Facebook Exposes Hundreds of Millions of Plain Text Passwords to Employees
Facebook investigates a massive security failure that leaves up to 600 million user passwords searchable by thousands of employees since 2012. The company claims it finds no evidence of internal abuse or data misuse.
Facebook investigates a major security failure that exposes the plain text passwords of hundreds of millions of users to its internal employees. Internal applications inadvertently log unencrypted password data on company servers, making these sensitive credentials searchable by more than 20,000 Facebook workers. Archives containing these visible passwords date back to 2012, affecting an estimated 200 million to 600 million user accounts.
Access logs reveal that approximately 2,000 engineers or developers make around nine million internal queries for data elements that contain these plain text user passwords. Despite this massive exposure, Facebook insists its ongoing investigation finds no indication that employees intentionally search for passwords or misuse the data. A senior employee shares that the legal team works to narrow down the exact number of affected users by focusing on data currently stored in the company warehouse.
Facebook software engineer Scott Renfro states that the company plans to notify affected users but refuses to force mandatory password resets. Renfro emphasizes that Facebook views the logging as inadvertent and sees no actual risk stemming from the situation, reserving forced password changes only for cases with definite signs of abuse. The social media giant continues to probe the exact scope and duration of this significant privacy lapse.