Skip to main content

PSA: Was your personal data leaked from Facebook? Here’s how to check…

It was revealed over the weekend that a huge data breach saw personal data leaked from Facebook, including phone numbers, full names, and dates of birth. There’s now a way for you to check if any of your personal data was compromised …

Background

Although it has just made the news now, the breach occurred much earlier, as tweeted back in January of this year by security firm Hudson Rock.

In early 2020 a vulnerability that enabled seeing the phone number linked to every Facebook account was exploited, creating a database containing the information 533m users across all countries. It was severely under-reported and today [January 14 2021], the database became much more worrisome.

Few days ago a user created a Telegram bot allowing users to query the database for a low fee, enabling people to find the phone numbers linked to a very large portion of Facebook accounts. This obviously has a huge impact on privacy.

Facebook confirmed the breach, but said that it actually took place in 2019, not 2020.

Business Insider verified some of the records.

Insider reviewed a sample of the leaked data and verified several records by matching known Facebook users’ phone numbers with the IDs listed in the data set. We also verified records by testing email addresses from the data set in Facebook’s password reset feature, which can be used to partially reveal a user’s phone number.

Was your personal data leaked from Facebook?

TNW reports that haveibeenpwned.com now has a copy of the data, allowing you to check whether your data was exposed.

  • Head to haveibeenpwned.com on your phone or desktop.
  • Enter your email ID.
  • If your email was compromised, you’ll get a warning to change the password and enable two-factor authentication. You can also scroll down on the page to see all the breaches that may have included your credentials tied to the email address you entered.

Right now, you can only search for your email address, but TNW says it’s possible the database will be expanded to allow phone number searches too.

As always, we recommend protecting your privacy by using a password manager for all the sites and services you use, and switching on two-factor authentication where supported. This blocks two of the most common forms of attack: dictionary attacks, where the hacker tries a variety of commonly used passwords; and trying credentials from one breached website on a bunch of others.

FTC: We use income earning auto affiliate links. More.

You’re reading 9to5Mac — experts who break news about Apple and its surrounding ecosystem, day after day. Be sure to check out our homepage for all the latest news, and follow 9to5Mac on Twitter, Facebook, and LinkedIn to stay in the loop. Don’t know where to start? Check out our exclusive stories, reviews, how-tos, and subscribe to our YouTube channel

Comments

Author

Avatar for Ben Lovejoy Ben Lovejoy

Ben Lovejoy is a British technology writer and EU Editor for 9to5Mac. He’s known for his op-eds and diary pieces, exploring his experience of Apple products over time, for a more rounded review. He also writes fiction, with two technothriller novels, a couple of SF shorts and a rom-com!


Ben Lovejoy's favorite gear

Manage push notifications

notification icon
We would like to show you notifications for the latest news and updates.
notification icon
You are subscribed to notifications
notification icon
We would like to show you notifications for the latest news and updates.
notification icon
You are subscribed to notifications