Facebook's 'View As' Breach (Sept 2018): 50 Million Access Tokens Stolen
Retrospective: this article looks back at events from September 2018, written in 2026 with the benefit of hindsight.
On September 28, 2018, Facebook announced that attackers had exploited a vulnerability in its "View As" feature to steal access tokens. Facebook initially said almost 50 million accounts were affected and later said attackers had obtained data from about 29 million people.
How it happened
"View As" let users see how their profile appeared to others. A combination of three bugs in the feature and a video upload tool caused it to generate an access token for the user being viewed, rather than the user doing the viewing. Attackers chained this across friend networks to collect tokens for many accounts.
Why tokens matter
An access token is what keeps you signed in. Anyone holding a valid token can act as that user without knowing the password and without passing MFA. Facebook responded by resetting the tokens for roughly 90 million accounts, forcing those users to sign in again.
Why this matters for cloud identity
Token theft has become one of the most important attack techniques against Microsoft 365 and other cloud services. Attackers steal session cookies and tokens through phishing proxies, malware on endpoints and leaked logs. The defenses are the same principles Facebook was forced to apply:
- Short token lifetimes and sign-in frequency controls for sensitive access.
- Fast, reliable session revocation.
- Binding tokens to devices so a stolen token can't be replayed elsewhere.
- Detecting anomalous token use.
In hindsight
Facebook's incident was a platform bug, but the lesson generalizes: authentication is only as strong as the session it creates. Modern identity security focuses as much on protecting tokens after sign-in as on the sign-in itself.
- How to Configure Token Lifetimes and Sign-In Frequency in Conditional Access How-To & Hardening
- Detecting Access Token Theft: Entra Sign-In Logs and Sentinel KQL Detection & Response
- CIO Brief: Stolen Tokens Bypass Passwords and MFA — What That Means for You CIO Briefings