The SecNews research team has identified a critical vulnerability in Facebook, which could affect anyone who, at least once in their life, had created an account on the platform, even if it is now deactivated.
SecNews, as part of its research to find vulnerabilities and security gaps in the most popular social networking platforms, recently identified something that will surely surprise you and further increase your concerns about how to secure your personal life online.
What actually happened?
Within the scope of the research, security experts conducted an experiment whose results are “mind blowing”.
Three months ago, a SecNews security researcher created a GMX mail, account which he will use to create a Facebook account in order to test the registration process offered by the platform.
As you will see in the screenshot, the GMX account was created on September 2, 2019 and the Facebook account was created today, November 29, 2019.
![Vulnerability in Facebook allows full access to your account by third parties without your knowledge! [SecNews research] 1 Facebook vulnerability allows third parties to fully access your account without your knowledge! [SecNews investigation]](https://cdnglobal.secnews.gr/wp-content/uploads/2019/11/18224407/facebook-secnews-12.png)
The researcher attempted to register officially on the social networking platform, following all the required steps.
![Vulnerability in Facebook allows full access to your account by third parties without your knowledge! [SecNews research] 2 Facebook](https://cdnglobal.secnews.gr/wp-content/uploads/2019/11/18224405/facebook-secnews-10.png)
Once the registration was completed, the researcher suddenly was logged into a user's account from India.
![Vulnerability in Facebook allows full access to your account by third parties without your knowledge! [SecNews research] 3 Facebook vulnerability allows third parties to fully access your account without your knowledge! [SecNews investigation]](https://cdnglobal.secnews.gr/wp-content/uploads/2019/11/18224409/facebook-secnews-4.png)
Surprised that he had so easily gained access to another user's account and since he had reset his password for security reasons, he browsed the profile to see if it was indeed a logical error on Facebook's part.
After researching the profile, it turns out to be an account that was created in 2015, remained active for a year and a half, and then the account was deactivated.
![A vulnerability in Facebook allows full access to your account by third parties without your knowledge! [SecNews research] 4 Facebook](https://cdnglobal.secnews.gr/wp-content/uploads/2019/11/18224402/facebook-secnews-31.png)
![Facebook vulnerability allows full access to your account by third parties without your knowledge! [SecNews research] 5 Facebook vulnerability allows third parties to fully access your account without your knowledge! [SecNews investigation]](https://cdnglobal.secnews.gr/wp-content/uploads/2019/11/18224412/facebook-secnews-2.png)
The fact that another user - from the other side of the world - managed to activate the account without needing anything more than registering on the platform proves that, once again, the way Facebook handles our data and personal information is dangerous and even if we think that by deactivating our account we will be safe, in the end it is not.
SecNews conducted a thorough investigation of both the Facebook account and the email address associated with it.
"There is a high probability that a user in India previously owned the specific email address with which he had linked his Facebook account. The email address was either no longer in use or had been blocked by the email service , resulting in the Facebook account being blocked as well," the security researcher specifically emphasized.
The email address was likely offered for reuse. Facebook, although completely different information was provided during registration than that of the original profile, automatically activated the account without any additional verification measures.
It's worth noting that according to Facebook's privacy policy, the platform states that "You will not be able to reactivate your account" after 30 days. In this case, three years had passed.
![Vulnerability in Facebook allows full access to your account by third parties without your knowledge! [SecNews research] 6 Facebook](https://cdnglobal.secnews.gr/wp-content/uploads/2019/11/18224415/%CF%83%CE%B5%CE%BD-%CE%B5%CF%81%CE%B5%CF%85%CE%BD%CE%B1-2.png)
Ultimately, how easy is it, information as well as entire accounts that you may have deleted in the past to “fall” into the wrong hands while you feel safe?
How many more Facebook errors do we need to understand that "what goes up is never lost"?
SecNews confirms the validity of this specific incident.
For GDPR and privacy reasons, sensitive information in the screenshots has been hidden.
For further questions on the topic you can contact our website.
This has been shared on Facebook as well and we await an official response from the popular platform regarding the incident.
