Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Cloud

10/12/2018
04:35 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Facebook Update: 30 Million Users Actually Hit in its Recent Breach

The good news: That number is less than the original estimate of 50 million. The bad news: It might not have been the only attack.

Facebook today confirmed the actual number of users hit in its recent data breach is 30 million rather than its original estimate of 50 million. 

The social media giant also is investigating other possible "smaller-scale attacks" leveraging the vulnerability in its code that was exploited in the breach, which it first reported late last month. The attackers already had control of a set of user accounts that were then connected to those users' Facebook friends.

"They used an automated technique to move from account to account so they could steal the access tokens of those friends, and for friends of those friends, and so on, totaling about 400,000 people," said Guy Rosen, vice president of product management for Facebook, in a post today.

This allowed the attackers to obtain Facebook profiles and see their timeline posts, lists of friends, groups, and names in recent Messenger chats. "Message content was not available to the attackers, with one exception. If a person in this group was a Page admin whose Page had received a message from someone on Facebook, the content of that message was available to the attackers," according to Facebook.

The FBI, which is investigating the attack, has asked the social media giant not to discuss who may be behind it.

Here's how the attack spread: The attackers used part of the 400,000 users' friends lists to steal tokens of 30 million people on Facebook. Some 15 million Facebook users' names, phone numbers, and email addresses were pilfered. For another 14 million users, their usernames and profile details – such as gender, relationship status, hometown, birthdate, city, and devices – as well as their 15 most recent searches from the platform also were stolen. That's in addition to their names, phone numbers, and email addresses.

The remaining 1 million Facebook members' information was not accessed in the attack.

'View As' Bug
Facebook last week announced that a previously unknown vulnerability in its code that existed between July 2017 and September 2018 had been exploited by attackers to steal Facebook access tokens, which could be used to hijack user accounts. Tokens are basically digital keys that allow users to remain logged into the social media platform without constantly signing in.

"The vulnerability was the result of a complex interaction of three distinct software bugs and it impacted "View As," a feature that lets people see what their own profiles look like to someone else," Rosen said.

Facebook discovered the attack on Sept. 25, after noticing unusual activity starting on Sept. 14. "Within two days, we closed the vulnerability, stopped the attack, and secured people's accounts by restoring the access tokens for people who were potentially exposed. As a precaution, we also turned off 'View As,'" Rosen said.

The company suggests Facebook users check the Help Center. It has already begun sending messages to affected victims about what information was stolen and how to protect themselves.

Note from author: While writing this story, I received a notice from Facebook today that I'm one of the breach victims: My name, email address, and phone number were accessed by the attackers.  

Related Content:

 

Black Hat Europe returns to London Dec 3-6 2018  with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the conference and to register.

Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
10 Ways to Keep a Rogue RasPi From Wrecking Your Network
Curtis Franklin Jr., Senior Editor at Dark Reading,  7/10/2019
The Security of Cloud Applications
Hillel Solow, CTO and Co-founder, Protego,  7/11/2019
Where Businesses Waste Endpoint Security Budgets
Kelly Sheridan, Staff Editor, Dark Reading,  7/15/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: "Jim, stop pretending you're drowning in tickets."
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-13360
PUBLISHED: 2019-07-16
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login process by leveraging knowledge of a valid username.
CVE-2019-13383
PUBLISHED: 2019-07-16
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, the Login process allows attackers to check whether a username is valid by reading the HTTP response.
CVE-2019-13603
PUBLISHED: 2019-07-16
An issue was discovered in the HID Global DigitalPersona (formerly Crossmatch) U.are.U 4500 Fingerprint Reader Windows Biometric Framework driver 5.0.0.5. It has a statically coded initialization vector to encrypt a user's fingerprint image, resulting in weak encryption of that. This, in combination...
CVE-2019-13605
PUBLISHED: 2019-07-16
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.838 to 0.9.8.846, remote attackers can bypass authentication in the login process by leveraging the knowledge of a valid username. The attacker must defeat an encoding that is not equivalent to base64, and thus this is different from CVE-2019-1...
CVE-2019-13615
PUBLISHED: 2019-07-16
VideoLAN VLC media player 3.0.7.1 has a heap-based buffer over-read in mkv::demux_sys_t::FreeUnused() in modules/demux/mkv/demux.cpp when called from mkv::Open in modules/demux/mkv/mkv.cpp.