/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Facebook says it will notify hundreds of millions of Facebook users and thousands of Instagram users after it found passwords were stored in a readable format

As part of a routine security review in January, we found that some user passwords were being stored in a readable format within our internal data storage systems.

Facebook Pedro Canahuati

Context & Ripple Effects

This disclosure lands four months after Facebook told some Instagram users that a now-fixed bug in its data download tool sent their passwords in plaintext inside a URL — so it is the second plaintext-password incident at the company in as many quarters. The new one is different in kind: rather than a bug leaking passwords outward, a routine January security review found passwords sitting readable inside Facebook's own internal systems.

Reporting the same day put the scale far above Facebook's first framing, with a source suggesting between 200 million and 600 million passwords were exposed and searchable by employees (Krebs on Security). The scope kept moving afterward too — an April update revised the Instagram count from tens of thousands to millions (Recode) — which matters because each revision extends who must be notified.

First-order effects

  • Hundreds of millions of Facebook users and thousands of Instagram users receive notifications that their credentials were stored in readable format, prompting password changes and support load for both platforms.
  • Facebook's internal employee access to credential logs becomes a disclosed fact, putting its internal data-handling practices directly into the public record alongside the notification itself.

Second-order effects

  • Advertisers, regulators, and partners weighing Facebook's data stewardship now have two consecutive plaintext incidents — the November Instagram download-tool bug and this storage lapse — to weigh against the company's assurances, raising the cost of every subsequent privacy commitment it makes.
  • The repeated upward revisions to affected-user counts force Facebook to run rolling notifications rather than a single clean disclosure, compounding operational cost and keeping the story alive across multiple news cycles.

Third-order effects

  • If the pattern holds — discovery by internal review, understated initial counts, later corrections — platform companies face pressure to treat credential storage hygiene as a reportable, auditable surface rather than an internal engineering detail, with disclosure accuracy itself becoming part of the trust calculus.
  • Two incidents in two quarters suggest plaintext handling was systemic rather than isolated, pointing toward industry-wide re-examination of how large platforms log, search, and retain authentication data inside their own infrastructure.

The trend: Large platforms' internal credential-handling practices are becoming recurring public disclosures, with each incident's scope tending to expand after the initial announcement.