The Mercury News

Business: Facebook hackers accessed intimate details of millions of users.

New details show fewer people affected but depth of theft deeper than thought

- By Brian Fung The Washington Post

An online attack that forced Facebook to log out 90 million users last month directly affected 29 million people on the social network, the company said Friday as it released new details about the scope of an incident that has regulators and law enforcemen­t on high alert.

Through a series of interrelat­ed bugs in Facebook’s programmin­g, unnamed attackers stole the names and contact informatio­n of 15 million users, Facebook said. The contact informatio­n included a mix of phone numbers and email addresses.

An additional 14 million users were affected more deeply, by having additional details taken related to their profiles such as their recent

search history, gender, educationa­l background, geolocatio­n data, birth dates, and lists of people and pages they follow.

Facebook said last month that it detected the attack when it noticed an uptick in user activity. An investigat­ion soon found that the activity was linked to the theft of security codes that, under normal circumstan­ces, allow Facebook users to navigate away from the site while remaining logged in.

The bugs that allowed the attack to occur gave hackers the ability to effectivel­y take over Facebook accounts on a widespread basis, Facebook said when it disclosed the breach. The attackers began with a relatively small number of accounts that they directly controlled, exploiting flaws in the platform’s “View As” feature to gain access to other users’ profiles. (The “View As” feature is designed to allow users to view their own profiles as though they are somebody else.)

Facebook said it is cooperatin­g with federal and other authoritie­s on its investigat­ion, but said the FBI had advised the company not to discuss who may be behind the attack.

The 29 million affected users, along with 1 million whose security tokens were taken but did not appear to have their data stolen, will be receiving customized messages from Facebook identifyin­g specifical­ly which types of informatio­n on their profiles, if any, were involved in the breach. Facebook executives told reporters Friday that the company will also try to reach affected users who have since deleted their Facebook profiles.

Facebook has also establishe­d a web page that will inform users who are logged in whether their accounts were affected.

 ?? JOSH EDELSON — AGENCE FRANCE-PRESSE VIA GETTY IMAGES ?? Facebook said they noticed the data hack when they saw an uptick in user activity.
JOSH EDELSON — AGENCE FRANCE-PRESSE VIA GETTY IMAGES Facebook said they noticed the data hack when they saw an uptick in user activity.

Newspapers in English

Newspapers from United States