Data of 533M Facebook users, including phone numbers, Facebook IDs, full names, locations, birthdates, bios, and in some cases email addresses, posted online
- The personal data of over 500 million Facebook users has been posted online in a low-level hacking forum.
Context & Ripple Effects
The posting follows a 2019 database exposure linking phone numbers to Facebook accounts, which Facebook attributed to a feature it had already disabled. A separate database of mostly US Facebook user information sold on the dark web showed that large Facebook-linked datasets had continued to circulate.
The newly posted dataset combines phone numbers with identity and profile fields at a far broader scale, turning an earlier access weakness into a persistent exposure problem rather than a one-time product fix.
First-order effects
- Affected Facebook users face a readily searchable package of contact details and identity information, making impersonation and targeted outreach easier for parties that obtain the forum dataset.
- Facebook must defend the claim that the data derives from a 2019 issue it fixed, while users bear the continuing consequences of information collected before that fix.
Second-order effects
- The dataset's combination of phone numbers and profile details gives scammers and identity-verification systems a more useful matching input than a standalone contact list.
- Facebook's earlier removal of phone-number account lookup no longer controls copies already collected, shifting the practical security challenge from feature design to the durability of exported data.
Third-order effects
- Repeated circulation of Facebook-linked datasets reinforces the public-data permission boundary: limiting a collection feature after the fact does not revoke access to data already harvested.
- If such archives remain reusable, platforms will face pressure to assess product permissions by the downstream harm of bulk collection, not merely whether individual fields were publicly visible.
The trend: Social platforms are moving toward a stricter view of bulk-access controls as old profile data persists and is recombined outside their services.