{"id":13572,"date":"2018-10-12T10:45:21","date_gmt":"2018-10-12T18:45:21","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2018\/10\/12\/news-7339\/"},"modified":"2018-10-12T10:45:21","modified_gmt":"2018-10-12T18:45:21","slug":"news-7339","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2018\/10\/12\/news-7339\/","title":{"rendered":"How to Check If Your Facebook Account Got Hacked\u2014And How Badly"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/5bc0e2a080ec002859e56bef\/master\/pass\/FacebookToken-BW-151811218.jpg\"\/><\/p>\n<p><strong>Credit to Author: Brian Barrett| Date: Fri, 12 Oct 2018 18:32:27 +0000<\/strong><\/p>\n<p><span class=\"lede\">At the end <\/span>of last month, <a href=\"http:\/\/www.wired.com\/tag\/facebook\">Facebook<\/a> made a <a href=\"https:\/\/www.wired.com\/story\/cybersecurity-disclosure-gdpr-facebook-google\/\">bombshell disclosure<\/a>: As <a href=\"https:\/\/wired.com\/story\/facebook-security-breach-50-million-accounts\/\">many as 90 million of its users<\/a> may have had their so-called access tokens\u2014which keep you logged into your account, so you don&#x27;t have to sign in every time\u2014stolen by hackers. Friday, the company put the actual number at 30 million. Here&#x27;s how to see if you were one of them, and if so, what the hackers got from your account.<\/p>\n<p>There might understandably be some confusion around the matter; a few weeks ago, Facebook logged out 90 million of its users out of an abundance of caution, making them reset their passwords and negating the access token hack. Over the next few days, Facebook will insert a customized message into the News Feeds of the 30 million people whose accounts were actually impacted, based on the extent of the damage.<\/p>\n<p class=\"paywall\">&quot;People\u2019s accounts have already been secured by the action we took two weeks ago to reset the access tokens for people who were potentially exposed\u2014no one needs to log out again, and no one needs to change their password,&quot; says Guy Rosen, Facebook&#x27;s vice president of product management. &quot;We\u2019ll be explaining what information the attackers may have accessed as well as steps they can take to help protect themselves from any suspicious emails or text messages or calls that could potentially result from this kind of information being exposed. &quot;<\/p>\n<p class=\"paywall\">If you don&#x27;t want to wait for the message to hit your News Feed to find out if you&#x27;re okay, go ahead and see if you were among those hit <a href=\"https:\/\/www.facebook.com\/help\/securitynotice?ref=sec\" target=\"_blank\">at this page<\/a>. Across past the background paragraph, and you\u2019ll see a header that reads <strong>Is my Facebook account impacted by this security issue?<\/strong><\/p>\n<p class=\"paywall\">From there, you\u2019ll see one of three outcomes. If it says that based on what Facebook knows so far, you\u2019re not impacted, you should be in the clear pending any revelations. The company says that one million of the 30 million people who had their access tokens stolen didn\u2019t have any of their data comprised.<\/p>\n<p class=\"paywall\">The remaining 29 million users will see one of two messages, depending on the extent of the damage. Fifteen million of them had their name, email addresses, and phone number accessed by hackers. While that\u2019s not ideal by any accounting, the remaining 14 million Facebook users are left with a much worse result.<\/p>\n<p class=\"paywall\">In addition to the basic contact information above, the list of details hackers accessed is long: username, date of birth, gender, devices you used Facebook on, and your language settings, at the very least. If you filled out the relationship status, religion, hometown, current city, work, education, or website sections of your profile, they got that too. And most unsettling of all, they could have accessed the 10 most recent locations you checked into or were tagged in, and the 15 most recent searches you\u2019ve entered into the Facebook search bar.<\/p>\n<p>&quot;No one needs to log out again, and no one needs to change their password.&quot;<\/p>\n<p name=\"inset-left\" class=\"inset-left-component__el\">Guy Rosen, Facebook<\/p>\n<p class=\"paywall\">Facebook says they\u2019ve seen no signs yet that attackers used its access tokens to <a href=\"https:\/\/wired.com\/story\/facebook-security-breach-third-party-sites\/\">infiltrate third-party apps and services<\/a>, as was <a href=\"https:\/\/wired.com\/story\/facebook-hack-single-sign-on-data-exposed\/\">technically possible<\/a>. And it maintains that no account passwords or credit card information was compromised. But the amount of information, and its sensitive nature, should be a boon to phishers and scammers for years to come. You can change your password or cancel a credit card. Your hometown will always be just that. And where you\u2019ve been and whom you\u2019ve searched for are deeply personal parts of your life, both online and in the real world.<\/p>\n<p class=\"paywall\">Facebook at least acknowledges this in its support page, offering some advice about <a href=\"https:\/\/www.wired.com\/story\/resist-phishing-attacks\/\">how to avoid phishing attempts<\/a>, like being \u201ccautious of unwanted phone calls, text messages or emails from people you don&#x27;t know.\u201d Presumably, you were doing this anyway. The rest of the advice is similarly rudimentary, but that\u2019s in part because there\u2019s only so much you can do to stop that kind of attack. If a determined phisher wants to get you, they <a href=\"https:\/\/www.wired.com\/story\/phishing-attempts-email-inbox\/\">almost certainly will eventually<\/a>. Especially if they have access to the kind of data that Facebook\u2019s security fail has given away.<\/p>\n<p class=\"related-cne-video-component__dek\">It seems like every time you turn around there&#39;s a new breach of personal information. Follow these steps to minimize the damage.<\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/facebook-hack-check-if-account-affected\" target=\"bwo\" >https:\/\/www.wired.com\/category\/security\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/5bc0e2a080ec002859e56bef\/master\/pass\/FacebookToken-BW-151811218.jpg\"\/><\/p>\n<p><strong>Credit to Author: Brian Barrett| Date: Fri, 12 Oct 2018 18:32:27 +0000<\/strong><\/p>\n<p>Facebook Friday offered more details about its recent breach. Here&#8217;s how to see if you were affected.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10607],"tags":[714],"class_list":["post-13572","post","type-post","status-publish","format-standard","hentry","category-security","category-wired","tag-security"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/13572","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=13572"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/13572\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=13572"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=13572"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=13572"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}