[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f31yv5pl7gt04j":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":33,"seoTitle":34,"seoTitleEn":35,"seoDescription":34,"seoDescriptionEn":36,"logoUrl":37,"isVerified":4,"isSensitive":38,"isSpamList":38,"isMalware":38,"company":39},"68e3266eda11adda488251c5","Facebook","Facebook Data Breach","facebook","facebook.com","2019-08-01T00:00:00.000Z","2021-04-04T03:20:45.000Z","2026-07-27T16:11:12.974Z","Verified breach record","https:\u002F\u002Fabout.fb.com\u002Fnews\u002F2021\u002F04\u002Ffacts-on-news-reports-about-facebook-data\u002F",[15,17,18],"https:\u002F\u002Fwww.troyhunt.com\u002Fthe-facebook-phone-numbers-are-now-searchable-in-have-i-been-pwned\u002F","https:\u002F\u002Fwww.businessinsider.com\u002Fstolen-data-of-533-million-facebook-users-leaked-online-2021-4",509458528,"known",null,"unknown","Critical",[25,26,27,28,29,30,31,32],"Dates of birth","Email addresses","Employers","Genders","Geographic locations","Names","Phone numbers","Relationship statuses","\u003Cp>The Facebook data breach is a major profile and contact data incident that went widespread in April 2021 and is associated with the misuse of the people search and phone matching feature, which was reported to have been fixed in August 2019. The verified scope affects 509,458,528 accounts, and at the center of the incident is the linking of phone numbers with real names and social profile information. Therefore, the risk is not limited to email address searches; for individuals whose phone numbers are still active and are used for banking, work, school, or personal accounts, identity matching, targeted fraud, and fake support queries become more likely.\u003C\u002Fp>\u003Cp>The incident should not be considered a leak of passwords, payment cards, financial accounts, health information, or private messages. Nevertheless, since phone numbers, names, gender, location, date of birth, relationship status, employer, and in some accounts email addresses can be seen together, attackers can obtain sufficient context about a person. This context can be used for SMS phishing, SIM swap attempts through carriers, fake job offers, pretexts to regain social media accounts, and authentication requests that appear trustworthy.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>The verified data categories consist of birth dates, email addresses, employer information, gender, geographic locations, names, phone numbers, and relationship statuses. The most critical aspect of the dataset is the widespread presence of phone numbers; email addresses are seen only in a smaller portion, not across all accounts. Unverified person counts, data fields, and threat-actor claims are not treated as part of the public incident scope. The combination of a phone number and a name creates a strong foundation for personalized messages, fake shipping notifications, bank alert impersonations, and account recovery scams.\u003C\u002Fp>\u003Cp>Fields such as date of birth, location, and employer are supportive information that make the attacker's message credible. Profile fields like relationship status and gender do not directly provide access to financial accounts; however, they can be used in target selection, social pressure, and personal persuasion attempts. The absence of passwords among verified data categories does not mean the risk is eliminated. If the phone number is still the same, some information asked to verify identity on account recovery screens or during customer service interactions may be in the attacker's possession.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The date of the breach is recorded as August 1, 2019, the verified addition date as April 4, 2021, and the last verification change date as April 6, 2021. The number of affected accounts is considered to be 509,458,528. Higher raw numbers may be seen in different news; the number used here is based on the verified record count for search and user notification screens. Leaked fields are limited to profile and contact information; financial information, health information, private message content, or passwords are not included in the verified scope of this incident.\u003C\u002Fp>\u003Cp>The root cause of the incident is the abuse of an old people-search flow in which phone numbers could be matched with user profiles. The company reported that it made changes to the relevant flow in 2019. Nevertheless, the risk cannot be considered to have ended in the past because the dataset circulated for free and with broad access in 2021. Since the data contained phone numbers, names, and profile contexts that remained unchanged or the same for many years for most users, the security impact can persist for a long time.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The highest risk is for people who have their phone number on their Facebook profile and are still using the same number. People who use their phone number as an authentication element in banking, cloud accounts, email, work systems, or operator transactions should be more careful. Users with fields such as employer, location, or date of birth visible can also be exposed to more convincing social engineering attempts. The risk is broader for the small group whose email address has been leaked; because when phone and email are seen together, account recovery and password reset scams can be targeted more easily.\u003C\u002Fp>\u003Cp>There is also an indirect risk for users who have transferred their old number to another person. If the number appearing in the dataset now belongs to a different user, the new number owner may receive misdirected calls or messages; the previous profile owner may experience identity confusion due to the past association of the number. For small business owners, public officials, content creators, and employees who interact with customers over the phone, visibility is higher, so attempts at misuse may occur more frequently.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>The priority is to check which accounts still use the phone number as an authentication or account recovery tool. Where possible, an authentication app or a hardware security key should be preferred over SMS. On social media accounts, it should be checked who can find the phone number, who has access to profile information, and whether account recovery options are up to date. Verification codes, bank alerts, delivery messages, job offers, or support call messages from unknown people should be independently verified through the service's official channel before clicking on any links.\u003C\u002Fp>\u003Cp>If there are security options such as additional passwords or in-store identity verification for SIM replacement and number porting on the operator account, they should be enabled. Affected users should also apply unique passwords, strong two-factor authentication, and session history checks on critical accounts associated with the same email address. Unknown sessions on the Facebook account should be closed, the list of trusted devices should be reviewed, and profile visibility should be reduced. Even though this incident does not involve passwords, attackers can use the profile information at hand as a pretext for password resets.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Although a phone number is a practical communication tool, it acts like a long-lasting identity marker. Therefore, rather than keeping the same phone number visible on every service, it is safer to use it only for accounts where it is truly necessary. Fields such as date of birth, employer, location, and relationship status on social media profiles should be made less public. Using different communication channels for professional and personal accounts makes it harder for a single data set to link many accounts.\u003C\u002Fp>\u003Cp>Corporate teams should not rely solely on phone requests in support, human resources, and finance processes, assuming that employee phone numbers and employer information could circulate externally. In customer service and helpdesk workflows, easily obtainable information such as date of birth, phone number, or address should not be the only means of verification. Individual users, on the other hand, should make habits such as regular privacy checks, updating account recovery options, reporting suspicious SMS messages, and renewing two-factor authentication a long-term protection routine.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>The result does not mean that your password has been leaked or that your account has been directly accessed. Nevertheless, you should be cautious about targeted messages that may come to your phone number, fake support calls, SIM swap attempts, and account recovery scams. The priority is to strengthen the two-factor authentication on critical accounts linked to your phone number, reduce profile visibility, and not share unexpected verification codes with anyone.\u003C\u002Fp>\u003Cp>If the control result is negative, this only means that no match was found in this data set; separate checks may be needed for other events or more recent data sets. If you have been using your phone number for years, it is more appropriate to make security decisions acknowledging that old profile information may still be circulating. Especially if you have changed your number, check that the old number has been removed from account recovery options and that the new number is used only for necessary services. This page aims to calmly show the user which data is risky and which steps should be prioritized.\u003C\u002Fp>","","Facebook Data Breach (509.5 Million Reported Records)","Facebook Data Breach. 509.5 Million reported records were reported. Reported data: Dates of birth, Email addresses, Employers. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Ffacebook_com.webp",false,{"name":7,"sector":40,"country":41,"website":10,"websiteArchiveUrl":34,"websiteStatus":34,"websiteCheckedAt":21},"Social Media","United States"]