Facebook this week informed users that it has partially restored a privacy feature abused by hackers last year as part of an attack that impacted 29 million accounts.
The social media giant informed customers in late September 2018 that hackers had exploited a series of vulnerabilities to steal tokens that could be used to access 50 million Facebook accounts. The company later told users that the attack, reportedly launched by spammers who wanted to make a profit through deceptive advertising, actually impacted only 29 million accounts.
According to Facebook, for 15 million of the affected users, the hackers accessed names, phone numbers and email addresses. For the remaining 14 million, they also accessed gender, hometown, date of birth, religion, and information on the places they had checked into.
In response to the breach, Facebook invalidated access tokens for nearly 90 million accounts and launched a tool that told users whether or not their account was impacted.
The attack involved three distinct flaws affecting the “View As” feature and a version of Facebook’s video uploader interface introduced in July 2017.
“View As” is a privacy feature that shows users how others, including specific friends or users they are not friends with (View As Public), see their profile. The feature is designed to help users ensure that they only share information with the intended audience.
Facebook disabled the “View As” feature following the massive breach, but it has partially re-enabled it this week. In an update to its initial blog post and on Twitter, the company said it restored the “View As Public” feature after completing its security review and determining that it was not involved in the incident.
The “View As Specific Person” feature remains disabled. However, Facebook says the “View As Public” version was much more popular. Facebook is likely restoring the feature gradually as it’s still not available to all users.
Related: Industry Reactions to Facebook Hack
Related: Is Facebook Out of Control? Investigations and Complaints Are Rising
Related: Zuckerberg Defends Facebook in New Data Breach Controversy
Related: UK Regulator Hits Facebook With Maximum Fine

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.
More from Eduard Kovacs
- Ransomware Group Used MOVEit Exploit to Steal Data From Dozens of Organizations
- Cybersecurity M&A Roundup: 36 Deals Announced in May 2023
- In Other News: Government Use of Spyware, New Industrial Security Tools, Japan Router Hack
- Apple Denies Helping US Government Hack Russian iPhones
- Zero-Day in MOVEit File Transfer Software Exploited to Steal Data From Organizations
- Russia Blames US Intelligence for iOS Zero-Click Attacks
- Cisco Acquiring Armorblox for Predictive and Generative AI Technology
- Moxa Patches MXsecurity Vulnerabilities That Could Be Exploited in OT Attacks
Latest News
- What if the Current AI Hype Is a Dead End?
- Microsoft Makes SMB Signing Default Requirement in Windows 11 to Boost Security
- Zyxel Urges Customers to Patch Firewalls Against Exploited Vulnerabilities
- Gigabyte Rolls Out BIOS Updates to Remove Backdoor From Motherboards
- SBOMs – Software Supply Chain Security’s Future or Fantasy?
- Ransomware Group Used MOVEit Exploit to Steal Data From Dozens of Organizations
- Cybersecurity M&A Roundup: 36 Deals Announced in May 2023
- Insider Q&A: Artificial Intelligence and Cybersecurity In Military Tech
