• Facebook announced a data breach on Friday, Sept. 28, in which the personal information of 50 million user accounts was put at risk due to a vulnerability in the social network’s code.
• Hackers gained the ability to steal “access tokens” that allow users to stay logged into their accounts. Fraudsters could use these to not only take over users’ Facebook profiles, but also to access third-party accounts like Airbnb, Spotify or Uber that use Facebook credentials to log in.
• Though the access tokens targeted in the attack could potentially be used to log into third-party sites, Facebook announced on Oct. 2 that its investigators don’t believe such third-party sites were affected.
• Since discovering the breach, Facebook has fixed the vulnerability, informed law enforcement to investigate and reset the access tokens on 90 million accounts as a precautionary measure.