Facebook stored hundreds of millions of user passwords in plain text

Image Credit: Shutterstock (Image credit: Shutterstock)

A new report from Krebs On Security has revealed that Facebook stored the account passwords of hundreds of millions of users in plain text and they were easily searchable by thousands of its own employees in some cases going back to 2012.

According to a senior employee familiar with the investigation, the social networking giant is currently probing a series of security failures in which employees wrote applications that logged unencrypted password data for Facebook users and stored this information in plain text on internal company servers.

So far, the investigation has discovered that between 200m and 600m Facebook users may have had their account passwords stored on its servers and searchable by over 20,000 employees.

The company is still trying to determine exactly how many passwords were exposed and for how long but archives with plain text user passwords have been discovered that date back to 2012.

Plain text passwords

Access logs at Facebook show that around 2,000 engineers or developers made nine million internal queries for data elements that contained plain text user passwords.

Software engineer at Facebook, Scott Renfro provided further insight into the ongoing investigation to Krebs On Security in an interview, saying:

“We’ve not found any cases so far in our investigations where someone was looking intentionally for passwords, nor have we found signs of misuse of this data. In this situation what we’ve found is these passwords were inadvertently logged but that there was no actual risk that’s come from this. We want to make sure we’re reserving those steps and only force a password change in cases where there’s definitely been signs of abuse.”

Affected users will not have to change their passwords as they were not leaked outside of the company, though Facebook is preparing to notify “hundreds of millions of Facebook Lite users, tens of millions of other Facebook users, and tens of thousands of Instagram users”. 

Via Krebs On Security

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
Isometric demonstrating multi-factor authentication using a mobile device.
NCSC gets influencers to sing the praises of 2FA
Sam Altman and OpenAI
OpenAI is upping its bug bounty rewards as security worries rise
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Dangerous new CoffeeLoader malware executes on your GPU to get past security tools
China
Notorious Chinese hackers FamousSparrow allegedly target US financial firms
A digital representation of a lock
NYU website defaced as hacker leaks info on a million students
NHS
NHS IT supplier hit with major fine following ransomware attack
Latest in News
Nintendo Switch 2 Joy-Con up-close from app store
Nintendo's new app gave us another look at the Switch 2, and there's something different with the Joy-Con
cheap Nintendo Switch game deals sales
Nintendo didn't anticipate that Mario Kart 8 Deluxe was 'going to be the juggernaut' for the Nintendo Switch when it was ported to the console, according to former employees
Three angles of the Apple MacBook Air 15-inch M4 laptop above a desk
Apple MacBook Air 15-inch (M4) review roundup – should you buy Apple's new lightweight laptop?
Witchbrook
Witchbrook, the life-sim I've been waiting years for, finally has a release window and it's sooner than you think
Amazon Echo Smart Speaker
Amazon is experimenting with renaming Echo speakers to Alexa speakers, and it's about time
Shigeru Miyamoto presents Nintendo Today app
Nintendo Today smartphone app is out now on iOS and Android devices – and here's what it does