Facebook has discovered a security issue affecting about 50 million user accounts, the company said on Friday.
Facebook said attackers stole Facebook access tokens through its "view as" feature, which they could then use to take over people's accounts. "View as" is a feature that allows users to see what their own profile looks like to someone else.
"Since we’ve only just started our investigation, we have yet to determine whether these accounts were misused or any information accessed," the company said in a blog post.
Facebook shares fell 3 per cent to $163.78 in afternoon trading.
Facebook is grappling with the worst crisis in its history, vilified for not more zealously guarding the information that users share.
The Silicon Valley-based internet colossus faced intense global scrutiny over the mass harvesting of personal data by Cambridge Analytica, a British political consultancy that worked for Donald Trump's 2016 election campaign.
The company has admitted up to 87 million users may have had their data hijacked in the scandal.
Facebook's acknowledgement came after a study by two US universities, first reported by news website Gizmodo, found that phone numbers given to Facebook for two-factor authentication were also used to target advertising.
"We use the information people provide to offer a better, more personalised experience on Facebook, including ads," a Facebook spokesperson has been quoted as saying by news agency AFP.
"We are clear about how we use the information we collect, including the contact information that people upload or add to their own accounts. you can manage and delete contact information you've uploaded at any time."
Two-factor authentication is intended to enhance security by requiring a second step, such as entering codes sent via text messages, as well as passwords to get into accounts.