Facebook Warns 1 Million Users About Usernames, Passwords Stolen via 400 Malicious Apps

Apple said 45 of the 400 problematic apps were on its App Store and have been removed, while Google removed all the malicious apps in question.

Advertisement
By Jack Gillum, Bloomberg | Updated: 8 October 2022 10:48 IST
Highlights
  • Google has removed all of these apps from the Play Store
  • Not all 1 million people necessarily had their passwords compromised
  • Meta would be sharing tips with victims to prevent this from recurring

The apps worked by disguising themselves as photo editors, mobile games, or health trackers

Photo Credit: Reuters

Meta said it would notify roughly 1 million Facebook users that their account credentials may have been compromised due to security issues with apps downloaded from Apple and Alphabet's software stores. The company announced Friday that it identified more than 400 malicious Android and iOS apps this year that target internet users in order to steal their login information. Meta said it informed both Apple and Google about the issue in order to facilitate the removal of the apps.

The apps worked by disguising themselves as photo editors, mobile games, or health trackers, Facebook said.

Advertisement

Apple said 45 of the 400 problematic apps were on its App Store and have been removed. Google removed all the malicious apps in question, a spokesperson said.

“Cybercriminals know how popular these types of apps are, and they'll use similar themes to trick people and steal their accounts and information,” said David Agranovich, director of global threat disruption at Meta. “If an app is promising something too good to be true, like unreleased features for another platform or social media site, chances are that it has ulterior motives.”

Advertisement

A typical scam would unfold, for example, after a user downloaded one of the malicious apps. The app would require a Facebook login to work beyond basic functionality, thus tricking the user into providing their username and password. Users could then, for example, upload an edited photo to their Facebook account. But in the process, they unknowingly compromised their account by giving the author of the app access.

Meta said it would be sharing tips with potential victims on how they can avoid being “re-compromised” by learning how to better spot problematic apps that pilfer credentials, whether for Facebook or other accounts. The malicious activity occurred off Meta systems, Agranovich said, adding that not all 1 million people necessarily had their passwords compromised.

Advertisement

© 2022 Bloomberg L.P.


5G is here. Should you buy a 4G phone? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Facebook, Meta, Apple, Google, Android, iOS 10
Advertisement

Related Stories

Popular Mobile Brands
  1. FIFA World Cup 2026: How to Watch the World Cup Live on OTT, TV Channels
  2. Vi 5G Comes to More Cities; Services Restored on Mumbai Metro Aqua Line 3
  3. This OnePlus N Series Phone Will Launch in India Soon
  4. Vivo X500 Tipped to Launch With This 'Upgraded' Dimensity Chipset
  5. Honor Magic 9 Series May Launch With an Official Stylus Accessory
  6. Motorola Edge 70 Pro+ With 6,500mAh Battery Goes on Sale in India: See Offers
  7. Samsung Brings New Galaxy AI Tools to Galaxy S25 With One UI 8.5 Update
  1. Samsung Galaxy S25 Gets New Galaxy AI Features From Galaxy S26 With New One UI 8.5 Update
  2. Honor Magic 9 Series to Launch With Official Stylus Accessory, Tipster Claims
  3. Ubisoft Shuts Down 2 More Studios, Lays Off Up to 380 Employees in Latest Round of Cost Cuts
  4. iOS 27 Might Let iPhone Users Boot Up Their Handset in a New macOS-Like Recovery Mode
  5. Oppo Find N7 Key Specifications Leaked, Could Launch in 2027 as a Wide-Screen Foldable Phone
  6. WhatsApp's Scheduled Messages Feature Leaks Ahead of Release, Might Offer Various Useful Capabilities
  7. Asus ProArt PZ14 Launched in India Alongside Refreshed Asus TUF Gaming A14: Price, Features
  8. Maa Hai Na OTT Release Date Revealed: When and Where to Watch This Shilpa Shetty Starrer Reality Show?
  9. Asus ROG Zephyrus Duo Launched in India Alongside Zephyrus G14, Zephyrus G16 Models
  10. Vivo Y500 4G Could Launch Soon, Smartphone Gets Listed on Google Play Console
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.