[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f37838joryc1x9":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":29,"seoTitle":15,"seoTitleEn":30,"seoDescription":15,"seoDescriptionEn":31,"logoUrl":32,"isVerified":4,"isSensitive":4,"isSpamList":33,"isMalware":33,"company":34},"68e3266eda11adda488251c6","facebook-marketplace","Facebook Marketplace Data Breach","facebook.com","2023-10-01T00:00:00.000Z","2024-02-22T00:53:37.000Z","2024-02-22T00:55:02.000Z","2026-07-18T23:50:28.022Z","Marketplace contractor records and profile data breach","",[],77267,"known",null,"unknown","Medium",[23,24,25,26,27,28],"Email addresses","Geographic locations","Names","Passwords","Phone numbers","Social media profiles","\u003Cp>The Facebook Marketplace data breach was confirmed when Marketplace records associated with a company contractor were published on forums in February 2024, following the incident in October 2023. These records are separate from the main Facebook 2019\u002F2021 phone number dataset. The main verified metric is 77,267 unique email accounts; incident reports mention around 200,000 Marketplace records. The confirmed data types include email addresses, geographic locations, names, passwords, phone numbers, and social media profile information. The password field appears as bcrypt hashes, and it has been noted that there is no clear evidence that these hashes correspond to Facebook accounts. Nevertheless, due to the password field, the records should be treated as sensitive data.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The data types listed in this record are Email addresses, Geographic locations, Names, Passwords, Phone numbers, and Social media profiles. When email, name, phone, and profile ID are found together, the user's Marketplace identity can be matched with real communication channels. Geographic location information makes local buying and selling, delivery, deposit, face-to-face meetings, and listing verification messages more convincing. Even if the password field is in bcrypt hash form, there is still a risk of account takeover for weak or reused passwords. However, since it has not been proven that these password hashes directly match the corresponding Facebook login information, the record should be evaluated with this limitation. The central risk is Marketplace-related fraud, profile matching, phone targeting, and password reuse.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified main metric is 77,267 unique email accounts. The statement of approximately 200,000 rows of Marketplace records refers to the total record volume; it is not the same as the number of unique emails. Data categories are limited to email, location, name, password hashes, phone, and social profile information. Payment card, bank account, official ID, private message content, the full content of listings, or product purchase history are not included in the verified data categories of this record. There is also a significant limitation for password hashes: it has not been verified that they correspond to the respective Facebook accounts. Therefore, users should be warned about password reuse, and the issue should be restricted in the context of Marketplace accounts and profile matching. It should not be considered duplicate with the main Facebook phone dataset and should be tracked with separate dates and separate data fields.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The main group at risk consists of users who buy and sell through Facebook Marketplace, share their phone numbers, post listings with local locations, or conduct transactions with their profile identity openly. People who shop locally can be targeted with fake deposits, fake payment receipts, fake deliveries, fake meeting place changes, or fake account verification messages. Users with a phone number can be contacted not only via email but also through calls and text messages. Geographic location information helps the attacker build trust from the same city or region. Due to password hashes, people who use the same or similar passwords on other platforms are at higher risk. Small business owners, frequent sellers, and users who sell high-value items should also be more cautious about targeted scam messages.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>If your email address appears in this record, check the security of your accounts associated with Facebook and Marketplace. If you have used the same or similar password on other services, change those passwords. Enable multi-factor authentication. In Marketplace buying and selling, before clicking links in deposit, shipping, payment receipt, listing verification, phone verification, or account security messages, access your account directly from a known web address. Even if the person calling on the phone knows your name, profile, or location, do not share one-time codes, bank information, or account passwords. For face-to-face meetings, choose safe, crowded, and monitored areas. If unnecessary phone or location information appears on your profile, tighten your privacy settings.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>Local marketplace accounts can pose a long-term tracking risk because they combine phone numbers and location information with social profile identities. Users should limit publicly available phone information on buying and selling accounts, keep communication within platform channels as much as possible, and develop a habit of additional verification for high-value items. A unique password should be used for each service, and a password manager should be preferred. Sellers should not deliver the product without verifying the bank transaction against deposit and payment receipt fraud. On the platform side, contractor accesses, marketplace data exports, retention periods for phone and location fields, and suspicious bulk access controls should be strictly managed. Users should regularly check whether the same phone number and email information have been combined with leaks from other marketplaces.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>LeakData check shows whether your email address is included in a Facebook Marketplace leak. A positive result does not mean your payment card, bank account, or private messages have been exposed; the verified risk is limited to email, location, name, phone number, social profile information, and bcrypt password hashes. User actions include changing reused passwords, enhancing Marketplace account security, verifying local buy-sell requests via phone, and limiting location\u002Fprofile visibility. This record is different from the main Facebook phone dataset; therefore, if the same person appears in both records, the risks may combine. Attackers can match Marketplace information with phone, address, or password data from other leaks to create more convincing local scam messages.\u003C\u002Fp>","Facebook Marketplace Data Breach (77.3 Thousand Reported Records)","Facebook Marketplace Data Breach. 77.3 Thousand reported records were reported. Reported data: Email addresses, Geographic locations, Names. Review the scope…","\u002Fuploads\u002Flogo\u002Ffacebook_com.webp",false,{"name":35,"sector":36,"country":37,"website":9,"websiteArchiveUrl":15,"websiteStatus":15,"websiteCheckedAt":19},"Facebook Marketplace","Social Media","United States"]