Back to Blog
high severity August 01, 2019 · 3 min read

Facebook — 509 Million Phone Numbers Tied to Real Names (2019, published 2021)

If you have an account with Facebook, here’s what’s now in circulation.

Roughly 20% of Facebook made freely downloadable in April 2021, scraped through a contact-import weakness Facebook says it fixed in August 2019. The value of the data is not passwords — there are none — it is that it welds a phone number to a real name. Ireland fined Meta 265 million euro over it.

A phone number linking outward to a name, birthday and employer

What happened

In April 2021 a data set covering 509,458,528 Facebook users — roughly a fifth of the platform — was posted for free download on a hacking forum. Facebook's position is that the data was obtained by abusing a contact-importer weakness that it fixed in August 2019, which is why the catalogue dates the incident to 2019 rather than to the day it became public.

Caught in this breach?
You can’t unleak a breach. You can take away what it’s worth.
Deep Sweep shows you every leak tied to you and exactly what to change. Then it strips your name, address and family off the look-up sites that turn a leaked record into somebody knocking on your door — $29 one-time, includes 30 days of Protection. We write to 582 companies. No subscription to start.
Scan free, then Deep Sweep — $29 →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

In November 2022 Ireland's Data Protection Commission concluded its inquiry and fined Meta 265 million euro, covering data processing through Facebook Search and the Facebook and Instagram Contact Importer tools between May 2018 and September 2019. The finding was a failure to build in appropriate technical safeguards — not a failure to stop an intrusion.

A scrape is not a hack, and the difference changes your response

Nobody broke into Facebook's servers. The contact importer was a feature: it let you upload phone numbers to find friends. Run at scale against generated number ranges, it turned into a lookup that converted phone numbers into profiles.

The consequence for you is specific. There were no passwords in this data, so changing your Facebook password does nothing about it. Only about 2.5 million of the half-billion records contained an email address at all. Most records held a phone number, a name and a gender, with many also carrying date of birth, location, relationship status and employer.

The primary value of the dataset, stated plainly, is the association of a phone number with an identity.

Why an un-rotatable identifier is the worst thing to lose

Security advice is built around the assumption that a compromised secret can be replaced. Passwords can. Phone numbers effectively cannot — changing yours means updating every bank, employer, two-factor enrolment and contact who has it. Almost nobody does it, which is exactly why this dataset stayed valuable for years after publication.

A phone number welded to a real name, a date of birth and an employer is the raw material for SIM-swap attacks, where an attacker persuades a carrier to move your number to their SIM and then collects your SMS second factors. It is also what makes a phishing call work: the caller already knows who you are, where you work and how old you are.

The identity-chain implication

For anyone with a public handle — streamers, creators, competitive players — this dataset is the bridge between a persona and a person. A handle leads to an email address in some other breach; the email address, for the 2.5 million records that carry one, leads here; and here supplies the phone number, the birthday and the employer.

Relationship status and employer are the fields harassment campaigns reach for once they have the rest, because they identify the other people worth contacting.

What to do now

The correct actions here are about hardening the number rather than replacing it, since replacing it is usually impractical.

What You Should Do

  1. Set a carrier port-out PIN or SIM-swap lock — this is the single most effective step against a leaked phone number
  2. Move two-factor authentication off SMS and onto an authenticator app wherever the service allows it
  3. Set Facebook's "Who can look you up using the phone number you provided?" to Friends, and consider removing the number entirely
  4. Treat any caller who already knows your name, employer and birthday as unverified until you call back on a number you looked up yourself
  5. Do not bother changing your Facebook password for this one — no passwords were exposed, and the advice misdirects effort

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove. That’s what a Deep Sweep buys.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Were you a Facebook customer?
Facebook is one breach. Your email is probably in others.
509.5M records accounts were exposed here. Check whether yours is one — and find every other leak tied to the same address, in about 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High
Disclosed August 01, 2019
Last reviewed July 22, 2026
Affected 509.5M records
Data exposed Phone numbersNamesGendersDates of birthGeographic locationsRelationship statusesEmployersEmail addresses
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email