center for Internet & Society.

"There is a structural problem here," Zittrain said in a tweet.

"Facebook has one of the best and most well-resourced cybersecurity outfits in the world, yet a breach of its servers appears to have compromised tens of millions of accounts in still-undisclosed ways."

(AFP)

More For You

Nepal’s new leader pledges to act on Gen Z calls to end corruption

Officials greet newly-elected Prime Minister of Nepal's interim government Sushila Karki (R) as she arrives at the prime minister's office in Kathmandu on September 14, 2025. (Photo by PRABIN RANABHAT/AFP via Getty Images)

Nepal’s new leader pledges to act on Gen Z calls to end corruption

NEPAL’s new interim prime minister Sushila Karki on Sunday (14) pledged to act on protesters’ calls to end corruption and restore trust in government, as the country struggles with the aftermath of its worst political unrest in decades.

“We have to work according to the thinking of the Gen Z generation,” Karki said in her first address to the nation since taking office on Friday (12). “What this group is demanding is the end of corruption, good governance and economic equality. We will not stay here more than six months in any situation. We will complete our responsibilities and hand over to the next parliament and ministers.”

Keep ReadingShow less
UK secures £1.25bn US investment ahead of Trump’s visit

US president Donald Trump and UK prime minister Sir Keir Starmer arrive at Trump International Golf Links on July 28, 2025 in Balmedie, Scotland. (Photo by Jane Barlow-WPA Pool/Getty Images)

UK secures £1.25bn US investment ahead of Trump’s visit

THE British government has announced over £1.25 billion ($1.69bn) in fresh investment from major US financial firms, including PayPal, Bank of America, Citigroup and S&P Global, ahead of a state visit by president Donald Trump.

The investment is expected to create 1,800 jobs across London, Edinburgh, Belfast and Manchester, and deepen transatlantic financial ties, the Department for Business and Trade said.

Keep ReadingShow less
Nearly 150,000 join anti-migrant protest in London as clashes erupt

Protesters wave Union Jack and St George's England flags during the "Unite The Kingdom" rally on Westminster Bridge by the Houses of Parliament on September 13, 2025 in London, England. (Photo by Christopher Furlong/Getty Images)

Nearly 150,000 join anti-migrant protest in London as clashes erupt

MORE THAN 100,000 protesters marched through central London on Saturday (13), carrying flags of England and Britain and scuffling with police in one of the UK's biggest right-wing demonstrations of modern times.

London's Metropolitan Police said the "Unite the Kingdom" march, organised by anti-immigrant activist Tommy Robinson, was attended by nearly 150,000 people, who were kept apart from a "Stand Up to Racism" counter-protest attended by around 5,000.

Keep ReadingShow less
Piyush Goyal

Piyush Goyal recalled that in February, Narendra Modi and Donald Trump had instructed their trade ministers to conclude the first phase of the bilateral trade agreement (BTA) by November 2025. (Photo: Getty Images)

Getty Images

Trade talks with US moving forward positively, says Indian minister Goyal

INDIA’s commerce and industry minister Piyush Goyal on Thursday said that negotiations on the proposed trade agreement between India and the United States, which began in March, are progressing in a positive atmosphere and both sides are satisfied with the discussions.

He recalled that in February, Indian prime minister Narendra Modi and US president Donald Trump had instructed their trade ministers to conclude the first phase of the bilateral trade agreement (BTA) by November 2025.

Keep ReadingShow less
West Midlands Police

West Midlands Police said they were called just before 08:30 BST on Tuesday, September 9, after the woman reported being attacked by two men near Tame Road. (Representational image: iStock)

Woman raped in racially aggravated attack in Oldbury

A WOMAN in her 20s was raped in Oldbury in what police are treating as a racially aggravated attack.

West Midlands Police said they were called just before 08:30 BST on Tuesday, September 9, after the woman reported being attacked by two men near Tame Road. Officers said the men made a racist remark during the incident.

Keep ReadingShow less