Facebook Plain-Text Password Debacle: Experts Say Change Your Password, Turn on 2FA

Advertisement
By Indo-Asian News Service | Updated: 22 March 2019 19:41 IST
Highlights
  • Facebook claims there is no evidence of passwords being misused
  • Security experts warn about changing passwords out of caution
  • Archives with plain text password date back to 2012

Security experts suggest users should change their password after Facebook's debacle

After a report revealed around 200-600 million Facebook users may have had their account passwords stored in plain text and searchable by over 20,000 Facebook employees, cybersecurity experts are urging users to change their passwords and turn on the two-factor authentication (2FA).

So far the inquiry has uncovered archives with plain text user passwords dating back to 2012, according to the report published this week by KrebsOnSecurity, a blog run by journalist Brian Krebs.

Facebook in a blog post on Thursday said that it had fixed the issue and will be notifying everyone whose passwords it found stored this way.

"It's perfectly possible that no passwords at all fell into the hands of any crooks as a result of this. But if any passwords did get into the wrong hands then you can expect them to be abused," said Paul Ducklin, Senior Technologist at global cybersecurity firm Sophos.

"Hashed passwords still need to be cracked before they can be used; plaintext passwords are the real deal without any further hacking or cracking needed," Ducklin added.

Facebook said it had found no evidence to date that anyone internally abused or improperly accessed the passwords.

"While the details of the incident are still emerging, this is likely an accidental programming error that led to the logging of plain text credentials. That said, this should never have happened and Facebook needs to ensure that no user credentials or data were compromised as a result of this error," said John Shier, Senior Security Advisor at Sophos.

"This is also another reminder for people who are still reusing passwords or using weak passwords to change their Facebook password to something strong and unique and to turn on two-factor authentication (2FA)," Shier said. 

Turning on 2FA would mean that a password alone is not enough for crooks to raid your account, Ducklin added.

Facebook also asked people to change their passwords "out of an abundance of caution".

Earlier this month, Facebook came under scrutiny for using phone numbers provided for security reasons -- like two-factor authentication (2FA) -- for things like advertising and making users searchable by their phone numbers across its different platforms.

"Another security measure users can implement to strengthen their digital security postures is to use different passwords for different online accounts. Don't use your Facebook password for any other login, particularly for personal/professional email accounts or online banking," said Sanjay Katkar, Joint Managing Director and Chief Technology Officer, Quick Heal Technologies Limited.

"It is also a good practice to log out whenever not using Facebook, even on mobile devices," Katkar added. 

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Facebook
Advertisement

Related Stories

Popular Mobile Brands
  1. Casio AE-1600HX Series Launched With Up to 10 Years of Battery Life
  2. Realme 16 5G With 7,000mAh Battery Goes on Sale in India: See Offers
  3. Samsung Sets Deadline for Messages App: Here's What Replaces It
  4. No More Black? iPhone 18 Pro New Leak Reveals Bold New Colour Options
  5. Here Is How to Watch NASA's Artemis II Lunar Flyby Live
  6. Infinix Note 60 Pro Design, Colourways Revealed as India Launch Nears
  7. Oppo Find X9 Ultra to Feature 10x Optical Zoom and External Lens Kit
  8. Thaai Kizhavi OTT Release Date: When and Where to Watch it Online?
  9. Take-Two Interactive Lays Off AI Team, Including Head of AI
  10. Oppo F33 Pro India Launch Date, Price Range Surface Online
  1. No More Black? iPhone 18 Pro New Leak Reveals Bold New Colour Options for 2026
  2. China Urges Banks to Use Blockchain for Lending, Tax Data Sharing
  3. Meta to Fire 200 Employees, Phase Out Middle Manager Titles Amid AI Push: Report
  4. Glory OTT Release Confirmed: Where to Watch Pulkit Samrat and Divyendu Sharma Starrer Online
  5. Oppo Find X9 Ultra to Feature 10x Optical Zoom and External Lens Kit
  6. China Removes Bitchat App From Apple Store Over Regulatory Concerns
  7. WhatsApp Reportedly Rolls Out Noise Cancellation for Voice and Video Calls to Android Beta Users
  8. Samsung Galaxy S27 Pro to Reportedly Launch Next Year With the Privacy Display Feature
  9. iPhone Fold Trial Production Begins Ahead of Anticipated Launch in H2 2026: Report
  10. New Study Claims There Might Be Way More Pulsars in Space Than We Previously Thought
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.