Celebrate King's Day with TNW 🎟 Use code GEZELLIG40 on your Business, Investor and Startup passes today! This offer ends on April 29 →

This article was published on October 29, 2013

Buffer confirms hackers stole users’ Twitter and Facebook tokens, but billing information unaffected


Buffer confirms hackers stole users’ Twitter and Facebook tokens, but billing information unaffected

buffer1-520x199Users of Buffer — the tool that allows you to schedule your social media across timezones — faced a nasty surprise when Buffer was hacked over the weekend and the service began spreading scam links. The Buffer team has finally learned how the hackers breached its system and closed the vulnerability, Joel Gascoigne, founder and CEO of the company wrote in an update to a blog post today.

The hackers managed to steal some of Buffer’s Facebook and Twitter access tokens from its users, resulting in the breach. However — more importantly — the hackers did not access any passwords, billing information or any other user information.

Buffer has since invalidated all Twitter access tokens and added encryption for all of them, while it has added an extra security parameter to all its Facebook API keys.

Buffer says: “With these improvements your Twitter and Facebook accounts are not at risk anymore. Attackers will not be able to use this method to send spam anymore.”

Buffer security breach has been resolved – here is what you need to know [Buffer Blog]

Get the TNW newsletter

Get the most important tech news in your inbox each week.

Also tagged with