Facebook employees 'had access to millions of user passwords'

18:01 • 22.03.19

Facebook stored up to 600 million user account passwords without encryption and viewable as plain text to tens of thousands of company employees, CNBC reports, citing cybersecurity journalist Brian Krebs.

Facebook stored up to 600 million user account passwords without encryption and viewable as plain text to tens of thousands of company employees, according to a report Thursday by cybersecurity journalist Brian Krebs.

The 600 million users represents a significant portion of Facebook's user base of 2.7 billion people. The company said Thursday it planned to start notifying those affected so they could change their passwords.

"As part of a routine security review in January, we found that some user passwords were being stored in a readable format within our internal data storage systems," Facebook said in a statement. "This caught our attention because our login systems are designed to mask passwords using techniques that make them unreadable. We have fixed these issues and as a precaution we will be notifying everyone whose passwords we have found were stored in this way."


Facebook's blog post did not say how many users were affected.

 

Facebook employees 'had access to millions of user passwords'