

Any old token you had is no longer valid, not for you and not for an attacker either. But many Facebook users don't use 2-factor authentication.Īction has already been taken for you. If your account had 2fa, it seems unlikely that an attacker could use this exploit to get into it. Is that incident normal or I should take security actions? Tl dr: Facebook account suddenly got logged out of all devices, password was not changed, logged in entries are gone, no email warning about account being compromised, no two-factor authentication prompt showed up.Īre there any chances that someone was successfully able to get into my account? If yes, then how could they bypass the two-factor authentication? However, I did not get any suspicious prompt on my phone to authenticate an unusual log in (Like "Did you just logged in near location xxxxx?"), also no warning email from my registered email telling me about my account being accessed on an unrecognized browser or computer. I was thinking of someone had tried (and succeeded?) to access my account, then logged out of all current sessions. The only entries I got were those log in on my phone and my laptop (also appeared to be my trusted devices).

After I logged back in, I went to security under settings and checked the section "When you're logged in" and I saw that all of the past logged in entries are gone. Before, long time ago, when I created this account, I'd set up two-factor authentication for my account and when I checked after I did the log in, it was still active.Īfter that, I opened my laptop and Chrome then went to Facebook, just to find out that the session on PC was also logged out. I then tried logging in with my current password and was success to log in my account.

#Facebook session expired 1 22 21 android#
A while ago, I was opening Facebook app on Android and then I got the message "Session expired.
