Facebook Failed to Warn Users of Known Risks Before 2019 Breach, Court Filing Shows

Single sign-on connects users to third-party social apps and services using their Facebook credentials.

Advertisement
By Reuters | Updated: 16 August 2019 16:39 IST

Facebook users suing the world's largest social media network over a 2018 data breach say it failed to warn them about risks tied to its single sign-on tool, even though it protected its employees, a court filing on Thursday showed.

Single sign-on connects users to third-party social apps and services using their Facebook credentials.

The lawsuit, which combined several legal actions, stems from Facebook's worst-ever security breach in September, when hackers stole login codes - or "access tokens" - that allowed them to access nearly 29 million accounts.

Advertisement

"Facebook knew about the access token vulnerability and failed to fix it for years, despite that knowledge," the plaintiffs said in a heavily redacted section of the filing in the US District Court for the Northern District of California in San Francisco.

Advertisement

"Even more egregiously, Facebook took steps to protect its own employees from the security risk, but not the vast majority of its users."

Facebook did not immediately respond to a request for comment.

Advertisement

Judge William Alsup told Facebook in January he was willing to allow "bone-crushing discovery" in the case to uncover how much user data was stolen.

Facebook has revealed few details since initially disclosing the attack, saying only that it affected a "broad" spectrum of users without breaking down the numbers by country.

Advertisement

The attackers took profile details such as birth dates, employers, education history, religious preference, types of devices used, pages followed and recent searches and location check-ins from 14 million users.

For the other 15 million users, the breach was restricted to name and contact details. In addition, attackers could see the posts and lists of friends and groups of about 400,000 users.

They did not steal personal messages or financial data and did not access users' accounts on other websites, Facebook said.

© Thomson Reuters 2019

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Facebook
Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus 15, OnePlus Ace 6 Price Leaks Hours Ahead of China Launch
  2. iQOO 15 Teased to Launch in India on This Date
  3. Mappls MapmyIndia Expresses Interest in Teaming Up With Perplexity AI
  4. New Images of Interstellar Object 3I/ATLAS Show a Giant Jet Shooting Toward the Sun
  5. Apple Could Increase Monthly AirPods Production Capacity in India
  1. OnePlus 15 New Gaming Core Chip, Other Specifications Revealed Hours Before Launch
  2. Oppo Find X9 Ultra Tipped to Pack Largest Battery Among 'Ultra' Models; Oppo May Be Working on Ultra-Thin Phone
  3. Instagram Announces Watch History Feature for Revisiting Already-Watched Reels
  4. Internet Is Too Important to Be Left in Google’s Hands, Says Perplexity CEO
  5. Apple Planning to Double Monthly AirPods Production Capacity in India After iPhone: Report
  6. Mappls' MapmyIndia Eyes Collaboration With Perplexity AI After CEO’s Comment on Mapping Challenges
  7. Apple to Equip Next-Gen iPad Pro with Vapour Chamber Cooling and M6 Chip: Mark Gurman
  8. OnePlus 15, OnePlus Ace 6 Price Reportedly Leaked Hours Ahead of Launch in China
  9. iQOO 15 Teased to Launch in India in November; to Come With Dynamic Glow UI Design
  10. New Images of Interstellar Object 3I/ATLAS Show a Giant Jet Shooting Toward the Sun
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.