Database with phone numbers of 267 million Facebook users shared online

Beware phone calls and texts from unknown numbers.
Original image replaced with Mashable logo

Millions of phone numbers publicly listed by Facebook users were shared in an online forum where hackers hang out.

A database containing more than 267 million Facebook phone numbers and user IDs were recently discovered by cybersecurity firm Comparitech in partnership with security researcher Bob Diachenko.

Many Facebook users publicly list their phone numbers, but an easily accessible database like this helps malicious actors in spam and phishing schemes.

Researchers aren't sure how the database was created. It could have been illegally compiled through an automated process called scraping, where public information is copied from the internet, in this case from Facebook profiles.

It could have also been created through the Facebook API, a tool that gives third-party developers access to user information so they can create Facebook applications. The API stopped giving access to user phone numbers in 2018, so it's possible the data was collected before the new policy was enacted.

Researchers believe the operation was being run by a criminal organization in Vietnam.

The database was not password protected and was completely open to the public. Diachenko usually notifies the owner of an exposed database so they can secure it. However, in this case, the owners of the database were illegally maintaining it. So, the researcher directly informed the internet service provider managing the IP address of the server where the database was stored, and it was taken down on Dec. 19. Diachenko believes the illegal database was set public by mistake.

Facebook users who have their phone number set to public should be cautious of phone calls and text messages from unknown numbers, as the information could be used in spam or phishing campaigns.

Facebook has been hit with a number of data breach issues this year. A similar database containing more than 400 million Facebook user IDs and phone numbers was discovered in September.

While publicly scraped data is harder for companies like Facebook to stop, there were other occasions where this information was accessed through the social network’s own developer API. For example, this past April, millions of Facebook user records, including plain-text passwords, were discovered. The data was exposed by third-party app developers.

Comparitech recommends that Facebook users set their privacy settings to “friends” or “only me” as well as turning off the option that allows search engines to link to your profile. This will help reduce the risk of your data being accessed by third parties.

However, the cybersecurity firm notes that the only way to be sure that it never happens is to deactivate or delete your Facebook profile.

Mashable Potato

Recommended For You
Jimmy Kimmel has a blunt response to 'Melania' documentary box office numbers
A man in a suit stands on a talk show stage. The caption reads, "Speaking of rigged outcomes, the 'Melania' documentary..."

Samsung Galaxy Z TriFold Phone quickly sells out online despite near $3,000 pricetag
White man holds samsung galaxy z trifold

Verified LinkedIn users' data is shared in shocking ways, report claims
LinkedIn app logo

3 AdultFriendFinder features exclusive to paid users
By Jack Dawes
Plus signs coming out of treasure chest

'SNL UK' cold open mocking Keir Starmer gets shared by Donald Trump
A worried man sits behind a desk.

More in Tech
Amazon's sister site is having a one-day sale, and this Bissell TurboClean deal is too good to skip
A woman using the Bissell TurboClean Cordless Hard Floor Cleaner Mop and Lightweight Wet/Dry Vacuum.

The best smartwatch you've never heard of is on sale for less than $50
Nothing CMF Watch 3 Pro in light green with blue and green abstract background

Reddit r/all takes another step into the grave
Reddit logo on phone screen

Take back your screen from ads and trackers with this $16 tool
AdGuard Family Plan: Lifetime Subscription


Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone

What's new to streaming this week? (April 3, 2026)
A composite of images from film and TV streaming this week.

Google launches Gemma 4, a new open-source model: How to try it
Google Gemma

The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!