Data breach
- Records
- 481,733,902
- Breach date
- 1 August 2019Estimated
- Added
- 1 December 2024
What was exposed
5 types of data
- Names481,615,728
- Phone numbers296,595,679
- Employment80,269,464
- Job titles80,269,464
- Email addresses2,287,172
About this breach
In early April 2021, personal data belonging to hundreds of millions of Facebook users appeared for free on a low-level hacking forum, reviving a data collection first exposed in 2019. The information, which included phone numbers and profile details, had been scraped from the platform before Facebook patched the underlying issue in August 2019.
The story traces back to 2019. On September 4, 2019, TechCrunch reported that an unsecured, password-free server held more than 419 million records containing Facebook users' phone numbers and account IDs, including 133 million records on US users. The server was taken offline after the web host was contacted. Facebook said at the time that the data was old and had been scraped before the company removed people's ability to find others by phone number.
Then on April 3, 2021, Business Insider reported that the full dataset, covering users in 106 countries, had been published on a hacking forum for free. Alon Gal of the cybercrime intelligence firm Hudson Rock discovered the posting. Earlier, in January 2021, a bot on the same forum had advertised the same data for a price.
Breach Timeline
August 2019: Facebook says it found and fixed the vulnerability in its contact importer feature that allowed malicious actors to scrape user data, according to a company blog post.
September 4, 2019: TechCrunch reports an unsecured server containing more than 419 million records of Facebook users' phone numbers and Facebook IDs.
April 3, 2021: Business Insider reports that personal data from 533 million Facebook users in 106 countries was posted for free on a hacking forum.
April 6, 2021: Facebook publishes a blog post explaining that the data was scraped before September 2019 through its contact importer feature, not obtained by hacking its systems.
What Information Was Compromised?
Our analysis found the following data types in this breach: names for 481,615,728 individuals, phone numbers for 296,595,679, job titles for 80,269,464, and email addresses for 2,287,172.
Reporting by Business Insider described additional details in the wider dataset, including Facebook IDs, locations, birthdates, and bios, though the presence and extent of these fields varied by record. Facebook stated in its 2021 response that the data did not include financial information, health information, or passwords.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Phone numbers linked to names are valuable to criminals even years after collection. Security experts cited by NPR in April 2021 warned that the data leaves users open to social engineering, impersonation, and phishing attempts, in which scammers pose as trusted contacts or companies to extract login credentials or money.
Exposed phone numbers also enable SIM-swapping attacks, in which an attacker tricks a mobile carrier into transferring a victim's phone number to a device they control. With that number, an attacker can intercept text-message security codes and reset passwords on accounts tied to the number, as TechCrunch noted in its 2019 reporting.
Because the data includes job titles and, in some records, location details, it can also make scam messages appear more convincing.
What Is Facebook Doing in Response?
Facebook confirmed the data's origin in a blog post on April 6, 2021, stating that malicious actors scraped the information using its contact importer before September 2019, and that it made changes to that feature in 2019 to block the abuse. The company said it was confident the specific issue no longer exists.
Facebook told NPR it had no plans to notify users individually, saying it could not reliably determine which users would need to be notified and that the information had already been publicly available. The company did not respond to a Guardian request for comment in early April 2021.
What Should You Do If You Were Affected?
Watch for phishing texts and calls that reference your name, employer, or location, and do not click links or share codes from unsolicited messages.
Check your mobile carrier account for SIM-swap protections, such as a PIN or port-freeze, and ask your provider to add one.
Use app-based or hardware-based two-factor authentication instead of SMS codes where possible, so a stolen phone number is less useful to attackers.
Use unique passwords across accounts and change any password if you suspect an account has been accessed.
Consider reducing the personal details, such as your phone number, that are visible on your social media profiles.
In the news
- Business Insider: Stolen Data of 533 Million Facebook Users Leaked Onlinebusinessinsider.com (opens in a new tab)
- Facebook Newsroom: The Facts on News Reports About Facebook Dataabout.fb.com (opens in a new tab)
- NPR: After Data Breach Exposes 530 Million, Facebook Says It Will Not Notify Usersnpr.org (opens in a new tab)
- TechCrunch: A huge database of Facebook users' phone numbers found onlinetechcrunch.com (opens in a new tab)
- The Guardian: Facebook data leak: details from 533 million users found on website for hackers
