The Denver Post

50M user accounts affected by security breach

- By Matt O’Brien and Mae Anderson

NEW YORK» Facebook reported a major security breach in which 50 million user accounts were accessed by unknown attackers.

The attackers gained the ability to “seize control” of those accounts, Facebook said, by stealing digital keys the company uses to keep people logged in. Facebook has logged out owners of the 50 million affected accounts — plus another 40 million who were vulnerable to the attack. Users don’t need to change their Facebook passwords, the company said.

Facebook said it doesn’t know who was behind the attacks or where they’re based. In a conference call with reporters on Friday, CEO Mark Zuckerberg said attackers would have had the ability to view private messages or post on someone’s account, but there’s no sign that they did.

“We do not yet know if any of the accounts were actually misused,” Zuckerberg said.

Facebook shares fell $4.38, or 2.6 percent, and closed at $164.46 on Friday.

The hack is the latest setback for Facebook during a tumultuous year of security problems and privacy issues. So far, though, none of that has significan­tly shak en the confidence of the company’s 2 billion global users.

The latest attack involved bugs in Facebook’s “View As” feature, which lets people see how their profiles appear to others. The attackers used that vulnerabil­ity to steal the digital keys, known as “access tokens,” from the accounts of people whose profiles were plugged into the “View As” feature — and then moved along from one user’s Facebook friend to another. Possession of those tokens would allow attackers to control those accounts.

Facebook confirmed late Friday that thirdparty apps, including its own Instagram app, could have been affected.

Newspapers in English

Newspapers from United States