Facebook stored passwords in plain text for hundreds of millions of users

Between 200 million and 600 million Facebook users were affected.
Facebook stored passwords in plain text for hundreds of millions of users
Hundreds of millions of Facebook users had their passwords stored in plain text, accessible by company employees, according to an internal security review. Credit: Florian Gaertner/Photothek via Getty Images

Hundreds of millions of Facebook users’ passwords were stored in plain text, completely searchable by Facebook employees for years.

Some users had their passwords stored in plain text as early as 2012, according to a senior Facebook source who spoke to KrebsOnSecurity. The source, speaking on condition of anonymity, says that somewhere between 200 million and 600 million Facebook users were affected. More than 20,000 Facebook employees would have had access to these plain text passwords.

Shortly after KrebsOnSecurity published its story, Facebook posted its own statement by its vice president of engineering, security and privacy, Pedro Canahuati. He states that the company first discovered the issue during “a routine security review in January.”

The users most affected by the security lapse are those who use the social network’s “lower connectivity” client, Facebook Lite. The company estimates that hundreds of millions of Facebook Lite users and tens of millions of “other” Facebook users had their passwords stored in plain text. Tens of thousands of Instagram users also were also affected.

Tens of thousands of Instagram users also were also affected

Facebook claims that no one outside of the company was able to view the passwords and that it has found no evidence that anyone working at the social network “abused or improperly accessed them.” According to KrebsOnSecurity’s source, around 2,000 engineers or developers queried data that contained plain text passwords approximately 9 million times.

“We have fixed these issues and as a precaution we will be notifying everyone whose passwords we have found were stored in this way,” stated Canahuati.

At this point, Facebook is no stranger to security failures. In one recent breach reported in October 2018, personal information of tens of millions of Facebook users were accessed by hackers. Just two months later, the company shared that millions of its users’ photos leaked to third-party developers who never had permission to view them in a completely separate breach.

Facebook is not forcing affected users to change their passwords at this time.

Mashable Potato

Recommended For You
How hackers are stealing millions from ATMs, FBI warns
a card being inserted into an atm

Grok is producing millions of sexualized images of adults and children
A sign next to bus stop in London reads "Who the hell would want to use social media with a built-in child abuse tool?" and a photo of Elon Musk.


Hackers target millions of iPhones with new DarkSword spyware
iPhone on keyboard

3 AdultFriendFinder features exclusive to paid users
By Jack Dawes
Plus signs coming out of treasure chest

More in Tech

Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

NYT Connections hints today: Clues, answers for April 4, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone

Wordle today: Answer, hints for April 4, 2026
Wordle game on a smartphone

Google launches Gemma 4, a new open-source model: How to try it
Google Gemma
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!