Facebook stored hundreds of millions of passwords unprotected

Facebook mistakenly stored “hundreds of millions” of passwords in plaintext, unprotected by any encryption, the company has admitted.
  • Nearly half million email addresses and passwords of Vietnamese users leaked
  • Google removes several blogs, YouTube accounts linked to Iran
  • Twitter suspends over 70 million accounts in two months: Washington Post
  • Facebook to remove accounts assuming names of leaders of Party and State

The mistake, which led to user passwords being kept in Facebook’s internal servers in an insecure way, affects “hundreds of millions of Facebook Lite users, tens of millions of other Facebook users, and tens of thousands of Instagram users”, according to the social networking site. Facebook Lite is a version of Facebook created for use in nations where mobile data is unaffordable or unavailable.

In a statement, Facebook’s vice-president for engineering, security and privacy, Pedro Canahuati, said: “We have found no evidence to date that anyone internally abused or improperly accessed” the passwords, which “were never visible to anyone outside of Facebook”. Affected users will be directly notified.

Nonetheless, the risk of misuse was high. According to security reporter Brian Krebs, who cited a “senior Facebook insider”, “access logs showed some 2,000 engineers or developers made approximately nine million internal queries for data elements that contained plaintext user passwords”.

Facebook’s data centre in Sweden. Passwords were kept on the company’s servers in an insecure way. Photograph: David Levene/The Guardian
 Facebook’s data centre in Sweden. Passwords were kept on the company’s servers in an insecure way. Photograph: David Levene/The Guardian

Best practice for password security involves a number of precautions to ensure that, even if the company is hacked, stolen passwords cannot be used. Passwords should be “hashed”, a one-way process which transforms every password into a unique “hash”, and ideally “salted”, ensuring that even two identical passwords produce different hashes. Those are the security practices that Facebook normally takes, and which were overlooked in this case.

Canahuati said Facebook has now fixed this particular issue, as well as some problems the company has discovered in other security features, such as the code by which users log in through other apps.

The information commissioner’s office warns companies: “Do not store passwords in plaintext – make sure you use a suitable hashing algorithm, or another mechanism that offers an equivalent level of protection against an attacker deriving the original password.

“You should also ensure that the architecture around your password system does not allow for any inadvertent leaking of passwords in plaintext.” The guidance refers to the exact sort of error that Facebook admitted to on Thursday.

The ICO has not issued a fine purely for storing passwords in an insecure fashion, although it has cited insecure storage as an aggravating factor when penalising more serious data protection breaches.

The Guardian

Other News

Vietnam attends SAHA 2026 defence, aerospace exhibition in Türkiye

Vietnam attends SAHA 2026 defence, aerospace exhibition in Türkiye

Vietnam’s participation in SAHA 2026 International Defence & Aerospace Exhibition in Istanbul reflects the country’s consistent policy of enhancing international defence integration and promoting defence industry cooperation towards self-reliance, self-strengthening, modernisation and dual-use development.

SK Group partners to build AI ecosystem in Vietnam

SK Group partners to build AI ecosystem in Vietnam

SK Innovation and SK Telecom signed MoUs with Nghe An province and the National Innovation Centre of Vietnam to advance AI ecosystem development and support the country’s long-term growth strategy.

Vietnam Research Excellence Fellowship for 2026-2030 approved

Vietnam Research Excellence Fellowship for 2026-2030 approved

Under the Vietnam Research Excellence Fellowship (VREF) for the 2026–2030 period, PhD students are identified as a core research force directly contributing to breakthroughs in sci-tech and innovation. Investing in top-tier doctoral OK9 Cabidates is more than workforce development, but a high-stakes strategic bet to forge a cohort of world-class scientists and technologists who can power Vietnam’s long-term economic ambitions.

Strategic tech must address practical challenges: PM

Strategic tech must address practical challenges: PM

Prime Minister Pham Minh Chinh on March 28 said strategic technologies must tackle Vietnam’s practical challenges, while chairing a meeting of the Government’s Steering Committee for science and technology, innovation, digital transformation, and Project 06.

Ho Chi Minh City sets sights on becoming semiconductor hub

Ho Chi Minh City sets sights on becoming semiconductor hub

Ho Chi Minh City is stepping up efforts to attract investment from global leading groups and companies in the fields of electronic components, semiconductors and chip manufacturing as it seeks to position itself as a leading semiconductor industry hub in both the region and the world. 

Ho Chi Minh City launches upgraded technology exchange platform

Ho Chi Minh City launches upgraded technology exchange platform

The upgraded platform represents a comprehensive shift from a simple information-sharing model to a managed online technology trading system, enabling monitoring and measurement of real transaction outcomes. It is built on three pillars, namely new tradable technology products, a modern digital platform, and an improved operational model.

AI – unmissable opportunity for Vietnam: Experts

AI – unmissable opportunity for Vietnam: Experts

AI also emerges as a key enabler for Vietnam's ambition to build financial and technology hubs. Applications can boost efficiency, automate workflows, cut costs, and sharpen data analytics, which are essential pillars of a modern financial system.

PM calls for accelerated space technology development in Vietnam

PM calls for accelerated space technology development in Vietnam

Vietnam aims by 2030 to achieve a mid-level position in space science and technology development within Southeast Asia, and after 2030 to build national capabilities to independently develop satellite technologies and apply space data to address global challenges and national security needs.

High-level forum advances Vietnam–US technological cooperation

High-level forum advances Vietnam–US technological cooperation

A high-level executive leadership forum focusing on strengthening Vietnam - US relations through technology cooperation was jointly held in Washington D.C. on March 11 by the Embassy of Vietnam in the US, the Weatherhead East Asian Institute of Columbia University, and the US -ASEAN Business Council (USABC).