Facebook Exposes Hundreds of Millions of User Passwords in Plaintext
Facebook admits to storing hundreds of millions of user passwords in readable plaintext since 2012. The company claims no internal abuse occurred, though thousands of employees had potential access to the unprotected data.
Facebook resets its track record for security incidents after confirming it stores hundreds of millions of user passwords in plaintext. The company discovers this massive oversight during a routine security review in January, but cybersecurity reporter Brian Krebs reveals that internal logs containing these readable passwords remain accessible to as many as 2,000 engineers and developers. This unprotected storage directly contradicts standard security practices, which require companies to scramble passwords using hashing and salting techniques.
The social media giant prepares to notify hundreds of millions of Facebook Lite users, tens of millions of regular Facebook users, and tens of thousands of Instagram users about the exposure. While Krebs estimates the total number of affected accounts reaches 600 million, Facebook does not confirm this exact figure. The company insists it finds no evidence of internal abuse or improper access, though it does not explain how it reaches this conclusion or how the bug originates in the first place.
This incident represents just the latest in a long string of embarrassing security issues for the social network, adding to ongoing congressional inquiries and criminal investigations into its data sharing practices. It remains unclear why Facebook takes months to publicly confirm the plaintext password storage or if the company properly notifies regulators under United States breach notification laws and European data protection rules. Similar plaintext password bugs affect other major tech companies like Twitter and GitHub in the past year.