{"id":4523,"date":"2018-10-01T11:34:18","date_gmt":"2018-10-01T07:34:18","guid":{"rendered":"http:\/\/www.uaebarq.ae\/en\/?p=4523"},"modified":"2018-10-01T11:34:18","modified_gmt":"2018-10-01T07:34:18","slug":"facebook-security-breach-exposed-50-million-accounts-to-attackers","status":"publish","type":"post","link":"https:\/\/www.uaebarq.ae\/en\/2018\/10\/01\/facebook-security-breach-exposed-50-million-accounts-to-attackers\/","title":{"rendered":"Facebook security breach exposed 50 million accounts to attackers"},"content":{"rendered":"<p>Fifty million Facebook users have been exposed to ID fraud after the biggest cyber attack on the social media giant in its history.<\/p>\n<p>The company revealed that hackers were able to access accounts on an unprecedented scale due to a security hole that had remained open for more than a year.<\/p>\n<p>Facebook said it had alerted the FBI over the breach, and security experts said\u00a0a rogue state such as Russia may have been responsible.<\/p>\n<p>The cyber defence arm of GCHQ said it was investigating the hack, which allowed attackers full access to private Facebook profiles, and advised British users to be on the lookout for fraud.<\/p>\n<p>Facebook was facing questions about why it had taken almost two weeks to shut the security hole after noticing \u201cunusual traffic\u201d on its systems in mid-September.<\/p>\n<p>The breach is the latest privacy embarrassment for\u00a0Facebook, which earlier this year acknowledged that\u00a0tens of millions of users had personal data hijacked by Cambridge Analytica, a political firm working for Donald Trump in 2016.<\/p>\n<p>Facebook said a change to its systems in July of last year had allowed hackers to steal \u201ctokens\u201d &#8211; digital keys that let users access Facebook without entering their password &#8211; from 50 million accounts.<\/p>\n<div class=\"articleBodyText section\">\n<div class=\"article-body-text component  \">\n<div class=\"component-content\">\n<p><span class=\"m_first-letter m_first-letter--flagged\">S<\/span>tealing the tokens let the hackers take over accounts, letting them see photos, messages and other private information.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"articleBodyText section\">\n<div class=\"article-body-text component  \">\n<div class=\"component-content\">\n<p><span class=\"m_first-letter m_first-letter--flagged\">F<\/span>acebook executives held two crisis press conferences on Friday after revealing that it had called in the FBI when it realised it had fallen victim to a \u201cmajor\u201d attack.<\/p>\n<p>It admitted that hackers would be able to access any third party apps or websites a user logged into with Facebook. It said that linked Instagram accounts were affected but that WhatsApp, which it also owns, was not compromised.<\/p>\n<p>Facebook&#8217;s Guy Rosen said it was unclear who was behind the attack, but that it was &#8220;broad&#8221;, suggesting it could be the work of an organised group.<\/p>\n<p>David Atkinson, the chief executive of cyber security company Senseon, said the details \u201cindicate that this hacker is toward the sophisticated end of the spectrum\u201d and that it had the hallmarks of a nation state attack.<\/p>\n<p>It comes just weeks\u00a0before the crucial US midterm elections, which Russian agents have been trying to disrupt through fake news campaigns.<\/p>\n<p>\u201cFacebook is a big target for nation states and given the proximity to the mid term elections in the US, this could be a gift for hackers,\u201d Mr Atkinson said. \u201cLet\u2019s be under no illusions, Facebook as a source of intelligence for foreign states has already been proven.\u201d<\/p>\n<div class=\"articleBodyText section\">\n<div class=\"article-body-text component  \">\n<div class=\"component-content\">\n<p><span class=\"m_first-letter m_first-letter--flagged\">A<\/span>\u00a0spokesman for the National Cyber Security Centre, the division of GCHQ responsible for cyber defence, said: \u201cWe are investigating how this breach has affected people in the UK and advise on appropriate mitigation measures.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"articleBodyText section\">\n<div class=\"article-body-text component  \">\n<div class=\"component-content\">\n<p>\u201cThere is no evidence that people have to take action such as changing their passwords or deleting their profiles. However, users should be particularly vigilant to possible phishing attacks, as if data has been accessed it could be used to make scam messages more credible.\u201d<\/p>\n<p><span class=\"m_first-letter\">U<\/span>nder recently-introduced European data laws, Facebook could face a fine of billions of pounds if it is found to have been irresponsible with users\u2019 personal information. The Irish Data Protection Commissioner (DPC), Facebook\u2019s key regulator in Europe,\u00a0criticised the company for being vague about the attack.<\/p>\n<p>\u201cThe DPC has received a preliminary notification from Facebook Ireland. However, the notification lacks detail and the DPC is concerned at the fact that this breach was discovered on Tuesday and affects many millions of user accounts but Facebook is unable to clarify the nature of the breach and the risk for users at this point,\u201d a spokesman said.<\/p>\n<p>\u201cThe DPC continues to press Facebook to clarify these matters further as a matter of urgency.\u201d<\/p>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"articleBodyText section\">\n<div class=\"article-body-text component  \">\n<div class=\"component-content\">\n<p><span class=\"m_first-letter m_first-letter--flagged\">F<\/span>acebook\u2019s chief executive Mark Zuckerberg said the flaw stemmed from a glitch in a video feature added in July 2017 which allowed users to upload happy birthday videos. This left a vulnerability in another feature, \u201cView As\u201d, which allows users to check what their profile appears like to their friends.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"articleBodyText section\">\n<div class=\"article-body-text component  \">\n<div class=\"component-content\">\n<p><span class=\"m_first-letter m_first-letter--flagged\">F<\/span>acebook has reset the login details of 90 million users, closing the loophole. In addition to the almost 50 million users affected by the attack, it logged an extra 40 million people out of their accounts, whose accounts had been accessed by the \u201cView As\u201d feature, as a security precaution.<\/p>\n<p>Facebook has more than 2.2 billion monthly users around the world, and 40 million in the UK.<\/p>\n<p>It spotted the attack when it received a large amount of traffic to its servers on September 16. Its security team confirmed the flaw on September 25 and the bug was fixed on Thursday.<\/p>\n<p>Democratic US Senator Mark Warner cited the breach as further proof of the privacy danger of companies such as\u00a0Facebook\u00a0and Equifax not adequately protecting the massive amounts of information they gather about people.<\/p>\n<p>&#8220;This is another sobering indicator that Congress needs to step up and take action to protect the privacy and security of social media users,&#8221; Warner said in a statement.<\/p>\n<p>&#8220;As I&#8217;ve said before &#8211; the era of the Wild West in social media is over.&#8221;<\/p>\n<p>&#8211;<\/p>\n<p>Telegraph<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Fifty million Facebook users have been exposed to ID fraud after the biggest cyber attack on the social media giant in its history. The company revealed that hackers were able to access accounts on an unprecedented scale due to a security hole that had remained open for more than a year. Facebook said it had &hellip;<\/p>\n","protected":false},"author":2,"featured_media":4525,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[],"class_list":["post-4523","post","type-post","status-publish","format-standard","has-post-thumbnail","","category-tech"],"_links":{"self":[{"href":"https:\/\/www.uaebarq.ae\/en\/wp-json\/wp\/v2\/posts\/4523","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.uaebarq.ae\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.uaebarq.ae\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.uaebarq.ae\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.uaebarq.ae\/en\/wp-json\/wp\/v2\/comments?post=4523"}],"version-history":[{"count":1,"href":"https:\/\/www.uaebarq.ae\/en\/wp-json\/wp\/v2\/posts\/4523\/revisions"}],"predecessor-version":[{"id":4529,"href":"https:\/\/www.uaebarq.ae\/en\/wp-json\/wp\/v2\/posts\/4523\/revisions\/4529"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.uaebarq.ae\/en\/wp-json\/wp\/v2\/media\/4525"}],"wp:attachment":[{"href":"https:\/\/www.uaebarq.ae\/en\/wp-json\/wp\/v2\/media?parent=4523"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.uaebarq.ae\/en\/wp-json\/wp\/v2\/categories?post=4523"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.uaebarq.ae\/en\/wp-json\/wp\/v2\/tags?post=4523"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}