Skip to main content
Breach Signal

Breach report

Social Media

Facebook (Meta)

Phone numbers for 533 million Facebook users leaked on hacking forum

A database linking phone numbers to 533 million Facebook profiles across 106 countries was dumped on a hacking forum in 2021, the product of a contact-import flaw abused in 2019 that later cost Meta a €265 million fine.

Reported by The Record

Records exposed

533M

533 million users

Scale vs. largest on file

When
2019 (leaked 2021)
How they got in
API scraping (contact importer vulnerability)
Sector
Social Media

Over the Easter weekend of 2021, a dataset covering roughly 533 million Facebook accounts was posted on a well-known cybercrime forum, where anyone with a few forum credits could download it. The records were split into more than one hundred country-specific files, with Egypt, Italy, the United States and Saudi Arabia among the largest. Researchers noted that the same data had already been monetized months earlier through a Telegram bot that sold phone-number lookups for a small fee.

The information did not come from a break-in of Facebook's servers in the traditional sense. Instead, attackers abused the platform's contact importer, a feature meant to help people find friends by uploading their address books. By feeding the tool huge volumes of generated phone numbers, the scrapers could match numbers to profiles and pull the associated public details. Facebook said it had closed the hole in August 2019, but by then the data had been harvested at massive scale.

What made the leak damaging was the pairing of phone numbers, many of which users had never made public, with names, hometowns, employers, birthdates and sometimes email addresses. That combination is ideal raw material for SIM-swap attacks, targeted phishing, robocall and SMS scams, and doxxing. Because phone numbers are rarely changed, the exposure has a long shelf life, and the dataset continues to circulate in criminal circles.

Facebook initially characterized the incident as old news and emphasized that the data had been scraped rather than stolen through a hack. It declined to notify affected users individually, a decision that drew sharp criticism from privacy advocates and European regulators. Ireland's Data Protection Commission opened an inquiry and, in November 2022, fined Meta €265 million for failing to build adequate data-protection safeguards into the features that were abused. The case also fueled class actions in Europe.

The episode became a reference point in the debate over whether mass scraping should be treated as a breach. For platforms, it underlined the need for rate limiting, anomaly detection and privacy-by-default settings on lookup features. For consumers, it was a reminder that a phone number is effectively a permanent identifier, and that using it for account recovery or two-factor authentication carries risk once it is tied publicly to an identity.

More from the wire

More in Social Media.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.