/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Unsecured database with 419M+ phone numbers linked to Facebook accounts found; FB says data was obtained before it disabled searching for users via phone number

Hundreds of millions of phone numbers linked to Facebook accounts have been found online.  —  The exposed server contained …

TechCrunch Zack Whittaker

Context & Ripple Effects

This 2019 exposure of 419M+ phone numbers tied to Facebook accounts turned out to be a seed stock rather than a one-off incident: when a 533M-user dataset including names, locations and birthdates surfaced online in 2021, Facebook said it stemmed from a vulnerability that had been reported on and fixed back in 2019 — i.e., from exactly this era of scraped contact data.

The pattern was already visible before then, too: a security firm bought a database of info on 267M+ mostly US Facebook users for just £500 on the dark web in 2020, showing these contact-graph dumps circulate as cheap, resellable inventory long after the original scrape.

First-order effects

  • Affected users' phone numbers are immediately usable for SIM-swap attempts, phishing and targeted scam texts, since the numbers are mapped to real Facebook identities rather than being random lists.

Second-order effects

  • Facebook's own fix — disabling phone-number search — only cuts off future scraping, leaving already-extracted datasets like the ones later resold on the dark web fully outside its control; every new dump forces Facebook to relitigate an incident it claims to have closed.

Third-order effects

  • Data scraped through a feature the platform later disables never expires: once a social graph's contact layer leaks, it becomes a permanent, resellable asset that outlives every patch, pushing the burden onto users who cannot revoke a number they were forced to publish to be findable.

The trend: Facebook-era contact graphs keep leaking in waves — scraped via lookup features, patched at the source, but resold and re-posted for years — making 'we fixed it in 2019' a statement about access, not about the data itself.

Discussion

  • @zackwhittaker Zack Whittaker on x
    Exclusive: Millions of phone numbers linked to Facebook accounts have been found in an exposed database. Facebook says the data was historically scraped but the phone numbers we tested were still valid. https://techcrunch.com/...
  • @albertwenger Albert Wenger on x
    How long will it take for people to understand that we need to work on shifting power rather than on privacy http://worldaftercapital.org/ https://twitter.com/...
  • @zackwhittaker Zack Whittaker on x
    Funny how Facebook says a lot of the exposed user phone numbers are “duplicates”. https://techcrunch.com/... A spokesperson told me background that only 217 million are affected. But that's just one database — see below. There's a lot more data — and little evidence of duplicatio…
  • @profcarroll David Carroll on x
    Privacy Paradox: Massive database of phone numbers scraped from Facebook discovered. No one knows who's responsible. Bad actors get privacy. The rest of us get none. https://techcrunch.com/...
  • @dhh @dhh on x
    If you ever shared your phone number with Facebook, there's a good chance it's now available on the internet, as hundreds of numbers tied to user IDs have been exposed. https://techcrunch.com/...
  • @matthew_d_green Matthew Green on x
    Facebook's handling of the SMS 2FA situation is one of the most depressing and reprehensible stories in modern information security. https://twitter.com/...
  • @campuscodi Catalin Cimpanu on x
    No surprise here. Site scraping has been a very financially rewarding business since the early 2000s. I'm willing to make a bet there's been hundreds of companies who've scraped Facebook the old classic way (no API shenanigans) already. https://twitter.com/...
  • @joshconstine Josh Constine on x
    @zackwhittaker @TechCrunch Facebook's dismissive response here “the data is old” highlights why Zack's reporting is so crucial. They'd otherwise sweep this under the rug as much as possible
  • @johnpaczkowski John Paczkowski on x
    “The future is private.” https://twitter.com/...
  • @zackwhittaker Zack Whittaker on x
    There were several databases on the exposed server containing 419 million records — including 133 million on U.S.-based Facebook users and 18 million on U.K. users. I asked Facebook for comment yesterday with a deadline of 12pm PT today. I got a reply at 11:59 am. Unsurprising.