Facebook updates a March blog post to say it stored passwords of millions of Instagram users in plain text, not tens of thousands as first announced
This number is much, much bigger than Facebook originally shared. — On the same morning Special Counsel Robert Mueller's report …
Context & Ripple Effects
In late March, Facebook said it would notify hundreds of millions of Facebook users and only thousands of Instagram users after finding passwords stored in readable format, while a Krebs on Security source put the true total at 200M–600M passwords searchable by employees. The April blog-post edit closes part of that gap from the other direction: the Instagram figure jumps from tens of thousands to millions.
The correction landed the same morning the Mueller report was released and just before a holiday weekend — timing CNN reads as a practiced news-dump strategy. That framing matters as much as the number: the story is no longer just the storage failure but how Facebook stages its admissions.
First-order effects
- Millions of Instagram users move into the notification-and-reset pool that Facebook's March disclosure had scoped at only thousands, expanding the direct blast radius of the plain-text storage incident.
- Facebook's own correction confirms its initial public estimate was off by orders of magnitude, handing regulators and reporters a documented case of an understated self-disclosure.
Second-order effects
- The holiday-weekend placement invites every future Facebook security post to be read through the news-dump lens, raising the reputational cost of quiet updates and pushing journalists to cross-check company blogs against researcher counts like Krebs' 200M–600M figure.
- Rival platforms now face pressure to audit their own credential storage proactively, since Facebook's sequence shows an internal bug can surface weeks later as a headline about scale, not just existence.
Third-order effects
- If the disclose-low-then-revise-upward pattern holds, corporate security blogs lose their standing as the authoritative record of incident scope, shifting verification work to independent researchers and the press.
- Repeated self-corrections of this kind strengthen the argument for externally enforced breach-notification standards, where scope estimates carry consequences rather than silent blog edits.
The trend: Platform security disclosures are becoming a credibility contest between companies' self-published incident posts and the researcher-and-press counts that keep revising them upward.