Facebook got hit hard by a currently unknown group of hackers. If you recently found yourself inexplicably logged out of the social media site, Facebook did it in response to the breach.
The breach resulted in the theft of data pertaining to more than fifty million of the site’s users.
Here’s what we know so far about the attack:
The hackers pulled off their heist by taking advantage of three different vulnerabilities.
Facebook detected the breach after spotting an unusual spike in traffic.
Your password has not been compromised, but unfortunately, the hackers don’t need it.
The hackers stole more than fifty million access tokens. These tokens can be used to take over Facebook accounts without passwords, even if you have two-factor authentication enabled.
If you were in the compromised group, the hackers have every scrap of personal information you’ve entered into the social media site.
If you use the “Logged in as Facebook” feature on other websites, those accounts are also at risk. The hackers can use the stolen tokens to access any site you log into with your Facebook credentials.
The reason you got logged out was because Facebook reset access tokens for everyone they suspected may have had their data stolen.
To find out if you’ve been hacked, you can check “Active Sessions” on Facebook. If you see an unknown IP address, or a location in some other country, that’s a sure sign that you’ve been hacked.
This breach is not connected in any way to the hacker who pledged to delete Mark Zuckerberg’s personal Facebook page.
In addition to that, you should know that Facebook is now facing a class-action lawsuit over the hack. The suit alleges that the company failed to protect their personal data from falling into the wrong hands due to the company’s lack of proper security practices.
While the vulnerabilities have been fixed, the class-action lawsuit has a good chance of succeeding. The investigation is still in its early stages, and there may be updates to this story as we learn more.
President & CEO
I hope you enjoyed this article. My mission is to take your stress away from dealing with IT problems. Call (252) 565-1235 or send me a message at our contact us page if you have a question, comment or want help.
Jose Rodriguez, a Spanish Apple enthusiast, has discovered a new security flaw to be aware of. He posted a Proof of Concept video showing the exploit in action.
Symantec’s most recent statistics have revealed a disturbing trend. Malware designed to compromise checkout pages is seeing a big spike in use, with the company reporting a staggering 248,000 attempts since August 13th of this year, with more than a third of them (36 percent) between September 13th through September 20th. As disturbing as those numbers are, that’s just the tip of the iceberg.
According to this year’s Traveler’s Risk Index, published by The Traveler’s Indemnity Company, a majority of business owners have a somewhat fatalistic view of hacking and data breaches.
Firefox is upping the ante where digital security is concerned, having just announced the release of a new, free service called ‘Firefox Monitor.’ The new service is designed with one specific goal in mind: To assist users in finding out if their accounts were exposed via a data breach.
If you use the GovPayNet portal, be advised that your personal information is currently at risk. Although at this point, there’s no indication that any hacker has made use of it. The portal is run by Government Payment Service, and is used by many Americans to pay fines, fees and bills generated by more than two thousand different government agencies operating in 35 states.
A new piece of legislation is making its way through the halls of Congress that could standardize and streamline the data security and breach notification process for financial institutions. This is something that most people in the industry tout as an improvement over the current situation.
Users of Apple tech have a new reason to worry. A security researcher named Sabri Haddouche, who works for an instant messaging app called “Wire,” has published a proof of concept web page. It contains a fatal exploit that can crash and restart iPhones, iPads and any Mac.
Western Digital has a big problem, and if you use the company’s “My Cloud” network-attached storage (NAS) storage devices, you’ve got one too. The WD My Cloud service is enormously popular because it’s so convenient, allowing both business owners and individuals to store their files, perform periodic backups, and of course, access their data from anywhere in the world.
We’ve known for some time now that the next big crisis the internet will have to come to grips with is the dramatic rise of the Internet of Things (IOT).