Facebook failed to warn users of 2018 data breach, lawsuit claims

finger above Facebook icon

US Facebook users have filed a lawsuit against the social media firm over the handling of a 2018 data breach, one that they say the company was aware of long before it was officially reported, a court filing has revealed.

The documents, seen by Reuters, also suggest that Facebook took steps to protect its employees from the vulnerability but not its users.

In October last year, Facebook revealed that some 30 million access tokens, used to keep accounts logged into Facebook whenever the app is closed down, were stolen after hackers exploited a coding vulnerability on the website.

The lawsuit alleges that the company was aware of the issue for a number of years prior to its October blog post, and that the company decided not to notify users of the flaw.

"Facebook knew about the access token vulnerability and failed to fix it for years, despite that knowledge," the plaintiffs said in a heavily redacted section of the filing in the U.S. District Court for the Northern District of California in San Francisco.

"Even more egregiously, Facebook took steps to protect its own employees from the security risk, but not the vast majority of its users."

At the start of the case, Judge William Alsup warned the company that he was willing to allow "bone-crushing discovery to uncover how much user data was stolen", according to Reuters. Since its initial disclosure of the hack, Facebook has put forward very little detail, saying only that a "broad" spectrum of users were affected.

The Irish Data Protection Commission (DPC) confirmed that three million EU users were hit by the attack. Of the 30 million total users affected, 15 million were said to have had their name, listed contact details, phone and email addresses exposed. Another 14 million had potentially sensitive information such as location data and search history leaked.

"As more details are coming to light about this massive security breach, the public and Facebook users are gaining a deeper understanding of exactly how their data was misused - not only be the attackers but also by Facebook," said Robert Ramsden-Board, VP for EMEA at Securonix.

"Facebook should have been much clearer to customers about how their data would be used when deploying the single sign-on tool, however, this clearly did not happen."

The breach happened in the same year as the Cambridge Analytica scandal, and while both initial incidents were major blows to the company's reputation, the manner in which the social network handled them proved to be just as damaging.

Currently, the UK government is questioning whether Facebook's CTO Mike Schroepfer had deliberately misled in his testimony of the Cambridge Analytica scandal, with MPs suggesting "inconsistent evidence" was provided.

IT Pro has approached Facebook for comment.

Bobby Hellard

Bobby Hellard is ITPro's Reviews Editor and has worked on CloudPro and ChannelPro since 2018. In his time at ITPro, Bobby has covered stories for all the major technology companies, such as Apple, Microsoft, Amazon and Facebook, and regularly attends industry-leading events such as AWS Re:Invent and Google Cloud Next.

Bobby mainly covers hardware reviews, but you will also recognize him as the face of many of our video reviews of laptops and smartphones.