/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Facebook admits it inadvertently stored some user passwords in plain text, searchable by employees; source says it may have been between 200M and 600M passwords

in some cases going back to 2012, KrebsOnSecurity has learned.” http://krebsonsecurity.com/... Joe Weisenthal / @thestalwart : This just knocked $FB shares a bit http://twitter.com/...

Krebs on Security Brian Krebs

Context & Ripple Effects

The arc here is a disclosure that keeps widening. KrebsOnSecurity first reported that Facebook had stored passwords in plain text going back to 2012, with a source estimating 200M–600M accounts; Facebook then said it would notify hundreds of millions of Facebook users and thousands of Instagram users after finding credentials in a readable format in its own notification post.

A month later the company revised its March blog post to say millions of Instagram passwords were exposed, not tens of thousands as first announced the April correction — a scope revision that preceded the Irish Data Protection Commission opening a formal inquiry into the incident.

First-order effects

  • Hundreds of millions of Facebook users and thousands of Instagram users get breach notifications for passwords that were internally searchable by employees, and Joe Weisenthal noted the report knocked FB shares on the day it broke.

Second-order effects

  • Facebook's understatement of the Instagram exposure in its March blog post hands regulators a concrete discrepancy to probe — the Irish DPC's inquiry is built directly on the company's own corrected self-report.

Third-order effects

  • If the pattern holds, companies' voluntary breach disclosures become the primary trigger for EU enforcement actions, raising the cost of initial undercounting and pushing firms toward conservative first estimates rather than minimal ones.

The trend: Platform security failures are shifting from self-managed disclosures to regulator-led investigations, with each scope correction inviting deeper scrutiny.