Entra ID & IdentityIncident TeardownsRetrospectives

Facebook's 'View As' Breach (Sept 2018): 50 Million Access Tokens Stolen

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from September 2018, written in 2026 with the benefit of hindsight.

On September 28, 2018, Facebook announced that attackers had exploited a vulnerability in its "View As" feature to steal access tokens. Facebook initially said almost 50 million accounts were affected and later said attackers had obtained data from about 29 million people.

How it happened

"View As" let users see how their profile appeared to others. A combination of three bugs in the feature and a video upload tool caused it to generate an access token for the user being viewed, rather than the user doing the viewing. Attackers chained this across friend networks to collect tokens for many accounts.

Why tokens matter

An access token is what keeps you signed in. Anyone holding a valid token can act as that user without knowing the password and without passing MFA. Facebook responded by resetting the tokens for roughly 90 million accounts, forcing those users to sign in again.

Why this matters for cloud identity

Token theft has become one of the most important attack techniques against Microsoft 365 and other cloud services. Attackers steal session cookies and tokens through phishing proxies, malware on endpoints and leaked logs. The defenses are the same principles Facebook was forced to apply:

  • Short token lifetimes and sign-in frequency controls for sensitive access.
  • Fast, reliable session revocation.
  • Binding tokens to devices so a stolen token can't be replayed elsewhere.
  • Detecting anomalous token use.

In hindsight

Facebook's incident was a platform bug, but the lesson generalizes: authentication is only as strong as the session it creates. Modern identity security focuses as much on protecting tokens after sign-in as on the sign-in itself.

facebook access token breachFacebook View As token theft2018

More on this story