Facebook failed to warn users of 2018 data breach, lawsuit claims

Court filings say the social network chose to protect employees over its users

finger above Facebook icon

US Facebook users have filed a lawsuit against the social media firm over the handling of a 2018 data breach, one that they say the company was aware of long before it was officially reported, a court filing has revealed.

The documents, seen by Reuters, also suggest that Facebook took steps to protect its employees from the vulnerability but not its users.

In October last year, Facebook revealed that some 30 million access tokens, used to keep accounts logged into Facebook whenever the app is closed down, were stolen after hackers exploited a coding vulnerability on the website.

The lawsuit alleges that the company was aware of the issue for a number of years prior to its October blog post, and that the company decided not to notify users of the flaw.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

"Facebook knew about the access token vulnerability and failed to fix it for years, despite that knowledge," the plaintiffs said in a heavily redacted section of the filing in the U.S. District Court for the Northern District of California in San Francisco.

"Even more egregiously, Facebook took steps to protect its own employees from the security risk, but not the vast majority of its users."

At the start of the case, Judge William Alsup warned the company that he was willing to allow "bone-crushing discovery to uncover how much user data was stolen", according to Reuters. Since its initial disclosure of the hack, Facebook has put forward very little detail, saying only that a "broad" spectrum of users were affected.

The Irish Data Protection Commission (DPC) confirmed that three million EU users were hit by the attack. Of the 30 million total users affected, 15 million were said to have had their name, listed contact details, phone and email addresses exposed. Another 14 million had potentially sensitive information such as location data and search history leaked.

"As more details are coming to light about this massive security breach, the public and Facebook users are gaining a deeper understanding of exactly how their data was misused - not only be the attackers but also by Facebook," said Robert Ramsden-Board, VP for EMEA at Securonix.

"Facebook should have been much clearer to customers about how their data would be used when deploying the single sign-on tool, however, this clearly did not happen."

Advertisement - Article continues below

The breach happened in the same year as the Cambridge Analytica scandal, and while both initial incidents were major blows to the company's reputation, the manner in which the social network handled them proved to be just as damaging.

Currently, the UK government is questioning whether Facebook's CTO Mike Schroepfer had deliberately misled in his testimony of the Cambridge Analytica scandal, with MPs suggesting "inconsistent evidence" was provided.

IT Pro has approached Facebook for comment.

Featured Resources

Transform the operator experience with enhanced automation & analytics

Bring networking into the digital era

Download now

Artificially intelligent data centres

How the C-Suite is embracing continuous change to drive value

Download now

Deliver secure automated multicloud for containers with Red Hat and Juniper

Learn how to get started with the multicloud enabler from Red Hat and Juniper

Download now

Get the best out of your workforce

7 steps to unleashing their true potential with robotic process automation

Download now
Advertisement

Most Popular

Visit/security/vulnerability/354309/patch-issued-for-critical-windows-bug
vulnerability

Patch issued for critical Windows bug

11 Dec 2019
Visit/cloud/microsoft-azure/354230/microsoft-not-amazon-is-going-to-win-the-cloud-wars
Microsoft Azure

Microsoft, not Amazon, is going to win the cloud wars

30 Nov 2019
Visit/operating-systems/microsoft-windows/354297/this-exploit-could-give-users-free-windows-7-updates
Microsoft Windows

This exploit could give users free Windows 7 updates beyond 2020

9 Dec 2019
Visit/data-insights/big-data/354311/google-reveals-uks-most-searched-for-terms-in-2019
big data

Google reveals UK’s most searched for terms in 2019

11 Dec 2019