About 533 million Facebook profiles were published in April 2021 from a 2019 scrape — phones and personal details, not passwords. Check whether your address is in that file, then treat a matched phone number as the first job.
Quick answer — was Facebook breached?
Yes — this page is the 2019 Facebook scrape released for free in April 2021, commonly reported as about 533 million records. Passwords were not included. A match means your address appeared in that profile file. Check if you were affected.
What happened in the Facebook data breach?
This catalog row is the 2019 Facebook scrape that was published for free in April 2021 — not a password-database theft. BleepingComputer reported about 533 million user records, almost all of them carrying a mobile number plus a Facebook ID, name, and gender, with emails, dates of birth, locations, relationship status, and occupation present on many rows. This lookup lists about 509 million unique email addresses because not every scraped row included an inbox. Facebook told reporters the data came from a vulnerability it said it fixed in August 2019.
Passwords were not in the file. Changing a Facebook password does not unsay a phone number. A number tied to a real name is raw material for SMS phishing, robocalls, and SIM-swap attempts that try to steal text-message login codes. Emails in the file remain phishing hooks. Dates of birth, employers, and relationship status make impersonation mail sound local and personal.
The same set was sold privately in 2020 before the April 2021 free dump. Facebook called it “old data” and did not run a mass user notification for the 2021 publication. Ireland’s Data Protection Commission later fined Meta €265 million over Facebook’s failure to protect personal data against scraping. That fine is about the scraping controls — not proof that passwords leaked. Learn more about what a data breach means for you.
Why was the Facebook breach so dangerous?
Passwords were not in the file. Changing a Facebook password does not unsay a phone number. A number tied to a real name is raw material for SMS phishing, robocalls, and SIM-swap attempts that try to steal text-message login codes. Emails in the file remain phishing hooks. Dates of birth, employers, and relationship status make impersonation mail sound local and personal.
Yes, for the phone-and-profile playbook, not the password playbook. Numbers and emails from 2019 are still useful in 2026. A password change alone does not fix this match. Move important accounts off SMS codes, treat unexpected texts as hostile, and assume your number can be looked up next to your name.check whether your email was exposed in this breach.
What data was stolen in the Facebook breach?
Dates of birth — used to verify identity for account takeover and fraud
Email addresses — used for phishing attacks and credential stuffing against your other accounts
Employers — may be combined with other breach data to build a profile for targeted attacks
Genders — may be combined with other breach data to build a profile for targeted attacks
Geographic locations — may be combined with other breach data to build a profile for targeted attacks
Names — used to build profiles and target you with personalised scams
Phone numbers — enables SIM-swapping attacks and targeted SMS phishing
Relationship statuses — reveals your approximate location and internet provider
Timeline of the Facebook breach
2019
Operators abuse a Facebook contact-importer / friend-lookup weakness to collect phone numbers and profile fields at scale
August 2019
Facebook says it found and fixed the issue
June 2020
The set is offered for private sale on a hacking forum — BleepingComputer later reported about 533 million user records
3 April 2021
The file is published for free; contemporaneous reporting notes phones on nearly every row, plus names, Facebook IDs, and other profile fields
April 2021
Facebook tells reporters this is old 2019 data and that the vulnerability was already patched
28 November 2022
Ireland’s Data Protection Commission announces a €265 million fine against Meta over Facebook’s failure to protect personal data against scraping
2021–2026
Copies remain in people-search and phishing kits; published numbers and emails stay useful for SMS and inbox scams
Is the Facebook breach still dangerous in 2026?
Yes, for the phone-and-profile playbook, not the password playbook. Numbers and emails from 2019 are still useful in 2026. A password change alone does not fix this match. Move important accounts off SMS codes, treat unexpected texts as hostile, and assume your number can be looked up next to your name.
Phone numbers and dates of birth do not expire. An authenticator app or a hardware key ages SMS-based takeover out of your life. Learn how long stolen data stays dangerous.
Was this a password breach or a scrape?
A password breach is a copy of a company’s stored logins. This was a scrape: operators abused a contact-importer / friend-lookup weakness to pull phone numbers and join them to profile fields. Facebook said the issue was fixed in August 2019. The 2021 event was the free publication of that older set, not a new vault dump.
That distinction changes the first hour of work. There is no Facebook password in this file to rotate as the primary fix. The durable harm is the binding of a mobile number — and often an email, birth date, and employer — to a real name. Those bindings get copied into later people-search and stuffing-adjacent lists.
Other Facebook incidents are separate stories: Cambridge Analytica was app-permission misuse, not this scrape. An internal 2019 finding that some passwords had been stored in plaintext on Facebook servers was not this public file. Do not fold them into this match.
- This row — 2019 scrape, published April 2021. Phones and profile fields. No passwords.
- A password change is hygiene, not a cure for a published number.
- SMS two-factor is the weak point once a number is public next to your name.
What does an EmailLeaked Facebook match mean?
If your address is in the scraped file, EmailLeaked shows a named Facebook match the same way it shows any other named incident. The row is a lookup against industry-standard breach data sources. We do not claim an exclusive copy of the 2021 dump, and we do not crawl hidden markets live.
A match is not proof someone is inside your Facebook session this week. It is evidence that the address — and typically a phone number and profile fields from that era — appeared in a file that has been public since 2021. A miss is a snapshot of the records we can search today. We do not keep the address you type into the checker. Hosting logs and a privacy-oriented analytics beacon can still record that the page was visited.
If you want the response order in one place, use what to do after a data breach and the phone playbook there. For whether the product is reasonable to keep using, see Is Facebook safe after the data breach?. For a second public index, see free data breach checkers.
What to do if your email was in the Facebook breach
Confirm the match and what was listed
Run the email check if you need the named incidents in one list. This Facebook row lists phones and profile fields, not passwords. That is the phone-and-phishing playbook.
Check this email — freeMove important logins off SMS codes
Turn on two-factor authentication with an authenticator app or a hardware key on email, banking, and Facebook. A published number makes a text-message code easier to steal via SIM swap or SMS phishing.
Treat unexpected texts and “Facebook security” mail as hostile
The file gives scammers a name, a number, and often a workplace or birth date. Do not tap links in surprise reset messages. Walk the account security checklist for sessions, recovery contacts, and leftover apps.
Open the account checklistFollow the after-breach playbook
Use the first-hour and 24-hour lists, then the phone / email-only playbook. A Facebook match on this page is not the password-leak playbook unless a different incident also listed passwords.
Open the after-breach playbookCompare how public checkers differ
A second lookup does not unsay a published number. It can show you how different public indexes present the same named incident.
Read the checker comparisonClose Facebook if you no longer use it
Deletion does not unsay the 2019 scrape. It stops a leftover profile and recovery phone from sitting around. Deactivate is a pause; deletion is for accounts you are done with.
How to delete your Facebook accountFrequently asked about the Facebook breach
What data was in the Facebook 533 million-record file?
Why are exposed phone numbers dangerous if the password did not leak?
Did Facebook notify the people in the 2021 dump?
I changed my Facebook password after 2021 — does that fix this match?
How does EmailLeaked show a Facebook match?
Is the Facebook scrape still dangerous in 2026?
How this breach page is reviewed
Breach pages are built from structured breach records and reviewed for practical risk guidance by EmailLeaked. Risk labels reflect exposed data types and are intended to help readers prioritise action.
Sources
Last updated: September 2026
Other major breaches
Was your email in this breach?
Check if your email appeared in the Facebook breach and 1033+ other known breaches — free, instant, no signup.
Check my email — freeWas my email hacked?
Check if your email is compromised in seconds. Free, private, no signup. Scan millions of breach records across 1034+ known breaches.
Check my email now — it's freeNo signup required · Results in under 5 seconds · Your data is never stored