Don’t do SECURITY. Do business SECURELY.

Personal data of 533 million Facebook users posted online

Phone numbers and personal details of 533 million Facebook users from 106 countries appear for free on a hacking forum.

Personal data belonging to about 533 million Facebook users from 106 countries was published for free on a hacking forum. Facebook said the data had been scraped in 2019 by abusing a feature that has since been fixed.

What happened

  • The data included phone numbers, Facebook IDs, names, locations, and in some cases email addresses and birth dates.
  • The largest affected countries included Egypt, Italy, and the US, with millions of UK users also included.
  • Attackers had exploited Facebook’s contact importer feature to match phone numbers to profiles; Facebook said it fixed the issue in 2019.
  • In November 2022 Ireland’s Data Protection Commission fined Meta €265 million over the scraping.

Why it mattered

The leak put phone numbers of a large share of Facebook’s users into criminal hands, fuelling smishing and scam calls, and showed that scraping can amount to a serious data protection failure. It also raised questions about whether old data from a fixed flaw should be treated as a new incident requiring notification.

Lessons for organisations

Rate-limit and monitor features that let users look up other accounts, test APIs for enumeration risks, and warn customers when their data is exposed.

Source: The Record

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with a link to our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights