Black Friday is Now! Don’t miss out on up to 60% OFF InvestingProCLAIM SALE

Facebook failed to warn users of known risks before 2018 breach -court filing

Published 16/08/2019, 01:15
Facebook failed to warn users of known risks before 2018 breach -court filing
META
-

By Katie Paul

(Reuters) - Facebook (O:FB) users suing the world's largest social media network over a 2018 data breach say it failed to warn them about risks tied to its single sign-on tool, even though it protected its employees, a court filing on Thursday showed.

Single sign-on connects users to third-party social apps and services using their Facebook credentials.

The lawsuit, which combined several legal actions, stems from Facebook Inc's worst-ever security breach in September, when hackers stole login codes - or "access tokens" - that allowed them to access nearly 29 million accounts.

"Facebook knew about the access token vulnerability and failed to fix it for years, despite that knowledge," the plaintiffs said in a heavily redacted section of the filing in the U.S. District Court for the Northern District of California in San Francisco.

"Even more egregiously, Facebook took steps to protect its own employees from the security risk, but not the vast majority of its users."

Facebook did not immediately respond to a request for comment.

Judge William Alsup told Facebook in January he was willing to allow "bone-crushing discovery" in the case to uncover how much user data was stolen.

Facebook has revealed few details since initially disclosing the attack, saying only that it affected a "broad" spectrum of users without breaking down the numbers by country.

The attackers took profile details such as birth dates, employers, education history, religious preference, types of devices used, pages followed and recent searches and location check-ins from 14 million users.

For the other 15 million users, the breach was restricted to name and contact details. In addition, attackers could see the posts and lists of friends and groups of about 400,000 users.

They did not steal personal messages or financial data and did not access users' accounts on other websites, Facebook said.

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.