Facebook stored hundreds of millions of passwords unprotected

Facebook mistakenly stored “hundreds of millions” of passwords in plaintext, unprotected by any encryption, the company has admitted.

The mistake, which led to user passwords being kept in Facebook’s internal servers in an insecure way, affects “hundreds of millions of Facebook Lite users, tens of millions of other Facebook users, and tens of thousands of Instagram users”, according to the social networking site. Facebook Lite is a version of Facebook created for use in nations where mobile data is unaffordable or unavailable.

In a statement, Facebook’s vice-president for engineering, security and privacy, Pedro Canahuati, said: “We have found no evidence to date that anyone internally abused or improperly accessed” the passwords, which “were never visible to anyone outside of Facebook”. Affected users will be directly notified.

Nonetheless, the risk of misuse was high. According to security reporter Brian Krebs, who cited a “senior Facebook insider”, “access logs showed some 2,000 engineers or developers made approximately nine million internal queries for data elements that contained plaintext user passwords”.

Facebook’s data centre in Sweden. Passwords were kept on the company’s servers in an insecure way. Photograph: David Levene/The Guardian
 Facebook’s data centre in Sweden. Passwords were kept on the company’s servers in an insecure way. Photograph: David Levene/The Guardian

Best practice for password security involves a number of precautions to ensure that, even if the company is hacked, stolen passwords cannot be used. Passwords should be “hashed”, a one-way process which transforms every password into a unique “hash”, and ideally “salted”, ensuring that even two identical passwords produce different hashes. Those are the security practices that Facebook normally takes, and which were overlooked in this case.

Canahuati said Facebook has now fixed this particular issue, as well as some problems the company has discovered in other security features, such as the code by which users log in through other apps.

The information commissioner’s office warns companies: “Do not store passwords in plaintext – make sure you use a suitable hashing algorithm, or another mechanism that offers an equivalent level of protection against an attacker deriving the original password.

“You should also ensure that the architecture around your password system does not allow for any inadvertent leaking of passwords in plaintext.” The guidance refers to the exact sort of error that Facebook admitted to on Thursday.

The ICO has not issued a fine purely for storing passwords in an insecure fashion, although it has cited insecure storage as an aggravating factor when penalising more serious data protection breaches.

The Guardian

Other News

SK Group partners to build AI ecosystem in Vietnam

SK Group partners to build AI ecosystem in Vietnam

SK Innovation and SK Telecom signed MoUs with Nghe An province and the National Innovation Centre of Vietnam to advance AI ecosystem development and support the country’s long-term growth strategy.

Vietnam Research Excellence Fellowship for 2026-2030 approved

Vietnam Research Excellence Fellowship for 2026-2030 approved

Under the Vietnam Research Excellence Fellowship (VREF) for the 2026–2030 period, PhD students are identified as a core research force directly contributing to breakthroughs in sci-tech and innovation. Investing in top-tier doctoral candidates is more than workforce development, but a high-stakes strategic bet to forge a cohort of world-class scientists and technologists who can power Vietnam’s long-term economic ambitions.

Strategic tech must address practical challenges: PM

Strategic tech must address practical challenges: PM

Prime Minister Pham Minh Chinh on March 28 said strategic technologies must tackle Vietnam’s practical challenges, while chairing a meeting of the Government’s Steering Committee for science and technology, innovation, digital transformation, and Project 06.

Ho Chi Minh City sets sights on becoming semiconductor hub

Ho Chi Minh City sets sights on becoming semiconductor hub

Ho Chi Minh City is stepping up efforts to attract investment from global leading groups and companies in the fields of electronic components, semiconductors and chip manufacturing as it seeks to position itself as a leading semiconductor industry hub in both the region and the world. 

Ho Chi Minh City launches upgraded technology exchange platform

Ho Chi Minh City launches upgraded technology exchange platform

The upgraded platform represents a comprehensive shift from a simple information-sharing model to a managed online technology trading system, enabling monitoring and measurement of real transaction outcomes. It is built on three pillars, namely new tradable technology products, a modern digital platform, and an improved operational model.

AI – unmissable opportunity for Vietnam: Experts

AI – unmissable opportunity for Vietnam: Experts

AI also emerges as a key enabler for Vietnam's ambition to build financial and technology hubs. Applications can boost efficiency, automate workflows, cut costs, and sharpen data analytics, which are essential pillars of a modern financial system.

PM calls for accelerated space technology development in Vietnam

PM calls for accelerated space technology development in Vietnam

Vietnam aims by 2030 to achieve a mid-level position in space science and technology development within Southeast Asia, and after 2030 to build national capabilities to independently develop satellite technologies and apply space data to address global challenges and national security needs.

High-level forum advances Vietnam–US technological cooperation

High-level forum advances Vietnam–US technological cooperation

A high-level executive leadership forum focusing on strengthening Vietnam - US relations through technology cooperation was jointly held in Washington D.C. on March 11 by the Embassy of Vietnam in the US, the Weatherhead East Asian Institute of Columbia University, and the US -ASEAN Business Council (USABC). 

AI Law takes effect, anchors national governance framework

AI Law takes effect, anchors national governance framework

While many countries are still drafting policy blueprints or issuing non-binding guidance, Vietnam has moved ahead with a standalone Law on Artificial Intelligence (AI), effective from March 1, placing it among a select group of nations to adopt dedicated AI legislation at the parliamentary level. 

Vietnam International Defence Expo 2026 preparations move into high gear

Vietnam International Defence Expo 2026 preparations move into high gear

Vietnam International Defence Expo 2026, themed “Peace, Friendship, Cooperation and Development,” will be organised on a larger scale, featuring a wide array of weapons and technical equipment alongside product exhibitions, seminars and panel discussions, drills, live field demonstrations, and business networking activities.

Ministry requests urgent measures to counter UAVs threatening aviation safety

Ministry requests urgent measures to counter UAVs threatening aviation safety

Ministry of Construction requested the Ministry of National Defence, the Ministry of Public Security and provincial and municipal steering committees for counter-terrorism to strengthen the management, inspection and supervision of UAVs and other aerial devices, ensuring strict compliance with Decree No. 288/2025/ND-CP and relevant legal regulations.