Skip to content
Back to Blog
high severity August 01, 2019 · 3 min read

Facebook — 509 Million Phone Numbers Tied to Real Names (2019, published 2021)

If you are a customer of Facebook, here’s what’s now in circulation.

Roughly 20% of Facebook made freely downloadable in April 2021, scraped through a contact-import weakness Facebook says it fixed in August 2019. The value of the data is not passwords — there are none — it is that it welds a phone number to a real name. Ireland fined Meta 265 million euro over it.

A phone number linking outward to a name, birthday and employer

What happened

In April 2021 a data set covering 509,458,528 Facebook users — roughly a fifth of the platform — was posted for free download on a hacking forum. Facebook's position is that the data was obtained by abusing a contact-importer weakness that it fixed in August 2019, which is why the catalogue dates the incident to 2019 rather than to the day it became public.

Named in this incident?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 582 companies.
See what is exposed about you — free scan →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

In November 2022 Ireland's Data Protection Commission concluded its inquiry and fined Meta 265 million euro, covering data processing through Facebook Search and the Facebook and Instagram Contact Importer tools between May 2018 and September 2019. The finding was a failure to build in appropriate technical safeguards — not a failure to stop an intrusion.

A scrape is not a hack, and the difference changes your response

Nobody broke into Facebook's servers. The contact importer was a feature: it let you upload phone numbers to find friends. Run at scale against generated number ranges, it turned into a lookup that converted phone numbers into profiles.

The consequence for you is specific. There were no passwords in this data, so changing your Facebook password does nothing about it. Only about 2.5 million of the half-billion records contained an email address at all. Most records held a phone number, a name and a gender, with many also carrying date of birth, location, relationship status and employer.

The primary value of the dataset, stated plainly, is the association of a phone number with an identity.

Why an un-rotatable identifier is the worst thing to lose

Security advice is built around the assumption that a compromised secret can be replaced. Passwords can. Phone numbers effectively cannot — changing yours means updating every bank, employer, two-factor enrolment and contact who has it. Almost nobody does it, which is exactly why this dataset stayed valuable for years after publication.

A phone number welded to a real name, a date of birth and an employer is the raw material for SIM-swap attacks, where an attacker persuades a carrier to move your number to their SIM and then collects your SMS second factors. It is also what makes a phishing call work: the caller already knows who you are, where you work and how old you are.

The identity-chain implication

For anyone with a public handle — streamers, creators, competitive players — this dataset is the bridge between a persona and a person. A handle leads to an email address in some other breach; the email address, for the 2.5 million records that carry one, leads here; and here supplies the phone number, the birthday and the employer.

Relationship status and employer are the fields harassment campaigns reach for once they have the rest, because they identify the other people worth contacting.

What to do now

The correct actions here are about hardening the number rather than replacing it, since replacing it is usually impractical.

What You Should Do

  1. Set a carrier port-out PIN or SIM-swap lock — this is the single most effective step against a leaked phone number
  2. Move two-factor authentication off SMS and onto an authenticator app wherever the service allows it
  3. Set Facebook's "Who can look you up using the phone number you provided?" to Friends, and consider removing the number entirely
  4. Treat any caller who already knows your name, employer and birthday as unverified until you call back on a number you looked up yourself
  5. Do not bother changing your Facebook password for this one — no passwords were exposed, and the advice misdirects effort

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove — and removing them is what we do.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Were you a Facebook customer?
Facebook is one listing. Your email is probably in others.
509.5M records accounts were exposed here. Check whether yours is one — and find every other leak tied to the same address, in about 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High
Disclosed August 01, 2019
Last reviewed July 22, 2026
Affected 509.5M records
Data exposed Phone numbersNamesGendersDates of birthGeographic locationsRelationship statusesEmployersEmail addresses
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email