Facebook — 509 Million Phone Numbers Tied to Real Names (2019, published 2021)
If you have an account with Facebook, here’s what’s now in circulation.
Roughly 20% of Facebook made freely downloadable in April 2021, scraped through a contact-import weakness Facebook says it fixed in August 2019. The value of the data is not passwords — there are none — it is that it welds a phone number to a real name. Ireland fined Meta 265 million euro over it.
What happened
In April 2021 a data set covering 509,458,528 Facebook users — roughly a fifth of the platform — was posted for free download on a hacking forum. Facebook's position is that the data was obtained by abusing a contact-importer weakness that it fixed in August 2019, which is why the catalogue dates the incident to 2019 rather than to the day it became public.
In November 2022 Ireland's Data Protection Commission concluded its inquiry and fined Meta 265 million euro, covering data processing through Facebook Search and the Facebook and Instagram Contact Importer tools between May 2018 and September 2019. The finding was a failure to build in appropriate technical safeguards — not a failure to stop an intrusion.
A scrape is not a hack, and the difference changes your response
Nobody broke into Facebook's servers. The contact importer was a feature: it let you upload phone numbers to find friends. Run at scale against generated number ranges, it turned into a lookup that converted phone numbers into profiles.
The consequence for you is specific. There were no passwords in this data, so changing your Facebook password does nothing about it. Only about 2.5 million of the half-billion records contained an email address at all. Most records held a phone number, a name and a gender, with many also carrying date of birth, location, relationship status and employer.
The primary value of the dataset, stated plainly, is the association of a phone number with an identity.
Why an un-rotatable identifier is the worst thing to lose
Security advice is built around the assumption that a compromised secret can be replaced. Passwords can. Phone numbers effectively cannot — changing yours means updating every bank, employer, two-factor enrolment and contact who has it. Almost nobody does it, which is exactly why this dataset stayed valuable for years after publication.
A phone number welded to a real name, a date of birth and an employer is the raw material for SIM-swap attacks, where an attacker persuades a carrier to move your number to their SIM and then collects your SMS second factors. It is also what makes a phishing call work: the caller already knows who you are, where you work and how old you are.
The identity-chain implication
For anyone with a public handle — streamers, creators, competitive players — this dataset is the bridge between a persona and a person. A handle leads to an email address in some other breach; the email address, for the 2.5 million records that carry one, leads here; and here supplies the phone number, the birthday and the employer.
Relationship status and employer are the fields harassment campaigns reach for once they have the rest, because they identify the other people worth contacting.
What to do now
The correct actions here are about hardening the number rather than replacing it, since replacing it is usually impractical.
What You Should Do
- Set a carrier port-out PIN or SIM-swap lock — this is the single most effective step against a leaked phone number
- Move two-factor authentication off SMS and onto an authenticator app wherever the service allows it
- Set Facebook's "Who can look you up using the phone number you provided?" to Friends, and consider removing the number entirely
- Treat any caller who already knows your name, employer and birthday as unverified until you call back on a number you looked up yourself
- Do not bother changing your Facebook password for this one — no passwords were exposed, and the advice misdirects effort
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove. That’s what a Deep Sweep buys.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
Report details & sourcing
Related breaches
Verifications.io — 763 Million Email Records Left on an Open Database (2019)
An email-validation firm most people had never heard of left 763 million records in a MongoDB instan…
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…
Deezer — 229 Million Records a Partner Was Supposed to Have Deleted (2019, disclosed 2022)
The music service was not breached. A third-party partner kept a mid-2019 backup after its contract …