Don’t do SECURITY. Do business SECURELY.

Facebook ‘View As’ flaw lets attackers steal account access tokens

Facebook said attackers exploited its 'View As' feature to steal access tokens, later putting the number affected at 29 million.

Facebook disclosed that attackers had exploited flaws in its ‘View As’ feature to steal access tokens, which let them take over user accounts. It was the largest security breach in the company’s history. The company said it had fixed the flaw and informed law enforcement.

What happened

  • The attackers combined three separate bugs to obtain access tokens that kept users logged in.
  • Facebook initially said almost 50 million accounts were affected and reset tokens for around 90 million.
  • In October 2018 it said the attackers had obtained data from around 29 million accounts.
  • In December 2024 Ireland’s Data Protection Commission fined Meta €251m over the breach.

Why it mattered

Coming months after Cambridge Analytica, the breach intensified scrutiny of Facebook and was one of the first major tests of GDPR breach rules. The DPC’s later decision focused on failures in breach notification and in building data protection into the platform’s design.

Lessons for organisations

Include security review in the design of new features, test how features interact, and be able to revoke sessions and tokens quickly when something goes wrong.

Sources: Meta, Data Protection Commission

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights