/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Security firm buys a database, first seen last month, with info on 267M+ mostly US Facebook users, including full names and phone numbers, for £500 on dark web

Threat actors are selling over 267 million Facebook profiles for £500 ($623) on dark web sites and hacker forums.

BleepingComputer Lawrence Abrams

Context & Ripple Effects

This £500 purchase fits a recurring pattern rather than a one-off: hackers were already selling Facebook account data at $0.10 each alongside the publication of private messages from 81K accounts in 2018, and a year later a far larger dump covering 533M Facebook users surfaced with phone numbers and personal details. The 2020 database shows the middle of that pipeline — scraped or leaked profiles being resold cheaply on dark web forums long before the big public dumps.

What makes this sale notable is the price and the buyer: full names and phone numbers for over 267 million mostly US users cost about a fraction of a cent per record, cheap enough that a security firm could buy the whole thing outright to verify and warn — the same verification dynamic that preceded the 2021 disclosures.

First-order effects

  • The 267M+ mostly US Facebook users in the database are exposed now to SMS phishing and spoofed-number scams built on the name-plus-phone pairing, with no notification from Facebook since the data predates this sale.
  • The purchasing security firm gains the ability to verify the dataset's authenticity and scope, turning a criminal listing into a documented exposure that Facebook will have to address.

Second-order effects

  • Facebook faces renewed pressure to explain how phone-number-linked data keeps reaching resale markets, echoing its 2019-fix defense from the 533M dump and its browser-extension blame in the 2018 message leak.
  • Dark web sellers gain a proven price point for bulk US profile data, incentivizing further scraping-and-resale cycles against Facebook's user base.

Third-order effects

  • The pattern — leak, fix, resale, bigger dump — suggests scraped social-graph data behaves as a durable commodity whose value outlives platform remediation, strengthening the case for regulators to treat phone-number harvesting as a systemic platform-design failure rather than isolated incidents.

The trend: Facebook user data is cycling through dark web resale markets faster than the company can remediate, with each disclosure exposing a larger slice of its user base.

Discussion

  • @piccadillycrown Piccadilly on x
    “Threat actors are selling over 267mil Facebook profiles for $623 on dark web sites & hacker forums. While none of these records incl passwords, they do contain info that could allow attackers to perform spear phishing or SMS attacks to steal credentials” https://www.bleepingcomp…