Up to 1 million Facebook users may have had their login details stolen by malicious Android and Apple apps.
The social media company says it is reaching out to inform those impacted.
Parent company Meta found more than 400 malicious apps that were designed to steal logins for the platform.
These apps were disguised as games, photo editors and health services.
Meta says it has removed the apps in question and is urging people to watch out for the telltale signs of a scam app.
This includes looking at an app's download count, rating and reviews.