Unsecured database with 419M+ phone numbers linked to Facebook accounts found; FB says data was obtained before it disabled searching for users via phone number
Hundreds of millions of phone numbers linked to Facebook accounts have been found online. — The exposed server contained …
TechCrunchZack Whittaker
Context & Ripple Effects
This 2019 exposure of 419M+ phone numbers tied to Facebook accounts turned out to be a seed stock rather than a one-off incident: when a 533M-user dataset including names, locations and birthdates surfaced online in 2021, Facebook said it stemmed from a vulnerability that had been reported on and fixed back in 2019 — i.e., from exactly this era of scraped contact data.
Affected users' phone numbers are immediately usable for SIM-swap attempts, phishing and targeted scam texts, since the numbers are mapped to real Facebook identities rather than being random lists.
Second-order effects
Facebook's own fix — disabling phone-number search — only cuts off future scraping, leaving already-extracted datasets like the ones later resold on the dark web fully outside its control; every new dump forces Facebook to relitigate an incident it claims to have closed.
Third-order effects
Data scraped through a feature the platform later disables never expires: once a social graph's contact layer leaks, it becomes a permanent, resellable asset that outlives every patch, pushing the burden onto users who cannot revoke a number they were forced to publish to be findable.
The trend: Facebook-era contact graphs keep leaking in waves — scraped via lookup features, patched at the source, but resold and re-posted for years — making 'we fixed it in 2019' a statement about access, not about the data itself.
Exclusive: Millions of phone numbers linked to Facebook accounts have been found in an exposed database. Facebook says the data was historically scraped but the phone numbers we tested were still valid. https://techcrunch.com/...
How long will it take for people to understand that we need to work on shifting power rather than on privacy http://worldaftercapital.org/ https://twitter.com/...
Funny how Facebook says a lot of the exposed user phone numbers are “duplicates”. https://techcrunch.com/... A spokesperson told me background that only 217 million are affected. But that's just one database — see below. There's a lot more data — and little evidence of duplicatio…
Privacy Paradox: Massive database of phone numbers scraped from Facebook discovered. No one knows who's responsible. Bad actors get privacy. The rest of us get none. https://techcrunch.com/...
If you ever shared your phone number with Facebook, there's a good chance it's now available on the internet, as hundreds of numbers tied to user IDs have been exposed. https://techcrunch.com/...
Facebook's handling of the SMS 2FA situation is one of the most depressing and reprehensible stories in modern information security. https://twitter.com/...
No surprise here. Site scraping has been a very financially rewarding business since the early 2000s. I'm willing to make a bet there's been hundreds of companies who've scraped Facebook the old classic way (no API shenanigans) already. https://twitter.com/...
@zackwhittaker @TechCrunch Facebook's dismissive response here “the data is old” highlights why Zack's reporting is so crucial. They'd otherwise sweep this under the rug as much as possible
There were several databases on the exposed server containing 419 million records — including 133 million on U.S.-based Facebook users and 18 million on U.K. users. I asked Facebook for comment yesterday with a deadline of 12pm PT today. I got a reply at 11:59 am. Unsurprising.