How to find out if you are one of the 30M Facebook users whose account was affected by the security breach, what data was stolen, and what to do next
Are you one of the 30 million users hit by Facebook's access token breach announced two weeks ago? Here's how to find out.
Context & Ripple Effects
Two weeks after Facebook's September 25 disclosure that a code flaw let attackers steal access tokens for roughly 50M accounts, the company has narrowed the picture: its first investigation results attribute the intrusion to a large-scale attack on September 14-27 that accessed information of about 29M people, while confirming other Facebook apps and third-party apps were not affected.
This piece is the user-facing companion to that scoping exercise — TechCrunch walks readers through checking whether their account is among the 30M affected, what data was taken, and what remediation steps apply. It matters because the gap between '50M vulnerable' and '~29M actually accessed' is exactly where individual users have been left guessing.
First-order effects
- Affected users can now move from uncertainty to a definitive answer: Facebook's self-check tool tells each person whether they were in the ~29M whose information was accessed, and which data categories were exposed.
- Users caught in the attack face concrete cleanup — sessions tied to stolen access tokens are invalidated, forcing re-authentication, and those whose profile or contact details were scraped know precisely what is now in attackers' hands.
Second-order effects
- Facebook's confirmation that third-party apps were untouched contains the blast radius for its developer ecosystem — no partner-platform revocations or integration audits follow, unlike broader token-leak scenarios.
- The narrowing from 50M to ~29M hands regulators and press a moving target: every revision re-opens questions about how quickly Facebook understood the scope of an attack it had already patched.
Third-order effects
- If the pattern holds, major platforms will standardize on staged breach communication — broad initial disclosure, then investigation-scoped numbers plus per-user self-check tools — making the first headline figure provisional by design.
- Token-based takeover at platform scale reinforces the case for treating access tokens as the critical security boundary, pushing architectures toward shorter-lived credentials and tighter permission boundaries around personal data.
The trend: Platform breach response is converging on disclose-broad-then-scope-narrow, with per-user self-check tools replacing blanket advisories as the primary way individuals learn their exposure.