Hackers accessed data of 30 million Facebook users

Agencies
October 13, 2018

Washington, Oct 13: Social media giant Facebook, which has its largest user base in India, said that a recent hacking into its system has affected about 30 million users.

Facebook product management vice president Guy Rosen on Friday said the cyber attackers exploited a vulnerability in Facebook's code that existed between July 2017 and September 2018.

The vulnerability has now been fixed, but not before the attackers used an automated technique to move from account to account so they could steal the access tokens of users, their friends, friends of their friends, and so on, totalling about 400,000 people.

"The attackers used a portion of these 400,000 people's lists of friends to steal access tokens for about 30 million people. For 15 million people, attackers accessed two sets of information, name and contact details -- phone number, email, or both, depending on what people had on their profiles," Rosen said.

For another 14 million people, the attack was potentially more damaging as the hackers accessed both their name and contact details as well as other details like username, gender, location, language, relationship status, religion, hometown, date of birth, device types used to access Facebook, education, work details, places they have recently "checked in" to as visiting, people or pages they follow and the 15 most recent searches.

For the remaining one million people whose access token were stolen, the attackers did not access any information, Rosen said. He said users' accounts have already been secured by the Facebook two weeks ago and they do not need to log out again or change their passwords. The attack did not affect Facebook-owned Messenger, Messenger Kids, Instagram, WhatsApp, Oculus, Workplace, third-party apps, payments, Pages, and advertising or developer accounts, the company said.

Asserting that Facebook is still looking at other ways the hackers may have used the platform, Rosen said, "People's credit card information would not have been visible to the attackers, as we do not display full credit card numbers -- not even to the account holder."

"We haven't ruled out the possibility of smaller-scale, low-level access attempts during the time the vulnerability was exposed. Our investigation into that continues," he said.

Facebook has been cooperating with the FBI, the US Federal Trade Commission, the Irish Data Protection Commission and other authorities.

"We don't have a specific indication of the intention of the attackers. And as we have said, we are cooperating with the FBI in an active investigation. As part of the information that we will be sharing with users over the coming days, we will be including information as to how they can watch out for any suspicious e-mails or text messages or things of that sort," Rosen said.

Responding to a question, he said, the company will be notifying people through Facebook so that they can understand what information was accessed from their account and which group they were part of.

"We will also work to contact people who may not be on Facebook any longer," he said.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 26,2025

Mangaluru, Nov 26: Mangaluru East police have registered a case following a sophisticated online fraud where a 57-year-old local resident was allegedly cheated out of ₹13.4 lakh after being targeted on Facebook.

The scam began in February when the complainant, while browsing Facebook reels, was contacted by a woman identifying herself as "Lillian Mary George" from London. After establishing a chat relationship, the woman claimed she would visit India in November and bring a significant sum of money.

The trap was sprung on November 15, when the victim received a call from a woman named "Sonali Gupta," who claimed Lillian had arrived at Mumbai International Airport but was detained by customs. The fraudsters convinced the man that Lillian was carrying £25,000 (about ₹26 lakh) in traveller’s cheques and 1 kg of gold (valued at around ₹30 lakh).

Under the pretense of clearing these items, the victim was asked to make numerous online transfers between November 15 and 18 for various bogus charges, including:

•    "Pounds exchange registration"
•    "Customs declaration issues"
•    "Discount charges"
•    "Money-laundering charges"

Believing the fictitious story, the complainant transferred the cumulative sum of ₹13.4 lakh to various bank accounts provided by the fraudsters. He realised he was cheated when the culprits later promised a refund within two days but stopped answering his calls. The Mangaluru East police are now investigating the case, which highlights the continuing threat of transnational cyber fraud using social engineering and promises of fictitious wealth.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
coastaldigest.com news network
December 2,2025

karkala.jpg

Udupi, Dec 2: A wave of regional pride is sweeping through Udupi district as Shagun S Verma Hegde, a talented Class 9 student from Christ King English Medium High School, Karkala, has been named the captain of the Indian National Team for the Under-15 Girls’ Volleyball Championship.

Shagun holds the unique distinction of being the sole player from Karnataka selected to represent the country in the prestigious international tournament. The championship, organized by the School Games Federation, is scheduled to take place in Shangluo, China, from December 3 to 13, where Shagun will lead the national squad.

A Remarkable Journey to the Top

Shagun’s selection is a testament to her dedication and exceptional skill on the court. Her journey included several rigorous rounds of selection:

•    She was the only player from Udupi district to qualify for the state-level selection camp.

•    Out of eight players from Karnataka who advanced to the national selection camp in Pune, Maharashtra, Shagun was the only one to secure a place in the final national squad.

•    The national camp saw participation from approximately 200 players, which was shortlisted to 23. Shagun not only made the final cut but was also ranked as the second-best player overall, solidifying her leadership role.

Shagun, who is the daughter of Sandesh Verma and Shruthiraj of Kallotte, Karkala, has trained under experienced coaches Santosh D’Souza, Jeevan D’Silva, Jairaj Poojary, and Ramesh. Her selection as the team captain has brought profound honour to her family, school, the Udupi district, and the entire state of Karnataka.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
December 5,2025

indigoCEO.jpg

New Delhi, Dec 5: IndiGo CEO Pieter Elbers issued a public apology this evening after more than a thousand flights were cancelled today, making it the "most severely impacted day" in terms of cancellations. The biggest airline of the country cancelled "more than half" of its daily number of flights on Friday, said Elbers. He also said that even though the crisis will persist on Saturday, the airline anticipates fewer than 1,000 flight cancellations.

"Full normalisation is expected between December 10 and 15, though IndiGo cautions that recovery will take time due to the scale of operations," the IndiGo CEO said. 

IndiGo operates around 2,300 domestic and international flights daily.

Pieter Elbers, while apologising for the major inconvenience due to delays and cancellations, said the situation is a result of various causes.

The crisis at IndiGo stems from new regulations that boost pilots' weekly rest requirements by 12 hours to 48 and allow only two night-time landings per week, down from six. IndiGo has attributed the mass cancellations to "misjudgment and planning gaps".

Elbers also listed three lines of action that the airline will adopt to address the issue.

"Firstly, customer communication and addressing your needs, for this, messages have been sent on social media. And just now, a more detailed communication with information, refunds, cancellations and other customer support measures was sent," he said.

The airline has also stepped up its call centre capacity.

"Secondly, due to yesterday's situation, we had customers stranded mostly at the nation's largest airports. Our focus was for all of them to be able to travel today itself, which will be achieved. For this, we also ask customers whose flights are cancelled not to come to the airports as notifications are sent," the CEO said.

"Thirdly, cancellations were made for today to align our crew and planes to be where they need to start tomorrow morning afresh. Earlier measures of the last few days, regrettable, have proven not to be enough, but we have decided today to reboot all our systems and schedules, resulting in the highest numbers of cancellations so far, but imperative for progressive improvements starting from tomorrow," he added.

As airports witnessed chaotic scenes, the Directorate General of Civil Aviation (DGCA) stepped in to grant IndiGo a temporary exemption from stricter night duty rules for pilots. It also allowed substitution of leaves with a weekly rest period. 

Civil Aviation Minister Ram Mohan Naidu has said a high-level inquiry will be ordered and accountability will be fixed.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.