Massive Facebook Data Leak Exposes Half a Billion Users
A database containing the personal information of 533 million Facebook users surfaces online, revealing a major scraping vulnerability. The breach prompts regulatory investigations in both the EU and the US.
The personal details of 533 million Facebook users surface online in a massive data leak discovered by security researcher Alon Gal. The exposed information includes sensitive data such as phone numbers, email addresses, full names, birth dates, and hometowns from users across more than 106 countries. Although Facebook initially dismisses the leak as old news from a previously patched 2019 vulnerability, the company later acknowledges the incident in an official blog post.
This massive data trove stems from malicious actors who exploit Facebook's contact importer tool to scrape user profiles prior to September 2019. While no passwords are compromised in this incident, the exposed information remains highly valuable to cyber criminals who frequently combine stolen data sets to execute targeted spam emails, phishing attacks, and robocalls.
The exact timing of the data scraping carries significant legal consequences for the social media giant. If the breach occurs after the implementation of the GDPR in May 2018 or after a specific FTC immunity deadline in June 2019, Facebook faces potential fines and enforcement actions from European and US regulators. Ireland's Data Protection Commission is currently investigating the breach, and affected users can verify their exposure by checking their email addresses or phone numbers on the website haveibeenpwned.com.