Meta warns 1M Facebook users that their account info may have been stolen by 400+ apps on the App Store and Google Play that have a “Login with Facebook” button
delete them now Priya Singh / BGR India : Meta warns against Android, iOS apps for stealing users' Facebook password Justin Luna / Neowin : Meta warns Facebook users about password-stealing Android and iOS malware apps Andrew Orr / AppleInsider : One million Facebook users had passwords stolen by fake apps Ravie Lakshmanan / The Hacker News : Facebook Detects 400 Android and iOS Apps Stealing Users Log-in Credentials José Adorno / BGR : Facebook found 400 malicious apps that steal your login - here's how to protect yourself MacDailyNews : Facebook warns 1 million users about stolen usernames, passwords Pranob Mehrotra / XDA Developers : Meta shares list of 400 Android and iOS apps that may have stolen your Facebook credentials Michael Kan / PCMag : Meta Uncovers 400 Malicious Android, iOS Apps Designed to Steal Logins Ben Lovejoy / 9to5Mac : Facebook security warning for 1M users: Scam apps stole login credentials Danny Palmer / ZDNet : Facebook users warned: You may have downloaded these password-stealing Android and iOS apps Tonya Riley / CyberScoop : Facebook warns 1 million users about apps trying to compromise accounts Karishma Vanjani / Barron's Online : Has Your Facebook Password Been Stolen? Meta Issues a Warning. Tweets: @metanewsroom : We identified more than 400 malicious mobile apps this year that target people across the internet to steal their @facebook login information. Learn more about how to stay safe and what to do if you're affected: https://about.fb.com/... https://twitter.com/... Paul Thurrott / @thurrott : “Meta warns 1M Facebook users that their account info may have been stolen by 400+ apps, often via a ‘Login with Facebook’ button, on App Store and Google Play” This is literally why you don't sign in to a website with your f'ing Facebook account, people. Kosta Eleftheriou / @keleftheriou : “The apps were listed in [...] Apple's App Store and disguised themselves as photo editors, games, VPN services, business apps and other utilities.” “The apps often publish fake reviews to drown out negative reviews and trick people into downloading them.” https://www.usatoday.com/... Zack Whittaker / @zackwhittaker : From what we did see, these apps were crap, buggy, offered basic functionality, and packed full of ads. But without evidence, or an explanation of how Meta reached its conclusions, we're just taking Meta's word for it. Alan Woodward / @profwoodward : If an unrelated app requires you to “login with Facebook” when not really required you need to be suspicious - a cautionary report from @iblametom https://www.forbes.com/... Rene Ritchie / @reneritchie : Never log in with a main service if you don't have to. If you do have to, set a recurring monthly reminder to check every social app for any access you've granted, and revoke anything you don't absolutely need https://twitter.com/... Zack Whittaker / @zackwhittaker : We were briefed on this news earlier this week, but couldn't verify Meta's claims. We asked Meta about this before the embargo lifted this morning but we didn't get a satisfactory response as to how Meta discovered these allegedly violating apps. https://twitter.com/... Todd Sherman / @tdd : I avoid login-with-any-app because it introduces open-ended risk to your account. Once you're in a routine with a password manager it is only a few extra seconds to generate a new login. https://twitter.com/... David Agranovich / @davidagranovich : 1/ We just shared new security research by our malware discovery team into 400+ malicious iOS and Android apps. They were designed to steal people's Facebook login info 🧵 https://about.fb.com/... Florian Mueller / @fosspatents : Manual app review didn't prevent this from happening. Two reasons: 1) bad actors are sneaky enough that an average of ten minutes per app is inevitably insufficient 2) especially Apple's app review is primarily about enforcing commercial rules (tyranny and taxation) https://twitter.com/... Michael Del Moro / @mikedelmoro : Look out for these! Tips on how to spot them in the post: https://twitter.com/... Drew Olanoff / @yoda : this wouldn't be a problem if you would have just shut up and let mark plug directly into your cerebral cortex like he asked. https://twitter.com/... Thomas Brewster / @iblametom : NEW - Meta says it's warning 1 million Facebook users about password-stealing malware that managed to make it onto Apple and Google app stores. Included a load of photoshopping apps, like those that turn your face into a cartoon. Basic but effective. https://www.forbes.com/...
Context & Ripple Effects
Meta had already encountered friction in its account-protection rollout: some users were locked out after being prompted to enable Facebook Protect. The discovery of credential-harvesting apps shifts the security problem beyond Meta’s own prompts to third-party mobile software using its login brand.
Later coverage of compromised verified Meta accounts used to push shady downloads shows why stolen Facebook credentials matter beyond a single app: an account takeover can become a distribution channel for further scams.
First-order effects
- About 1 million Facebook users are being alerted that credentials entered into more than 400 iOS and Android apps may be exposed, requiring Meta to manage a large account-security response.
- Apple’s App Store and Google Play are implicated as distribution channels for apps that presented a “Login with Facebook” option, putting their app-review controls alongside Meta’s login flow under scrutiny.
Second-order effects
- Developers that use Facebook login face more user skepticism around embedded authentication screens, while Meta has an incentive to distinguish legitimate integrations from credential-collection imitations.
- The warning gives scammers’ account-takeover tactics a clearer upstream source of credentials; the later use of verified accounts for malware-style downloads illustrates how compromise can extend into advertising and impersonation.
Third-order effects
- If credential theft continues to arrive through ostensibly legitimate mobile apps, social-login providers and app stores will have to treat third-party integration governance as an account-security boundary rather than a developer-convenience feature.
- The pattern points toward identity security being judged across the full app-distribution chain—platform login tools, store review, and recovery processes—rather than by a social network’s protections alone.
The trend: Consumer-platform security is shifting from protecting accounts at the service itself to governing the third-party apps and login interfaces that collect those credentials.