The Irish Data Protection Commission (DPC) is investigating the massive Facebook data leak affecting 533 million users of the social network.
According to the DPC, previous datasets were published in 2019 and 2018 as part of a large-scale scraping of Facebook’s website, which Facebook says occurred between June 2017 and April 2018 , when the social media giant fixed a vulnerability in its phone lookup feature. Because the scraping took place before the GDPR came into effect , Facebook chose not to disclose it as a data breach under the GDPR.

The DPC also said that the recently leaked dataset appears to include information from additional user records , which may date back to a later period. The Commission added that it had difficulty contacting Facebook over the weekend to verify the facts.
Read also: UK: Will authorities have access to Facebook messaging services?
When asked for more details about the leak, a Facebook spokesperson told Bleeping Computer: “This is old data that was previously reported in 2019. We identified and fixed this issue in August 2019.”

Additionally, Graham Doyle, Head of Media and Deputy Commissioner of the DPC, stated the following: “Following this weekend’s media reports, we are looking into the matter to establish whether the dataset being reported is indeed the same as that reported in 2019.”
The mobile phone numbers and other personal information of hundreds of millions of Facebook users around the world were leaked for free on a popular hacking forum. Malicious actors stole information from the profiles 533,313,128 Facebook users, including phone numbers, Facebook IDs, names, genders, locations, relationship statuses, occupations, dates of birth and email addresses.
See also: Zuckerberg: My 5-year-old daughter uses Facebook Messenger Kids
Notably, the data exposed in the leak includes the phone numbers of three Facebook executives – Mark Zuckerberg, Chris Hughes, and Dustin Moskovitz.

At present, it is believed that hackers exploited the now-patched vulnerability in Add Friend feature in 2019, aiming to gain access and collect Facebook members' phone numbers.
This is extremely sensitive data that has remained unchanged for most of the affected Facebook users – data that cybercriminals can use in phishing or smishing attacks.
Suggestion: Brazil: First in phishing attacks. Which countries follow?
Additionally, fraudsters can use the information leaked in SIM swapping attacksto steal their targets' multi-factor authentication (MFA) codes, which are sent via SMS.

You can use the Have I Been Pwned to check if your information has been exposed in this massive Facebook data leak by entering email or phone number in the search field.
Roskomnadzor , Russia's media and internet watchdog, has asked Facebook to provide information about the leak of Russian users' personal data. It also demands that the social network's administration take all necessary measures to prevent such leaks .
Information source: bleepingcomputer.com
