Facebook disclosed that attackers had exploited flaws in its ‘View As’ feature to steal access tokens, which let them take over user accounts. It was the largest security breach in the company’s history. The company said it had fixed the flaw and informed law enforcement.
What happened
- The attackers combined three separate bugs to obtain access tokens that kept users logged in.
- Facebook initially said almost 50 million accounts were affected and reset tokens for around 90 million.
- In October 2018 it said the attackers had obtained data from around 29 million accounts.
- In December 2024 Ireland’s Data Protection Commission fined Meta €251m over the breach.
Why it mattered
Coming months after Cambridge Analytica, the breach intensified scrutiny of Facebook and was one of the first major tests of GDPR breach rules. The DPC’s later decision focused on failures in breach notification and in building data protection into the platform’s design.
Lessons for organisations
Include security review in the design of new features, test how features interact, and be able to revoke sessions and tokens quickly when something goes wrong.
Sources: Meta, Data Protection Commission
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.