533 million Facebook users exposed in massive data leak — how to see if you're impacted

How to use Facebook dark mode on Android, iPhone and desktop
(Image credit: Shutterstock)

Some 533 million Facebook user records are being offered up for free on an online hacking forum, multiple sources report.

The good news, if there can be any in this situation, is that the data is old and has been available to cybercriminals for at least two years. Facebook said in statements to The Record and Bleeping Computer that it was all data that had been "scraped" — copied from the Facebook website without Facebook's permission — before a loophole was closed in 2019. 

We've reported on this same stash of data, or parts of it, three times before.

The bad news is that the data contains full names, email addresses, mobile phone numbers and sometime birthdates, exactly the type of things that people tend not to change. Spammers and scammers could use the information to target people with personalized emails or text messages.

The data is pegged to phone numbers, and it wasn't stolen from Facebook. Rather, it was "scraped" more or less legally from data that Facebook had made public.

Facebook used to have a feature where you could punch in a phone number, even a total stranger's, and you'd get a link to any Facebook account associated with that number. You could look up only one number at a time.

What could possibly go wrong? Pretty soon someone rigged up a computer to generate valid-format phone numbers, toss 'em at Facebook and harvest a list of the resulting accounts and all their publicly available details.

At the end, you'd get a reverse-lookup phone book with hundreds of millions of entries. That's what is now being offered up online.

What can I do about this?

If you have a Facebook account, it doesn't mean your data is in this stash. The person who is offering this data claims to have already broken down into country-specific batches. The U.S. batch numbers about 32.3 million records, and the Canadian one about 3.5 million. That's a lot of users, but they're a small fraction of the estimated 258 million Americans and Canadians who are on Facebook.

Only people who gave Facebook their phone numbers would be included, and even then, you may not be in it. 

Considering that the Facebook apps for Android and iPhone will try to grab your phone number and those of all your contacts as soon as you install the apps, Facebook probably has a whole lot more than 36 million North American phone numbers.

So what can you do about this? Be wary of random emails, texts, instant messages and social-media posts that promise riches or rewards, or tell you that you need to take urgent action to avoid paying fines and fees you didn't previously know about. 

The best Windows 10 antivirus and best Mac antivirus software will screen out some scamming attempts on your computers; so will the best Android antivirus apps if you're not on an iPhone. If you do use an iPhone, just keep your wits about when replying to emails, texts and messages.

How to check if your email address is part of this

Troy Hunt, who runs the breach-lookup service HaveIBeenPwned, analyzed the data set over the weekend and found only 2.5 million email addresses among the 533 million individual records. About 65% of the email addresses were already in the HaveIBeenPwned database, Hunt said on Twitter.

Not many of the records, relatively speaking, had dates of birth either. That means the data is mostly just phone numbers and names, about what you'd find in an old-fashioned phone book but still useful to spammers and scammers. 

Hunt has added the Facebook email addresses to the HaveIBeenPwned database, and is considering whether to add the phone numbers as well. To see whether your email address is affected, go to https://haveibeenpwned.com/

Paul Wagenseil

Paul Wagenseil is a senior editor at Tom's Guide focused on security and privacy. He has also been a dishwasher, fry cook, long-haul driver, code monkey and video editor. He's been rooting around in the information-security space for more than 15 years at FoxNews.com, SecurityNewsDaily, TechNewsDaily and Tom's Guide, has presented talks at the ShmooCon, DerbyCon and BSides Las Vegas hacker conferences, shown up in random TV news spots and even moderated a panel discussion at the CEDIA home-technology conference. You can follow his rants on Twitter at @snd_wagenseil.

Read more
A picture showing different credit cards stacked on top of each other on a table
5 million Americans just had their credit card details leaked online — what to do now
An open lock depicting a data breach
12 million hit in Zacks Investment data breach — how to protect yourself now
An open lock depicting a data breach
Thousands including children exposed in major data breach — names, addresses, Social Security numbers and more accessed by hackers
An open lock depicting a data breach
Massive healthcare data breach just exposed the personal info of 1 million Americans — what to do now
Discord on a phone and a laptop
Almost 1 million Discord users just had their account details exposed in new RestoreCord data breach — what to do now
An open lock depicting a data breach
3.5 million hit in major law firm data breach — full names, SSNs, dates of birth, addresses and more exposed
Latest in Social Media
Bluesky logo with X logo in the background
Flashes is a brand new Instagram alternative — and it’s basically Bluesky for images
elon musk in front of image of earth from space
Elon Musk reportedly exploring buying TikTok — Bytedance says 'pure fiction'
Instagram logo on iPhone with Instagram website in background.
Instagram now lets you schedule DMs — here's how to do it
TikTok displayed on a smart phone with a USA flag in the background
Google and Apple warned by Congress to be ready to remove TikTok from app stores — here's the date
Facebook logo on a phone display
Facebook and Instagram were down — latest updates on massive outage
How to access archived web pages in Google
How to access archived web pages in Google
Latest in News
Gboard app logo on mobile phone resting on a keyboard
Google Gboard redesign has already angered users — and I can see why
Reese Witherspoon as Elle Woods (dressed in all pink) holding her dog Bruiser in Legally Blonde
Prime Video top 10 has 3 must-watch movies — including a classic Reese Witherspoon comedy
The Sling TV app button on the Apple TV home screen.
Sling just added 11 free streaming channels — here's what's you can watch
and image of the Google Chrome logo on a laptop
Google Chrome at risk from shape-shifting browser extensions — how to stay safe
YouTube Premium logo on a phone in front of YouTube on a browser
YouTube Premium Lite vs YouTube Premium: What's the difference?
Shogun season 1
'Shogun' season 2 just got an ominous update from a prominent Disney executive