LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Facebook Marketplace Data Breach (2023)

HIGH severityConfirmedHow we verify

Facebook Marketplace Data Breach (2023): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·October 1, 2023

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Facebook Marketplace Data Breach (2023)

Reported October 1, 2023. Approximately 77K people affected.

HIGH
Severity
77K
People affected
6
Data types exposed
October 1, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Facebook Marketplace Data Breach (2023) (reported October 1, 2023) exposed Email addresses, Geographic locations, Names and Passwords belonging to roughly 77K people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityConfirmed
Account credentials exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the Facebook Marketplace Data Breach (2023) breach?
77K accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In a threat landscape where marketplace platforms and their contractors remain frequent targets for data theft and resale, a 2023 incident tied to Facebook Marketplace illustrates how records can move from internal systems into public forums months later. What is known is limited but concrete: tens of thousands of unique records associated with the service were later posted online, carrying personal identifiers that can be reused for fraud or further targeting.

According to reporting dated 1 October 2023 and subsequent forum activity described in early 2024, roughly 200,000 Facebook Marketplace records—allegedly obtained from a Meta contractor—were shared on a popular hacking forum. Those records included about 77,000 unique email addresses along with names, phone numbers, Facebook profile IDs, geographic locations, and bcrypt password hashes whose link to actual Facebook accounts is unconfirmed. The episode matters because marketplace users often treat such platforms as routine channels for local commerce, not as repositories of lasting personal data.

What happened

Public detail describes an alleged acquisition of Facebook Marketplace records from a Meta contractor in October 2023. In February 2024 those records—approximately 200,000 in total—were posted to a popular hacking forum. Analysis of the material indicated roughly 77,000 unique email addresses, together with names, phone numbers, Facebook profile IDs and geographic locations. The same dataset also contained bcrypt password hashes; there is no indication these hashes belong to the corresponding Facebook accounts. No further technical method, exact contractor identity, or confirmed root cause has been disclosed in the available facts. Scale is therefore stated only in the figures above; timing of the original access is given as October 2023, with public posting following in February 2024.

How a breach like this happens

Incidents of this general type commonly begin with access to systems or files held by a third-party contractor rather than by the primary platform itself. Contractors often receive bulk extracts or operational datasets for support, moderation, analytics or logistics work. Once an unauthorised party obtains those files—through compromised credentials, misconfigured storage, insider misuse or other means—the material can be copied, packaged and later offered or dumped on criminal forums. Password material, when present, is frequently stored as one-way hashes; bcrypt is a deliberately slow hashing algorithm intended to slow offline guessing, yet the mere presence of hashes still signals that credential-related data left its intended boundary. No specific threat group is named in connection with this case, and the precise vector remains undisclosed. The pattern itself is familiar: contractor-held copies become the weak link, after which the data’s secondary life on forums determines how widely it circulates.

Who is Facebook Marketplace?

Facebook Marketplace is the classifieds and local-commerce feature operated within Meta’s Facebook ecosystem. It allows individuals and small sellers to list goods, arrange local pickup or shipping, and communicate with buyers. Like other large consumer marketplaces, it necessarily processes account identifiers, contact details, approximate location information tied to listings or profiles, and related social-graph data so that users can complete transactions. Because the service sits inside a major social network, a breach involving Marketplace-linked records can expose not only commerce-related fields but also bridges to broader profile information. That combination makes any confirmed or alleged exposure consequential: affected people may face targeted phishing that references real listings or locations, while the organisation must contend with trust erosion among users who rely on the platform for everyday buying and selling.

The information in question

The facts name the following data types as present in the posted material: email addresses, geographic locations, names, passwords (in the form of bcrypt hashes), phone numbers, and social media profiles (including Facebook profile IDs). Approximately 77,000 unique email addresses were identified within a larger set of roughly 200,000 records. The bcrypt hashes are explicitly noted as lacking any confirmed correspondence to the Facebook accounts of the individuals involved. Beyond these points, exact file formats, full field schemas and any additional undisclosed elements remain unconfirmed. Organisations of this kind typically also hold listing histories, message metadata and device or session signals; whether any of those appeared here is not stated in the available record.

Why it matters

For individuals, the combination of name, email, phone number, location and social-profile identifiers supplies ready material for phishing, smishing, account-recovery abuse and social-engineering attempts that appear locally relevant. Even if the password hashes cannot be tied to Facebook logins, their presence still expands the set of secrets an attacker might try to crack or correlate with other breaches. Geographic data can narrow physical or regional targeting. For the organisation, contractor-sourced leaks raise ongoing questions about data-minimisation and third-party controls, and they can prompt regulatory scrutiny or user attrition even when the primary platform’s own authentication systems are not shown to have been directly compromised. The delay between alleged acquisition (October 2023) and public posting (February 2024) also means affected people may have had little timely notice.

If your data was in this breach

If you used Facebook Marketplace and recognise the timeframe or data types described, treat the exposure as a prompt for basic hygiene rather than panic. Concrete first steps include:

You can also run a free exposure scan of your email address to check whether it has appeared in known breach datasets. Public detail on this incident remains bounded by the figures and field types already stated; treat any broader claims with corresponding caution until further verified information appears.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyFacebook Marketplace security record
74/100
DoxxScan™ · Moderate doxx risk
B- 77Above-average record

1 reported incident on record.

See Facebook Marketplace’s full breach history →

More recent breaches

Hathway Data Breach (2023)December 17, 2023InflateVids Data Breach (2023)December 12, 2023KitchenPal Data Breach (2023)November 14, 2023Naz.API Data Breach (2023)September 20, 2023

Latest breaches

Read GalaxyWarden’s full analysis of the Facebook Marketplace Data Breach (2023) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram