Facebook says it will notify hundreds of millions of Facebook users and thousands of Instagram users after it found passwords were stored in a readable format
As part of a routine security review in January, we found that some user passwords were being stored in a readable format within our internal data storage systems.
Context & Ripple Effects
This disclosure lands four months after Facebook told some Instagram users that a now-fixed bug in its data download tool sent their passwords in plaintext inside a URL — so it is the second plaintext-password incident at the company in as many quarters. The new one is different in kind: rather than a bug leaking passwords outward, a routine January security review found passwords sitting readable inside Facebook's own internal systems.
Reporting the same day put the scale far above Facebook's first framing, with a source suggesting between 200 million and 600 million passwords were exposed and searchable by employees (Krebs on Security). The scope kept moving afterward too — an April update revised the Instagram count from tens of thousands to millions (Recode) — which matters because each revision extends who must be notified.
First-order effects
- Hundreds of millions of Facebook users and thousands of Instagram users receive notifications that their credentials were stored in readable format, prompting password changes and support load for both platforms.
- Facebook's internal employee access to credential logs becomes a disclosed fact, putting its internal data-handling practices directly into the public record alongside the notification itself.
Second-order effects
- Advertisers, regulators, and partners weighing Facebook's data stewardship now have two consecutive plaintext incidents — the November Instagram download-tool bug and this storage lapse — to weigh against the company's assurances, raising the cost of every subsequent privacy commitment it makes.
- The repeated upward revisions to affected-user counts force Facebook to run rolling notifications rather than a single clean disclosure, compounding operational cost and keeping the story alive across multiple news cycles.
Third-order effects
- If the pattern holds — discovery by internal review, understated initial counts, later corrections — platform companies face pressure to treat credential storage hygiene as a reportable, auditable surface rather than an internal engineering detail, with disclosure accuracy itself becoming part of the trust calculus.
- Two incidents in two quarters suggest plaintext handling was systemic rather than isolated, pointing toward industry-wide re-examination of how large platforms log, search, and retain authentication data inside their own infrastructure.
The trend: Large platforms' internal credential-handling practices are becoming recurring public disclosures, with each incident's scope tending to expand after the initial announcement.