Breach report
Social MediaFacebook (Meta)
Phone numbers for 533 million Facebook users leaked on hacking forum
A database linking phone numbers to 533 million Facebook profiles across 106 countries was dumped on a hacking forum in 2021, the product of a contact-import flaw abused in 2019 that later cost Meta a €265 million fine.
Reported by The Record
Records exposed
533M
533 million users
Scale vs. largest on file
- When
- 2019 (leaked 2021)
- How they got in
- API scraping (contact importer vulnerability)
- Sector
- Social Media
Over the Easter weekend of 2021, a dataset covering roughly 533 million Facebook accounts was posted on a well-known cybercrime forum, where anyone with a few forum credits could download it. The records were split into more than one hundred country-specific files, with Egypt, Italy, the United States and Saudi Arabia among the largest. Researchers noted that the same data had already been monetized months earlier through a Telegram bot that sold phone-number lookups for a small fee.
The information did not come from a break-in of Facebook's servers in the traditional sense. Instead, attackers abused the platform's contact importer, a feature meant to help people find friends by uploading their address books. By feeding the tool huge volumes of generated phone numbers, the scrapers could match numbers to profiles and pull the associated public details. Facebook said it had closed the hole in August 2019, but by then the data had been harvested at massive scale.
What made the leak damaging was the pairing of phone numbers, many of which users had never made public, with names, hometowns, employers, birthdates and sometimes email addresses. That combination is ideal raw material for SIM-swap attacks, targeted phishing, robocall and SMS scams, and doxxing. Because phone numbers are rarely changed, the exposure has a long shelf life, and the dataset continues to circulate in criminal circles.
Facebook initially characterized the incident as old news and emphasized that the data had been scraped rather than stolen through a hack. It declined to notify affected users individually, a decision that drew sharp criticism from privacy advocates and European regulators. Ireland's Data Protection Commission opened an inquiry and, in November 2022, fined Meta €265 million for failing to build adequate data-protection safeguards into the features that were abused. The case also fueled class actions in Europe.
The episode became a reference point in the debate over whether mass scraping should be treated as a breach. For platforms, it underlined the need for rate limiting, anomaly detection and privacy-by-default settings on lookup features. For consumers, it was a reminder that a phone number is effectively a permanent identifier, and that using it for account recovery or two-factor authentication carries risk once it is tied publicly to an identity.