First results of breach investigation: large-scale attack on Sept. 14-27 accessed info of ~29M people; other Facebook apps or third-party apps not affected
We have been working around the clock to investigate the security issue we discovered and fixed two weeks ago so we can help people understand …
Context & Ripple Effects
Two weeks after Facebook disclosed that a vulnerability let attackers steal access tokens for roughly 50M accounts — an exploit chain Wired reconstructed as view-as-page flaws chained into token theft — the company has finished its first pass at what was actually taken. The answer narrows the blast radius: the September 25 discovery covered about 50M exposed accounts, but the attackers actively pulled profile data on only ~29M of them during a Sept. 14–27 window.
The other open question was whether the stolen tokens reached beyond Facebook itself into connected apps. An earlier update found no evidence “so far” of third-party app access and shipped a developer tool to force logouts; today's results close that loop with a firm negative, which matters because token theft is precisely the kind of credential that would have unlocked the wider app ecosystem.
First-order effects
- About 29M users learn their name, contact details, or other profile information was accessed by the attackers, while the remaining ~21M of the originally exposed 50M are downgraded to 'vulnerable but not accessed'; Facebook can now target its user notifications instead of blanket warnings.
Second-order effects
- The clean bill of health for third-party apps removes the worst-case scenario for the developer ecosystem — a token-based breach cascading into every connected service — but leaves Facebook alone holding the accountability, since the flaw lived in its own view-as feature.
Third-order effects
- If the pattern holds, platform-level identity infrastructure (single sign-on tokens, social login) concentrates breach risk at the hub rather than the spokes, pushing regulators and partners to treat the platform operator — not individual apps — as the accountable party when tokens leak.
The trend: As social platforms become identity hubs whose access tokens unlock whole app ecosystems, breach accounting is shifting from counting compromised passwords to auditing what authenticated sessions exposed.