LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Facebook Data Breach (2019)

CRITICAL severityConfirmedHow we verify

Facebook Data Breach (2019): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·August 1, 2019

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Facebook Data Breach (2019)

Reported August 1, 2019. Approximately 509.5M people affected.

CRITICAL
Severity
509.5M
People affected
8
Data types exposed
August 1, 2019
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Facebook Data Breach (2019) (reported August 1, 2019) exposed Dates of birth, Email addresses, Employers and Genders belonging to roughly 509.5M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
CRITICAL severityConfirmed
Exposes government-ID data.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the Facebook Data Breach (2019) breach?
509.5M accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

People whose personal contact details and profile information were included in this dataset face ongoing risks of unwanted contact, account takeovers, and targeted scams. The scale of the exposure means that even users who rarely interact with the platform could still see their information used without their knowledge. The incident involves a dataset covering 509.5 million Facebook users that was made freely available for download in April 2021. The records were allegedly obtained through a vulnerability that Facebook states it fixed in August 2019. Public reporting of the matter began on 1 August 2019. The data set represents roughly 20 percent of the platform’s subscribers at the time.

What happened

The records first appeared on a public forum in April 2021. Each entry primarily linked a phone number to an individual profile. Only 2.5 million records also contained an email address. Facebook has stated that the access method relied on a flaw it addressed in August 2019. No official confirmation of the exact acquisition date or the number of records downloaded by any party has been released.

How a breach like this happens

Incidents involving large-scale scraping of user directories often begin with the discovery of an application programming interface or feature that returns profile data when supplied with a phone number or other identifier. Once identified, automated scripts can iterate through large lists of numbers to collect associated names, locations, and other fields. The resulting files are then shared or sold on forums where the main commercial value lies in verified phone-to-identity pairings rather than in any single data element.

About Facebook

Facebook operates one of the largest social platforms worldwide and stores extensive user-provided information to support its advertising and connection features. This includes contact details, demographic attributes, and relationship indicators that users supply when creating or maintaining profiles. A release of this information at the reported scale affects a significant portion of the global internet population and underscores the concentration of personal data within a single service.

What data was at risk

The published records included dates of birth, email addresses, employers, genders, geographic locations, names, phone numbers, and relationship statuses. The facts confirm that phone numbers were present in every record, while email addresses appeared in only a small fraction. The precise completeness of each field across the full set remains unconfirmed beyond these reported categories.

The real-world impact

Individuals whose phone numbers are now linked to verified names and other attributes may receive increased unsolicited messages or be targeted in social-engineering attempts that reference accurate personal details. Organisations that rely on phone-based verification can face higher rates of account-recovery abuse. For Facebook, the episode highlights the difficulty of containing data once an enumeration technique has been used, even after the original access path is closed.

If your data was in this breach

Begin by reviewing privacy settings on any accounts that use the same phone number or email. Enable two-factor authentication that does not rely solely on SMS. Monitor statements and login alerts for unexpected activity. Readers can run a free exposure scan of their email to check whether their information has surfaced in known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyFacebook security record
70/100
DoxxScan™ · Moderate doxx risk
D 54Poor record

2 reported incidents on record.

See Facebook’s full breach history →
RelatedMore incidents at Facebook

More recent breaches

BtoBet Data Breach (2019)December 26, 2019IndiHome Data Breach (2019)November 1, 2019Data Enrichment Exposure From PDL Customer Data Breach (2019)October 16, 2019The Halloween Spot Data Breach (2019)September 27, 2019

Latest breaches

Read GalaxyWarden’s full analysis of the Facebook Data Breach (2019) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram