Facebook Stored Hundreds of Millions Passwords in Plain Text, Thousands of Employees Had Access

Facebook today announced that during a routine security review it discovered "some user passwords" were stored in a readable format within its internal data storage systems, accessible by employees.

As it turns out, "some user passwords" actually means hundreds of millions of passwords. A Facebook insider told KrebsOnSecurity that between 200 and 600 million Facebook users may have had their account passwords stored in plain text in a database accessible to 20,000 Facebook employees. Some Instagram passwords were also included, and Facebook claims many of the passwords came from Facebook Lite users.


Facebook says that there's no "evidence to date" that anyone within Facebook abused or improperly accessed the passwords, but KrebsOnSecurity's source says 2,000 engineers or developers made around nine million internal queries for data elements that contained plain text user passwords.

Facebook employees reportedly built applications that logged unencrypted password data, which is how the passwords were exposed. Facebook hasn't determined exactly how many passwords were stored in plain text, nor how long they were visible.

Facebook plans to notify users whose passwords were improperly stored, and the company says that it has been looking at the ways certain categories of information, such as access tokens, are stored, and correcting problems as they're found.

"There is nothing more important to us than protecting people's information, and we will continue making improvements as part of our ongoing security efforts at Facebook," reads Facebook's blog post.

Facebook and Instagram users who are concerned about their account security should change their passwords, using unique passwords that are different from passwords used on other sites. Facebook also recommends users enable two-factor authentication.

Top Rated Comments

(View all)
Avatar
17 months ago
Delete Facebook and delete your accounts
Score: 104 Votes (Like | Disagree)
Avatar
17 months ago
How is this company not being criminally prosecuted?
Score: 84 Votes (Like | Disagree)
Avatar
17 months ago
While many are saying "is anyone surprised" I actually am at this.

This is one of the largest corporations in the world, whose sole business is its internet applications, and they ignored one of the most basic security expectations of hashing a password?

That is absolutely surprising and shameful and there is no excuse from them that is acceptable.
Score: 47 Votes (Like | Disagree)
Avatar
17 months ago
Consider my mind blown.

Score: 35 Votes (Like | Disagree)
Avatar
17 months ago
I'm shocked at Facebook's lack of security!
Said nobody.
Score: 34 Votes (Like | Disagree)
Avatar
17 months ago
Disgusting.


Use privacy enhancing tech or pay the price, in future privacy will be currency.

* GPG
* Veracrypt
* Monero
* VPN
* DuckDuckGo
* Pi.hole
Score: 31 Votes (Like | Disagree)

Top Stories

Apple Warns Against Closing MacBooks With a Cover Over the Camera

Friday July 10, 2020 11:12 am PDT by
Apple this month published a support document that warns customers against closing their Mac notebooks with a cover over the camera as it can lead to display damage. Image via Reddit Apple says that the clearance between the display and the keyboard is designed to very tight tolerances, which can be problematic. Covering the camera can also cause issues with automatic brightness and True Tone....

iPhone Users Who Experienced 'Batterygate' Can Now File to Receive Around $25 Settlement From Apple

Monday July 13, 2020 6:50 am PDT by
Earlier this year, Apple agreed to settle a U.S. class action lawsuit that accused the company of "secretly throttling" older iPhone models. Now, eligible iPhone owners are beginning to be notified about their legal rights and options. Under the proposed settlement, Apple will provide a cash payment of approximately $25 to each eligible iPhone owner who submits a claim, with its total payout ...

Possible 'iPhone 12' Battery Certifications Suggest Lower Capacities Than iPhone 11 Series

Monday July 13, 2020 4:22 am PDT by
MySmartPrice has spotted certifications for three new Apple batteries that it believes could be for the upcoming iPhone 12 lineup, despite them being less capacitive than the batteries in the current iPhone 11 series. The batteries are identified with the model numbers A2471, A2431, and A2466, and appear on Safety Korea, China's 3C, and the Danish agency UL Demko. Apple is expected to...

Google to 'Dramatically' Improve Chrome Impact on Mac Battery Life

Sunday July 12, 2020 1:56 pm PDT by
Google will address long-standing battery life issues, particularly on Mac devices, reports The Wall Street Journal. Chrome will improve "tab throttling" by better prioritizing active tabs and limiting resource drain from tabs open in the background. This is said to have a "dramatic impact on battery and performance." Google has reportedly been performing early tests on Mac laptops in...

Arm-Intel-PowerPC Universal Binaries Are Possible

Saturday July 11, 2020 1:42 pm PDT by
Casual MacRumors visitors may not realize that we have a very active PowerPC forum where users discuss issues related to PowerPC Macs that have not been produced since 2006. Threads range from hardware upgrades and software options to nostalgia: Photo by AphoticD Apple's recently announced transition to Apple Silicon (Arm) based Macs raised some interesting questions about future support...

Apple Pays Samsung an Estimated $950 Million for Missing OLED Panel Purchase Targets

Monday July 13, 2020 10:03 am PDT by
Apple in the second quarter of 2020 paid Samsung approximately $950 million for not meeting OLED panel purchase goals established in agreements between the two companies, according to display analysts at Display Supply Chain Consultants. Samsung last week shared guidance on revenue and operating profit for the second quarter of 2020, which included a one-time gain related to its display...

Apple Shares Humorous 'Working-From-Home Thing' Video

Monday July 13, 2020 9:31 am PDT by
Apple today shared a funny video focused on the problems that people working from home have to deal with, including noisy children, chaotic schedules, communication issues, and more. The video focuses on showing off Apple products and their capabilities that can be useful when working from home, such as the ability to scan a document with an iPhone, mark up a PDF, Siri Reminders, and more.The...

SoftBank Considering Possible Sale of Arm Holdings as Apple Gears Up for Arm-Based Macs

Monday July 13, 2020 2:00 pm PDT by
SoftBank, the company that owns chip designer Arm Holdings, is exploring options that include a full or partial sale or a public offering, reports The Wall Street Journal. SoftBank is working with Goldman Sachs Group as an advisor, and the explorations are at an early stage. The Wall Street Journal says that it's unknown how much interest there would be in Arm from financial or industry...

Rumor Suggests New Apple App for Windows Could Be Coming Soon

Tuesday July 14, 2020 1:54 am PDT by
Apple could be working towards the release of a new app for Windows 10, according to a report this week from an Italian website. The blog Aggiornamenti Lumia suggests that an app from Apple is "coming soon" to the Microsoft Store, but stops short of providing additional details. Apple still maintains a Windows version of the iTunes app, which has been discontinued on Mac and replaced by...

Deals: Amazon Taking $400 Off 16-Inch MacBook Pro, Starting at New Low Price of $1,999.99 for 512GB

Monday July 13, 2020 5:34 am PDT by
Amazon has introduced a new low price on Apple's 16-inch MacBook Pro today, including both 512GB and 1TB models. Starting with the 512GB model (2.6GHz 6-Core, 16GB RAM), you can get this notebook for $1,999.99, down from $2,399.00. Note: MacRumors is an affiliate partner with Amazon. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running....