Skip to main content
Breach Signal

Breach report

Social Media

Facebook (Meta)

Facebook Says Security Breach Affected Almost 50 Million Accounts

Attackers chained three bugs in Facebook's "View As" privacy tool to steal login tokens, eventually pulling personal data from 29 million accounts. Ireland later fined Meta €251 million over the incident.

Reported by NPR

Records exposed

29M

29 million users (initially estimated at nearly 50 million)

Scale vs. largest on file

When
2018
How they got in
Access token theft via chained bugs in the "View As" feature
Sector
Social Media

On September 28, 2018, Facebook disclosed that attackers had exploited a flaw in its code to steal access tokens, the digital keys that keep users logged in without re-entering a password. The company said nearly 50 million accounts were directly affected and reset tokens for another 40 million as a precaution, forcing roughly 90 million people to log back in.

The weakness sat in "View As," a privacy feature that lets people see how their profile appears to others. A combination of three separate bugs, introduced in July 2017 alongside a change to the video upload tool, caused the feature to generate an access token for the person being viewed rather than the viewer. Attackers began with accounts they controlled and hopped outward through friend networks, harvesting tokens automatically. Facebook said it spotted unusual activity in mid-September, fixed the flaw within days, and temporarily disabled View As.

In a follow-up in October 2018, Facebook narrowed the scope: attackers had actually taken data from about 29 million accounts. For roughly 15 million, the intruders accessed names and contact details such as phone numbers and email addresses. For about 14 million more, they also pulled a much richer set of information, including gender, relationship status, hometown, birthdate, education and work history, recent check-ins, and recent searches. Passwords and payment card data were not taken. Facebook worked with the FBI, which asked the company not to discuss who might be behind the attack.

The breach arrived just months after the Cambridge Analytica scandal and deepened concerns about the company's stewardship of user data. Lawmakers including Senator Mark Warner called for stronger privacy rules, and a US class action followed. Because the incident occurred after the EU's General Data Protection Regulation took effect, Ireland's Data Protection Commission opened an inquiry; in December 2024 it fined Meta €251 million for failures in breach notification and in building data protection into its systems.

The incident is often cited as a case study in how session tokens can be more valuable to attackers than passwords, since they bypass login protections including two-factor authentication. It also showed how a seemingly minor feature can become a skeleton key when code changes interact in unexpected ways, and why large platforms need rigorous security review of features that touch authentication.

More from the wire

More in Social Media.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.