Massive Facebook Data Leak Exposes Half a Billion Users
A massive data trove containing the personal information of 533 million Facebook users surfaces online, exposing phone numbers and addresses. Facebook now faces regulatory investigations over its delayed disclosure of the breach.
The personal data of 533 million Facebook users across 106 countries circulates freely online after security researcher Alon Gal uncovers the massive data trove. The exposed information includes sensitive details such as phone numbers, email addresses, full names, birth dates, and hometowns. Although Facebook initially claims this breach stems from a previously reported 2019 issue, the company acknowledges the leak in an April blog post after facing intense public scrutiny.
Malicious actors exploit Facebook's contact importer tool to scrape this vast amount of data from user profiles prior to September 2019. While passwords remain secure during this incident, cyber criminals routinely combine stolen data sets like this to execute spam emails, robocalls, and targeted phishing attacks. The exact timing of the scraping complicates the situation due to Facebook's long history of various data privacy controversies.
The timing of the breach carries severe legal implications for the social media giant. If the data extraction occurs after the implementation of the General Data Protection Regulation in May 2018 or a specific FTC immunity deadline in June 2019, Facebook faces significant fines and enforcement actions. Ireland's Data Protection Commission actively investigates the incident, while affected users check their exposure on the website haveibeenpwned.com.