AGL 38.50 Increased By ▲ 0.35 (0.92%)
AIRLINK 129.00 Increased By ▲ 3.93 (3.14%)
BOP 7.14 Increased By ▲ 0.29 (4.23%)
CNERGY 4.55 Increased By ▲ 0.10 (2.25%)
DCL 8.25 Increased By ▲ 0.34 (4.3%)
DFML 38.10 Increased By ▲ 0.76 (2.04%)
DGKC 79.97 Increased By ▲ 2.20 (2.83%)
FCCL 32.20 Increased By ▲ 1.62 (5.3%)
FFBL 72.85 Increased By ▲ 3.99 (5.79%)
FFL 12.18 Increased By ▲ 0.32 (2.7%)
HUBC 109.80 Increased By ▲ 5.30 (5.07%)
HUMNL 13.85 Increased By ▲ 0.36 (2.67%)
KEL 4.93 Increased By ▲ 0.28 (6.02%)
KOSM 7.48 Increased By ▲ 0.31 (4.32%)
MLCF 37.50 Increased By ▲ 1.06 (2.91%)
NBP 69.80 Increased By ▲ 3.88 (5.89%)
OGDC 187.89 Increased By ▲ 8.36 (4.66%)
PAEL 25.10 Increased By ▲ 0.67 (2.74%)
PIBTL 7.28 Increased By ▲ 0.13 (1.82%)
PPL 150.61 Increased By ▲ 6.91 (4.81%)
PRL 24.98 Increased By ▲ 0.66 (2.71%)
PTC 17.20 Increased By ▲ 0.80 (4.88%)
SEARL 80.80 Increased By ▲ 2.23 (2.84%)
TELE 7.47 Increased By ▲ 0.25 (3.46%)
TOMCL 32.85 Increased By ▲ 0.88 (2.75%)
TPLP 8.50 Increased By ▲ 0.37 (4.55%)
TREET 16.60 Increased By ▲ 0.47 (2.91%)
TRG 56.15 Increased By ▲ 1.49 (2.73%)
UNITY 27.90 Increased By ▲ 0.40 (1.45%)
WTL 1.33 Increased By ▲ 0.04 (3.1%)
BR100 10,394 Increased By 304.4 (3.02%)
BR30 30,698 Increased By 1189.1 (4.03%)
KSE100 97,472 Increased By 2897.6 (3.06%)
KSE30 30,413 Increased By 968.6 (3.29%)

Facebook said Friday that hackers accessed personal data of 29 million users in a breach at the world''s leading social network disclosed late last month. The company had originally said up to 50 million accounts were affected in a cyberattack that exploited a trio of software flaws to steal "access tokens" that enable people to automatically log back onto the platform.
"We now know that fewer people were impacted than we originally thought," Facebook vice president of product management Guy Rosen said in a conference call updating the investigation.
The hackers - whose identities are still a mystery - accessed the names, phone numbers and email addresses of 15 million users, he said.
For another 14 million people, the attack was potentially more damaging.
Facebook said cyberattackers accessed that data plus additional information including gender, religion, hometown, birth date and places they had recently "checked in" to as visiting.
No data was accessed in the accounts of the remaining one million people whose "access tokens" were stolen, according to Rosen.
The attack did not affect Facebook-owned Messenger, Messenger Kids, Instagram, WhatsApp, Oculus, Workplace, Pages, payments, third-party apps or advertising or developer accounts, the company said.
Facebook said engineers discovered a breach on September 25 and had it patched two days later.
That breach allegedly related to a "view as" feature - described as a privacy tool to let users see how their profiles look to other people. That function has been disabled for the time being as a precaution.
Facebook reset the 50 million accounts believed to have been affected, meaning users would need to sign back in using passwords.
The breach was the latest privacy embarrassment for Facebook, which earlier this year acknowledged that tens of millions of users had their personal data hijacked by Cambridge Analytica, a political firm working for Donald Trump in 2016.
"We face constant attacks from people who want to take over accounts or steal information around the world," chief executive Mark Zuckerberg said on his own Facebook page when the breach was disclosed.
"While I''m glad we found this, fixed the vulnerability, and secured the accounts that may be at risk, the reality is we need to continue developing new tools to prevent this from happening in the first place."
Facebook said it took a precautionary step of resetting "access tokens" for another 40 million accounts which had accessed the "view as" function.
Hackers evidently started the cyber-onslaught on September 14 with 400,000 "seed accounts" they had a hand in or were otherwise close to, according to Rosen.
"The attackers started with a set of accounts they controlled directly, then moved to their friends, and their friend''s friends, and so on - each time taking advantage of the vulnerability," he added.
The exploit allowed hackers to steal copies of access tokens from accounts of "friends" by using the "view as" feature.
Once they had keys to accounts, hackers had the ability to get into them and control them as though they were the real owner.
Hackers could have seen the last four digits of credit card data in people''s accounts, with the rest hidden for security, but there was no sign that data was taken, according to Facebook.
Rosen said they found no reason yet to believe hackers were in interested in people''s information, rather that it appeared the mission was to harvest access tokens from friends associated with breached accounts.
He declined to discuss progress regarding figuring out who was behind the attack, saying Facebook had been asked by the FBI to remain quiet on the topic.
The California-based social network says it is cooperating with the FBI, US Federal Trade Commission, Irish Data Protection Commission and other authorities regarding the breach.
Rosen said the FBI investigation also limited what he could disclose about what the hackers'' end-goal may have been, but maintained that Facebook had "no reason to believe this attack was related to the mid-term elections" in the US.

Copyright Agence France-Presse, 2018

Comments

Comments are closed.