/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

How to find out if you are one of the 30M Facebook users whose account was affected by the security breach, what data was stolen, and what to do next

Are you one of the 30 million users hit by Facebook's access token breach announced two weeks ago?  Here's how to find out.

TechCrunch Josh Constine

Context & Ripple Effects

Two weeks after Facebook's September 25 disclosure that a code flaw let attackers steal access tokens for roughly 50M accounts, the company has narrowed the picture: its first investigation results attribute the intrusion to a large-scale attack on September 14-27 that accessed information of about 29M people, while confirming other Facebook apps and third-party apps were not affected.

This piece is the user-facing companion to that scoping exercise — TechCrunch walks readers through checking whether their account is among the 30M affected, what data was taken, and what remediation steps apply. It matters because the gap between '50M vulnerable' and '~29M actually accessed' is exactly where individual users have been left guessing.

First-order effects

  • Affected users can now move from uncertainty to a definitive answer: Facebook's self-check tool tells each person whether they were in the ~29M whose information was accessed, and which data categories were exposed.
  • Users caught in the attack face concrete cleanup — sessions tied to stolen access tokens are invalidated, forcing re-authentication, and those whose profile or contact details were scraped know precisely what is now in attackers' hands.

Second-order effects

  • Facebook's confirmation that third-party apps were untouched contains the blast radius for its developer ecosystem — no partner-platform revocations or integration audits follow, unlike broader token-leak scenarios.
  • The narrowing from 50M to ~29M hands regulators and press a moving target: every revision re-opens questions about how quickly Facebook understood the scope of an attack it had already patched.

Third-order effects

  • If the pattern holds, major platforms will standardize on staged breach communication — broad initial disclosure, then investigation-scoped numbers plus per-user self-check tools — making the first headline figure provisional by design.
  • Token-based takeover at platform scale reinforces the case for treating access tokens as the critical security boundary, pushing architectures toward shorter-lived credentials and tighter permission boundaries around personal data.

The trend: Platform breach response is converging on disclose-broad-then-scope-narrow, with per-user self-check tools replacing blanket advisories as the primary way individuals learn their exposure.