Comparitech, in collaboration with security researcher Bob Diachenko database , of more than 267 million Facebook user IDs, phone numbers, and names was exposed online revealed that a without passwords or other authentication.
According to the evidence available so far, Diachenko believes that this is a hacking attack by cybercriminals from Vietnam, who either abused the Facebook API or used the "scraping" technique.
The information contained in the database could be used to carry out large-scale attacks with spam SMS and phishing emails, as well as other hacking campaigns.
Diachenko informed the internet service provider that manages the serverto block unauthorized access to the database. However, Diachenko said the data has already been published on a hacking forum.
The chronicle of the leak
The database of Facebook users' details was exposed online for about two weeks:
December 4 – The initial database entry.
December 12 – The data was posted as a “download” on a hacking forum.
December 14 – Diachenko discovered the database and informed the ISP.
December 19 – The database is no longer available.

What kind of data was exposed?
According to the data, the database contained 267,140,436 records user, most of which were from the United States. What data was exposed:
- A unique Facebook ID
- Telephone number
- Full name etc.
It is not yet known how the criminals managed to obtain the users' IDs. They were likely stolen from the Facebook API before 2018, when the company had not yet banned access to phone numbers . Facebook's API is used by app developers to add social context to their apps by accessing users' profiles, friends lists, photos and event data. Phone numbers were also available to third parties before 2018.
Also, according to Diachenko, Facebook's API could have a vulnerabilitythat allowed criminals to gain access to users' IDs and numbers.
Another possibility is that data from user profiles was stolen.
“ Scraping ” is a technique in which automated bots search a large number of pages and copy data into a database. Social networking platforms , such as Facebook, cannot easily prevent scraping because they usually cannot distinguish between legitimate users and bots.
In September 2019, something similar happened, with a database containing 419 million Facebook user records.
Risks of data exposure
Exposed databases containing such data can be used by cybercriminals to carry out many different attacks. The most common are phishing emails and spam SMS. Therefore, users should be very careful and be aware of any message from an unknown source.
Facebook users themselves can limit the scraping of their profiles by changing their account privacy settings :
- Open Facebook and go to “Settings”
- Click on “Privacy”
- Set all relevant fields: “Friends” or “Only me”
- To the question “Do you want search engines outside of Facebook to connect to your profile?” select the answer “No”.
This will reduce the chances of scraping. Of course, the only surefire way to protect yourself is to deactivate or delete your Facebook account.
