Facebook

Medium

About 533 million Facebook profiles were published in April 2021 from a 2019 scrape — phones and personal details, not passwords. Check whether your address is in that file, then treat a matched phone number as the first job.

509.5M
Records exposed
2019
Year
8
Data types
Free
To check
Check if you were affected — free

Quick answer — was Facebook breached?

Yes — this page is the 2019 Facebook scrape released for free in April 2021, commonly reported as about 533 million records. Passwords were not included. A match means your address appeared in that profile file. Check if you were affected.

What happened in the Facebook data breach?

This catalog row is the 2019 Facebook scrape that was published for free in April 2021 — not a password-database theft. BleepingComputer reported about 533 million user records, almost all of them carrying a mobile number plus a Facebook ID, name, and gender, with emails, dates of birth, locations, relationship status, and occupation present on many rows. This lookup lists about 509 million unique email addresses because not every scraped row included an inbox. Facebook told reporters the data came from a vulnerability it said it fixed in August 2019.

Passwords were not in the file. Changing a Facebook password does not unsay a phone number. A number tied to a real name is raw material for SMS phishing, robocalls, and SIM-swap attempts that try to steal text-message login codes. Emails in the file remain phishing hooks. Dates of birth, employers, and relationship status make impersonation mail sound local and personal.

The same set was sold privately in 2020 before the April 2021 free dump. Facebook called it “old data” and did not run a mass user notification for the 2021 publication. Ireland’s Data Protection Commission later fined Meta €265 million over Facebook’s failure to protect personal data against scraping. That fine is about the scraping controls — not proof that passwords leaked. Learn more about what a data breach means for you.

Why was the Facebook breach so dangerous?

Passwords were not in the file. Changing a Facebook password does not unsay a phone number. A number tied to a real name is raw material for SMS phishing, robocalls, and SIM-swap attempts that try to steal text-message login codes. Emails in the file remain phishing hooks. Dates of birth, employers, and relationship status make impersonation mail sound local and personal.

Yes, for the phone-and-profile playbook, not the password playbook. Numbers and emails from 2019 are still useful in 2026. A password change alone does not fix this match. Move important accounts off SMS codes, treat unexpected texts as hostile, and assume your number can be looked up next to your name.check whether your email was exposed in this breach.

What data was stolen in the Facebook breach?

Dates of birth Email addresses Employers Genders Geographic locations Names Phone numbers Relationship statuses

Dates of birth — used to verify identity for account takeover and fraud

Email addresses — used for phishing attacks and credential stuffing against your other accounts

Employers — may be combined with other breach data to build a profile for targeted attacks

Genders — may be combined with other breach data to build a profile for targeted attacks

Geographic locations — may be combined with other breach data to build a profile for targeted attacks

Names — used to build profiles and target you with personalised scams

Phone numbers — enables SIM-swapping attacks and targeted SMS phishing

Relationship statuses — reveals your approximate location and internet provider

Timeline of the Facebook breach

2019

Operators abuse a Facebook contact-importer / friend-lookup weakness to collect phone numbers and profile fields at scale

August 2019

Facebook says it found and fixed the issue

June 2020

The set is offered for private sale on a hacking forum — BleepingComputer later reported about 533 million user records

3 April 2021

The file is published for free; contemporaneous reporting notes phones on nearly every row, plus names, Facebook IDs, and other profile fields

April 2021

Facebook tells reporters this is old 2019 data and that the vulnerability was already patched

28 November 2022

Ireland’s Data Protection Commission announces a €265 million fine against Meta over Facebook’s failure to protect personal data against scraping

2021–2026

Copies remain in people-search and phishing kits; published numbers and emails stay useful for SMS and inbox scams

Is the Facebook breach still dangerous in 2026?

Yes, for the phone-and-profile playbook, not the password playbook. Numbers and emails from 2019 are still useful in 2026. A password change alone does not fix this match. Move important accounts off SMS codes, treat unexpected texts as hostile, and assume your number can be looked up next to your name.

Phone numbers and dates of birth do not expire. An authenticator app or a hardware key ages SMS-based takeover out of your life. Learn how long stolen data stays dangerous.

Was this a password breach or a scrape?

A password breach is a copy of a company’s stored logins. This was a scrape: operators abused a contact-importer / friend-lookup weakness to pull phone numbers and join them to profile fields. Facebook said the issue was fixed in August 2019. The 2021 event was the free publication of that older set, not a new vault dump.

That distinction changes the first hour of work. There is no Facebook password in this file to rotate as the primary fix. The durable harm is the binding of a mobile number — and often an email, birth date, and employer — to a real name. Those bindings get copied into later people-search and stuffing-adjacent lists.

Other Facebook incidents are separate stories: Cambridge Analytica was app-permission misuse, not this scrape. An internal 2019 finding that some passwords had been stored in plaintext on Facebook servers was not this public file. Do not fold them into this match.

  • This row — 2019 scrape, published April 2021. Phones and profile fields. No passwords.
  • A password change is hygiene, not a cure for a published number.
  • SMS two-factor is the weak point once a number is public next to your name.

What does an EmailLeaked Facebook match mean?

If your address is in the scraped file, EmailLeaked shows a named Facebook match the same way it shows any other named incident. The row is a lookup against industry-standard breach data sources. We do not claim an exclusive copy of the 2021 dump, and we do not crawl hidden markets live.

A match is not proof someone is inside your Facebook session this week. It is evidence that the address — and typically a phone number and profile fields from that era — appeared in a file that has been public since 2021. A miss is a snapshot of the records we can search today. We do not keep the address you type into the checker. Hosting logs and a privacy-oriented analytics beacon can still record that the page was visited.

If you want the response order in one place, use what to do after a data breach and the phone playbook there. For whether the product is reasonable to keep using, see Is Facebook safe after the data breach?. For a second public index, see free data breach checkers.

What to do if your email was in the Facebook breach

1

Confirm the match and what was listed

Run the email check if you need the named incidents in one list. This Facebook row lists phones and profile fields, not passwords. That is the phone-and-phishing playbook.

Check this email — free
2

Move important logins off SMS codes

Turn on two-factor authentication with an authenticator app or a hardware key on email, banking, and Facebook. A published number makes a text-message code easier to steal via SIM swap or SMS phishing.

3

Treat unexpected texts and “Facebook security” mail as hostile

The file gives scammers a name, a number, and often a workplace or birth date. Do not tap links in surprise reset messages. Walk the account security checklist for sessions, recovery contacts, and leftover apps.

Open the account checklist
4

Follow the after-breach playbook

Use the first-hour and 24-hour lists, then the phone / email-only playbook. A Facebook match on this page is not the password-leak playbook unless a different incident also listed passwords.

Open the after-breach playbook
5

Compare how public checkers differ

A second lookup does not unsay a published number. It can show you how different public indexes present the same named incident.

Read the checker comparison
6

Close Facebook if you no longer use it

Deletion does not unsay the 2019 scrape. It stops a leftover profile and recovery phone from sitting around. Deactivate is a pause; deletion is for accounts you are done with.

How to delete your Facebook account

Frequently asked about the Facebook breach

What data was in the Facebook 533 million-record file?
Contemporaneous reporting described about 533 million user records with a mobile number on nearly every row, plus Facebook IDs, names, and gender, and often email, date of birth, location, relationship status, and occupation. This catalog row lists about 509 million unique emails. Passwords were not included.
Why are exposed phone numbers dangerous if the password did not leak?
A number next to a real name is enough for SMS phishing and for SIM-swap attempts that try to steal text-message login codes. Changing a Facebook password does not change the published number. Move important accounts off SMS two-factor authentication.
Did Facebook notify the people in the 2021 dump?
Facebook told reporters the data was old and from a patched 2019 issue. It did not run a mass personal notification for the April 2021 free publication. Ireland’s Data Protection Commission later fined Meta over the scraping controls.
I changed my Facebook password after 2021 — does that fix this match?
Not for this file. Passwords were not in the scrape. Password hygiene is still wise, but the match-specific work is phone-number risk, SMS codes, and phishing that uses your name and workplace.
How does EmailLeaked show a Facebook match?
As a named row in the email checker, using industry-standard breach data sources. This explainer is the plain-English layer: 2019 scrape, phones and profile fields, not a password vault. We do not claim exclusive ownership of the 2021 dump.
Is the Facebook scrape still dangerous in 2026?
Yes, for phishing and SIM-swap risk. The bindings of name, number, and email do not expire. Authenticator-app two-factor authentication and skepticism toward unexpected texts are what age this file out of your life.

How this breach page is reviewed

Breach pages are built from structured breach records and reviewed for practical risk guidance by EmailLeaked. Risk labels reflect exposed data types and are intended to help readers prioritise action.

Was your email in this breach?

Check if your email appeared in the Facebook breach and 1033+ other known breaches — free, instant, no signup.

Check my email — free

No signup · Under 2 seconds · Never stored

Was my email hacked?

Check if your email is compromised in seconds. Free, private, no signup. Scan millions of breach records across 1034+ known breaches.

Check my email now — it's free

No signup required · Results in under 5 seconds · Your data is never stored