Facebook got hit hard by a currently unknown group of hackers. If you recently found yourself inexplicably logged out of the social media site, Facebook did it in response to the breach.
The breach resulted in the theft of data pertaining to more than fifty million of the site’s users.
Here’s what we know so far about the attack:
The hackers pulled off their heist by taking advantage of three different vulnerabilities.
Facebook detected the breach after spotting an unusual spike in traffic.
Your password has not been compromised, but unfortunately, the hackers don’t need it.
The hackers stole more than fifty million access tokens. These tokens can be used to take over Facebook accounts without passwords, even if you have two-factor authentication enabled.
If you were in the compromised group, the hackers have every scrap of personal information you’ve entered into the social media site.
If you use the “Logged in as Facebook” feature on other websites, those accounts are also at risk. The hackers can use the stolen tokens to access any site you log into with your Facebook credentials.
The reason you got logged out was because Facebook reset access tokens for everyone they suspected may have had their data stolen.
To find out if you’ve been hacked, you can check “Active Sessions” on Facebook. If you see an unknown IP address, or a location in some other country, that’s a sure sign that you’ve been hacked.
This breach is not connected in any way to the hacker who pledged to delete Mark Zuckerberg’s personal Facebook page.
In addition to that, you should know that Facebook is now facing a class-action lawsuit over the hack. The suit alleges that the company failed to protect their personal data from falling into the wrong hands due to the company’s lack of proper security practices.
While the vulnerabilities have been fixed, the class-action lawsuit has a good chance of succeeding. The investigation is still in its early stages, and there may be updates to this story as we learn more.
President & CEO
I hope you enjoyed this article. My mission is to take your stress away from dealing with IT problems. Call (252) 565-1235 or send me a message at our contact us page if you have a question, comment or want help.
Jose Rodriguez, a Spanish Apple enthusiast, has discovered a new security flaw to be aware of. He posted a Proof of Concept video showing the exploit in action.
Change is coming to the way Microsoft handles search across its ecosystem. If you use the home edition of Office, you’re not likely to notice, but if you use Office 365, the changes will be significant.
If you’re one of the relatively few people who use Google+ in something other than an Enterprise setting, be advised that the clock is ticking. Google has just announced that they’re sunsetting the service. It will be going offline for consumers at some point over the next ten months.
Symantec’s most recent statistics have revealed a disturbing trend. Malware designed to compromise checkout pages is seeing a big spike in use, with the company reporting a staggering 248,000 attempts since August 13th of this year, with more than a third of them (36 percent) between September 13th through September 20th. As disturbing as those numbers are, that’s just the tip of the iceberg.
According to this year’s Traveler’s Risk Index, published by The Traveler’s Indemnity Company, a majority of business owners have a somewhat fatalistic view of hacking and data breaches.
Firefox is upping the ante where digital security is concerned, having just announced the release of a new, free service called ‘Firefox Monitor.’ The new service is designed with one specific goal in mind: To assist users in finding out if their accounts were exposed via a data breach.
Windows 10 is far and away the fastest growing version of the OS in the company’s history. It recently hit an installation base of a staggering 700 million devices after about three years on the market.
If you use the GovPayNet portal, be advised that your personal information is currently at risk. Although at this point, there’s no indication that any hacker has made use of it. The portal is run by Government Payment Service, and is used by many Americans to pay fines, fees and bills generated by more than two thousand different government agencies operating in 35 states.
Google is making a small but pivotal change as it relates to calls placed to 911 operators. Having recently finalized a complex partnership with RapidSOS and West (two emergency technology companies) and T-Mobile, Google will now send location data from its “Emergency Location Service” when an Android user places a 911 call.