18 ms·
The Facebook phone numbers are now searchable in Have I Been Pwned
- Tenoke 6y agoOddly enough even my email doesn't show up for the Facebook breach (possibly because I never added a number on Facebook, just whatsapp). It does show up for companies I've trusted more though - Dropbox, Linux Mint, XKCD (md5 really?), Forbes, etc.
- nikbackm 6y agoI just logged in to Facebook for the first time in years to check the data it has on me. Luckily I never added my phone number or address, so should hopefully be in the clear.
- Macha 6y agoDid you ever set up SMS 2fa? Did any of your contacts use the Facebook app to sync their contacts (at least at one point a default behaviour)? Then Facebook has your number. I remember when I still used it being promoted by a bar at the top of the web UI "Is this your number?" With my actual number suggesting I add it to my profile, so I know they have mine.
- antegamisou 6y agoI have had the exact same experience. Interestingly, it took them a few tries to get to my actual number and they still carried on throwing other random phone numbers I did not recognize.
- jtylr 6y agoDespite using 2FA and listing my number on my profile - albeit restricted to "just me", I don't appear in the data. It's not as simple as they just having a record of it somewhere.
- wccrawford 6y agoI'm in the same situation and very surprised. I've sat here wondering if I'm entering my numbers wrong, or if I'm really not in it. I've read the blog post and I'm entering the 1 in front of my 10 digits, because I'm in the USA. My wife's number isn't in there, either. I'm just really surprised, because I checked facebook the other day and it said I was searchable by email and phone number. I even searched my email address, and a lot of other breaches show, but not Facebook. I guess I got lucky?
- ricardobayes 6y agoUS numbers are not uploaded yet
- wccrawford 6y agoAh, that makes sense then. I assumed they were because the instructions showed the US style specifically. Thanks!
- Etheryte 6y agoLikewise, it seems there's more nuance to this leak. I checked the data out and a large number of my contacts have correct numbers in it. At the same time, numerous people don't appear in it, even if they do have a phone number on their profile.
- vmception 6y agoI've been intentionally breaking my social graph since at least 2012. Looks like its worked here. When I make a Facebook account, usually for my living complex's community or a bunch of Gen-Xer's doing a burning man thing, I use a new email or new phone number for signup and one time passwords. I don't let it get access to my contacts, assuming I inadvertently installed the Facebook app on a phone. Doesn't look like they meaningfully go deeper than that. I find the social graph to be very fungible, so if I really ever want to recreate it I can just add my phone number or give any app access to my contacts. This knowledge also lets me not be married to any of these services. I'm very content downloading the account data and then deleting the account.
- freebuju 6y agoTry creating a new facebook account today. The site won't let you do that without verifying a phone number. The difficulty level increases if you try doing so behind a vpn. Same goes for other SM sites like Twitter.
- mimimi31 6y agoI don't think that's true. I created a Facebook account a few weeks ago and a Twitter account just yesterday, both without needing a phone number.
- teddyh 6y agoBy all accounts, anyone can create an account, but then the account invariably quickly gets suspended, requiring a phone number for “verification”.
- durnygbur 6y agoDon't they have a "real person" policy now? ie. not only phone number but as well a requirement to upload a passport style photo. Concidentally on entrance to US a camera makes a high resolution photo of every traveller during passport control.
- nonameiguess 6y agoI believe they have always had this policy, though it wasn't particularly well enforced when they opened up the platform to all comers. I actually had a Facebook account before I even first got a mobile phone at all, back in 2004 when you needed a .edu email address to sign up, which just meant they were delegating identity verification to the university. I think people were fairly comfortable with it back then because the only other users who could see you were people from the same school and it just mimicked the physical "facebook" that universities already published and made available to everyone with directory listings including your official photo and the phone number and room number of your dorm if you lived on campus. There was no open network. You could only even search for people from your own school. Obviously, the platform has radically changed since then, but they have gotten a lot of mileage out of the illusion that you could freely share what you wanted because the only people who were going to see it were people who already knew you anyway, which was at least somewhat true at first.
- layoutIfNeeded 6y agoHaha, no. It’s enough if one of your friends/relatives/etc. had allowed Facebook/Instagram/WhatsApp/etc. to scan their contact list. Your phone number is in there, just not shown, trust me. In fact Facebook used to show creepy suggestions when such cross-pollination of data occured, like “Click here to confirm that XXXXXX is your phone number!”, but they stopped doing that a few years ago.
- benaadams 6y ago> "One last note on the data load process: At the time of publishing this blog post, all phone numbers beginning with international codes 4, 6, 8 and 9 have completed loading. The other codes are in progress and may take several hours more before they're searchable." https://twitter.com/troyhunt/status/1379366099544797189 https://twitter.com/troyhunt/status/1379366099544797189
- woko 6y agoThanks, because the end of the blog post mentions 8 instead of 9: > At the time of publishing this blog post, all phone numbers beginning with international codes 4, 6, 8 and 8 have completed loading. The other codes are in progress and may take several hours more before they're searchable. So I was like: what about another 8? Edit: Actually, it is "4, 6, 7 and 8"! cf. https://twitter.com/troyhunt/status/1379377818618884098 https://twitter.com/troyhunt/status/1379377818618884098
- drcongo 6y agoI'm completely unsurprised that my phone number is in there despite the fact that I deleted and closed my account 10 years ago.
- 2muchcoffeeman 6y agoI got a bunch of spam phone calls today.
- shnp 6y agoI deleted my phone number around mid-2018 and it’s also part of the leak tying the phone number to my name and gender https://news.ycombinator.com/item?id=26708923 https://news.ycombinator.com/item?id=26708923
- milofeynman 6y agoSimilar experience. Class action?
- hendersoon 6y agoWe don't know exactly when the data was exfiltrated, just that it ended in early 2019. It could have been taken at any point before that time.
- shnp 6y ago
- pedrocr 6y agoOne thing I didn't find on the website was a way to get an email with the actual data that was leaked so I can evaluate what's at stake. Showing it online would be poor privacy but sending it to the email should solve that. Some of the leaks are from companies I don't even know, that work behind the scenes aggregating information. Particularly for those I'd like to see what was leaked. For the services I actually used directly I have a clearer idea.
- account42 6y ago> One thing I didn't find on the website was a way to get an email with the actual data that was leaked so I can evaluate what's at stake. Showing it online would be poor privacy but sending it to the email should solve that. Not it would not solve that since HIBP would have to store that data (which they currently don't) and thus might be subject to leaks themselves.
- teddyh 6y agoLinks to the actual data (allegedly): https://pastebin.com/sq7UDyVb https://pastebin.com/sq7UDyVb
- J_tt 6y agoSeems to be missing Australia, I was curious to see what data had been leaked about me, since it seems to vary significantly.
- coatmatter 6y agoThis set is missing Australia yes, but not the other set Troy Hunt was sent - he covers this in his blog post and tweets. There are at least two sets floating around. The ones loaded into HIBP do contain Australian numbers - I've checked.
- jaywalk 6y agoThanks, I was looking for that. Aside from linking my name to my cell phone number (which I really can't even assume is private anymore) there's nothing private in there for me.
- gmargari 6y agoThanks, I did a quick hack to find my Google contacts in leak file, so I can inform them: https://gist.github.com/gmargari/95976c58d2ef0c05cc1f03fc02379341 https://gist.github.com/gmargari/95976c58d2ef0c05cc1f03fc023...
- HenryBemis 6y agoI searched my number(s), no hits. I did a +/- a few numbers, and there is a hit. The message is though: "Oh no — pwned!" The only information exposed to me is that the person with that number, has a FB profile. If I am to trust FB (which I don't - for nothing) is that FB has this person's number and lost it. I place no reliance to anything that FB states. For all I know that person is a WhatsApp user and the FB branch 'stole' the number and added that to their FB account (yes, I know this is not how data works, but this is how FB works). (semi-rant follows - apologies) There is a mention of 2FA/MFA in another comment. I wouldn't be surprised if FB already has a 'super profile', where all data by FB-WA-IG are merged. I believe that would be a nightmare to do, but hey, FB is good at nightmares. Edit: I feel this is a semi "Ashley Madison" moment. People who have a 'secret' FB profile may get busted by their BFs/GFs.
- williesleg 6y agoWhat do you expect? Passwords aren't security, they're a programming construct.
- polycaster 6y agoI'm sure not to be the first one to point this out, but checking other people's emails is quite revealing. It's very much documenting in public which sort of websites about every person you know is visiting. Among them [1] "Baby Names", "Ashley Madison", "Adult FriendFinder", "diet.com". Want to profile your friends – there you are. I wonder if the benefits of haveibeenpwned outweights this. [1] https://haveibeenpwned.com/PwnedWebsites https://haveibeenpwned.com/PwnedWebsites
- paranoidrobot 6y agoTroy has covered this several times, but some sites, even showing in the PwnedWebsites list, are not viewable until/unless you confirm control of the email address or Domain. e: To be clear, the Ashley Madison, and Adult Friend Finder (both breaches) are denoted on the list as not being publicly searchable.
- nonameiguess 6y agoI just checked myself and thankfully I've apparently only been in a few breaches, but of the ones listed, I only knowingly had accounts on LinkedIn and Dropbox. Nothing embarrassing because I'm smart enough to use burner accounts for embarrassing stuff, but I only even recognize last.fm and LuminPDF as services. I'm surprised last.fm still exists. I guess I might have signed up for it at some point and forgotten. My phone number isn't in here anywhere, so lucky me, but it doesn't make a difference. The State of Texas finally forced me to get a Texas driver's license in order to continue being able to vote, and the State of Texas sells your address and phone number to marketers once they have it, so my number is trash now anyway. 99 out of 100 texts and calls are either politicians or people claiming to want to buy one of my houses. I basically no longer use a phone except when my dad calls. I guess the plus side there is I'm somewhat immune from whatever location tracking can't be disabled since I don't even take my phone with me most of the time when I go anywhere, but that was an old habit from when I worked in a SCIF and couldn't bring a phone with me anyway.
- astura 6y agoIt's set up so that you have to prove you own the email address before knowing if you're included in "sensitive" breaches.
- jhoechtl 6y agoWhat a great service to gather phone numbers even from those who haven't been pawned!
- diegoperini 6y agoI trust Troy more than I trust Facebook. His incentives are aligned with staying honest.
- durnygbur 6y agoEvery time Facebook/Gmail/Google/Amazon/LinkedIn/Tinder/whoever asks me to give them phone number "just in case" my first and only thought is "hell no". I haven't been wrong a single time.
- codedokode 6y agoSadly, many companies now require a phone number to use their services. For example: Signal, Telegram, Whatsapp, social networks like Instagram and Vk. They don't like anonymous users. For some users, Google requires a phone number to sign up. Twitter requires a phone number if they see something "suspicious" in user's behaviour.
- 0x_rs 6y agoLet's not forget the notable case of Twitter "accidentally" using your provided phone number for advertising purposes [0], and to this day still banning you after registration if you refuse to give it. [0]. https://www.eff.org/deeplinks/2019/10/twitter-uninentionally-uses-your-2fa-number-targeted-advertising https://www.eff.org/deeplinks/2019/10/twitter-uninentionally...
- finiteseries 6y agoI’ve been using Twitter to follow some people who don’t have blogs etc since last May, and haven’t been banned yet. Lots of likes, no RTs or posts though.
- Nextgrid 6y agoFacebook did this as well.
- deleted 6y ago[deleted]
- sneak 6y agoTwitter also had staff who leaked Twitter account PII from the Twitter DB to spies from the Saudi government, who have a habit of killing journalists from time to time. https://www.buzzfeednews.com/article/alexkantrowitz/how-saudi-arabia-infiltrated-twitter https://www.buzzfeednews.com/article/alexkantrowitz/how-saud... Collecting this data is an accident (or murder?) waiting to happen.
- ClearAndPresent 6y agoTroy says: " At the time of publishing this blog post, all phone numbers beginning with international codes 4, 6, 8 and 8 have completed loading." Interestingly, several cellphone numbers I know to be present in one set of leak data which start with international code 4 are not detected by HaveIBeenPwned.
- edf13 6y agoInterestingly www.TroyHunt.com is blocked by Quad9 DNS!
- coatmatter 6y agoFixed now.
- hypertele-Xii 6y agoCan I sue Facebook for leaking my number? Serious question.
- kube-system 6y agoWhat damages have you incurred?
- bogwog 6y agoIdentity theft most likely, and the consequences arising from that.
- kube-system 6y agoWhat is the monetary amount, and do you have evidence of the theft?
- bogwog 6y agoI'm speaking hypothetically of course, I haven't actually been affected by this leak (so far). But that doesn't seem hard to prove at all. At the very least, you could claim that Facebook's leak forced you to pay for identity theft protection/monitoring as a very reasonable precaution, and whatever that cost you would be the damages. Then of course there's the possibility that someone did actually steal your identity and used it to drain money from your accounts, or simply caused you to waste a bunch of time hunting down for example fake accounts opened using your information, credit cards, etc. And I'm not a lawyer, but I'm pretty sure somewhere in all this fuckupery you can throw in some punitive damages.
- astura 6y agoWhat? How you gonna steal someone's identity just by knowing their phone number? You know that's something that hundreds of people and organizations already know?
- nixass 6y agoIs it just me or... why do people even share their phone number with Facebook? What did you use it for? It wasn't mandatory or anything. Why the Pikachu faces?
- fishbacon 6y agoIt is very convenient for your friends/family to be able to get your phone number from your facebook profile. I have used it a few times to contact people for whom immediate contact was preferable to facebook post/message.
- inetknght 6y agoYour comment is disingenuous. Facebook has been around for nearly two decades. There's plenty of time there for people to make mistakes and try to fix them. Unfortunately they're competing with their contacts who re-add those same mistakes and also competing with Facebook's own incentives to not delete data. It'll be fun if/when any of these numbers can prove they requested Facebook to delete their data under GDPR.
- javagram 6y agoI have my phone number and mailing address on my Facebook, set to friends only. Why not? When I grew up, we had a phone book listing everyone’s name and address and phone number so you could find them to contact. I consider all of this essentially public information and would rather make it easier for people I know to contact me. If it gets lost in a breach, whatever. I already get plenty of junk mail because I give to charities and they sell my address.
- rwmj 6y agoI believe their app uploads the address books of other people and those address books might contain your phone number and other details.
- astura 6y agoMy number is on my profile, so that my friends can contact me shall they lose my number. Less important now that messenger exists and we can access it any time, but I put it there before it existed. It's come in handy in the past. I also don't consider my phone number "sensitive" information I want to keep secret - it's already quasi-public and something I give out when I want people to be able to contact me. I grew up looking people up in the physical phone book when I lost their number, fwiw.
- aboringusername 6y agoNote to anyone that cares: Make your data as stale as possible: you can't change your address easily, sure. But you can recycle phone numbers (once a year, minimum). Change your credit/debit cards yearly (say to your bank you 'lost' it). When ordering online, always, always, always use a fake number, it's not required. Always use a fake name where possible. Sure, you need to provide that as a 'billing' address, but in some cases it stops other third parties getting that info (on eBay you can type a random name to ship to, I've had fun with this :) ). But lastly, LOL. Giving your data to facebook this is what you deserve, and for society accepting facebook as a standard part of life. When do we protest to delete the website?
- avh02 6y ago> When ordering online, always, always, always use a fake number, it's not required Until something's gone wrong in the process and they need to call you to clarify/fix it. (happens regularly to me due to address suffixes not propagating correctly through crappy systems)
- ricardobayes 6y agoThis is region dependent. In spanish speaking countries they pretty much never use email. Everyone - including the courier will just call you.
- shmoogy 6y ago> When ordering online, always, always, always use a fake number, it's not required Don't do this if you order anything that doesn't ship small parcel. The freight company may need to contact you and it will complicate matters and delay your final delivery.
- bshep 6y agoI do something similar when a site asks for my birthday, i used to pick a random date, but sonce its sometimes used to reset password or asks u to confirm i just use the first of january of the year i was born so i can make sure i remember what i put.
- deleted 6y ago[deleted]
- yosito 6y agoA note for people with US numbers who aren't finding their info: > And finally, one last note on the data load process: At the time of publishing this blog post, all phone numbers beginning with international codes 4, 6, 8 and 8 have completed loading. The other codes are in progress and may take several hours more before they're searchable. US numbers begin with international code 1, and it seems that they aren't yet searchable. I was surprised that mine hadn't come up, since I've had a few Facebook accounts over the years with my phone number, and this explains it.
- deleted 6y ago[deleted]
- nohuck13 6y agoThanks. For anybody getting a miss and wondering if they messed up the formatting, my US number is coming up now, formatted with a vanilla +1-123-456-7890.
- heleninboodler 6y agoMy US number also came up when entered as 12345678901 (1-prefixed but with no extra formatting or chars)
- Naracion 6y ago"When you search any of the endpoints on Have I Been Pwned, you can add a + prefix if you like and it'll be automatically stripped off when performing the search. Same with spaces and same with dashes."
- untouchable 6y agoAccording to the edit at the bottom of the post, "1" is now complete.
- yosito 6y agoInteresting. I've still got no hits, which surprises me.
- deleted 6y ago[deleted]
- VBprogrammer 6y agoI have noticed an uptick in the number of scam calls and texts I've been receiving over the last few days. No surprise that my number was included in this dataset.
- samerjj 6y agoAs a Syrian who have used many throw-away accounts on FB, this is a life or death matter for many of us. I'm sure the Syrian regime will use this information to track activists. I have checked and there are 7 million leaked accounts from Syria, probably covers everyone who uses Facebook in the country. Facebook made it mandatory to provide the phone number and now that this is leaked, they bear the moral responsibility for all the people who will be affected by this.
- BoDlulu 5y agoI'm really sorry for the situation you're in but, > they bear the moral responsibility for all the people who will be affected by this Facebook should not be held responsible for dictatorships and totalitarian regimes killing people - even if they use Facebook's leaked data to do so. It's quite unfortunate, but the responsible party to blame is still the people actually doing the killing.
- indigowind 6y agoWhat’s the legal recourse for users who have had their numbers leaked? Any group action possible? Could the US or EU fine them as well?
- cwhiz 6y agoGetting to the point where we’re going to need phone, email, and SMS to be deny all by default. Can’t reach me unless you’re information is already in my contacts.
- mcculley 6y agoI get a lot of value out of being reachable by people I do not yet know.
- gh123man 6y agoAs do I. This is a difficult problem to solve especially as the signal to noise becomes worse as abuse becomes more common. Ive had to wildcard block my area code (since I don't live there anymore) which captures 95% of my daily spam calls - but people can still leave a message to break through my wall if it's truly urgent. I don't see how this could work with SMS. Even message requests on facebook/messenger have problems where you are unlikely to even see the request unless you check regularly.
- cwhiz 6y agoNo one said it had to be by force.
- mcculley 6y agoMaybe I misunderstood your use of the "we" in "we're".
- sethammons 6y agoI found a novel solution by accident to this. I moved to a new area but kept my old number. 99% of my spam calls are from my phone’s area code. If you are not a contact and a number comes up from that area code, it is spam. If it is my new area code, it is a person or business trying to reach me. You could likely get a far off area coded number.
- derwiki 6y ago
- rwmj 6y agoI'm slightly surprised to find that my number has apparently not been pwned, given the huge uptick in spam calls that I've been receiving which seems to be coincident with the Facebook leak.
- breakingcups 6y agoNot all phone numbers have finished uploading, check the blog post for details.
- 2Gkashmiri 6y agosurprising that "Pakistan" isn't even on the list of countries. Anyone knows why?
- devgoldm 6y agoFound my number on there too even though I've deleted Facebook for at least 5 or 6 years now -_- Not sure when I gave them my number either, I hope it wasn't scraped from someone else's contact list... At least it makes sense why I received a bunch of spam calls over the weekend. Anyway it's probably good practice to recycle your number every few years, and not use it for 2FA to make switching numbers a lot easier. Who knows what services I'll be locked out of once I change, let's hope not too many.
- scrose 6y agoI can’t imagine telling everyone I know that I’m changing my number every couple years, and I’m not even calling/messaging a lot of people nowadays. I have a family member who did something similar(not on purpose) and I still have 3 of her numbers and still get confused which is the working one.
- devgoldm 6y agoI know exactly what you mean, there's only so many times you can append "New" on the end of a contact name! A good chunk of people will probably communicate mostly on platforms like WhatsApp/Telegram/Discord/whatever that don't need numbers at all or facilitate switching of numbers without your contacts having to do anything. I don't think that will constitute anywhere near the majority of people across the world though, switching numbers will definitely be a pain for most.
- 52-6F-62 6y agoI had a company phone about 6 or 7 years ago for a company I worked for at the time. When I was on my way out they unilaterally revoked my company-provided cellphone after convincing me I should get rid of my old private number for theirs. I'll never do that again. It happened shortly after ditching social media and I just about all of my contact info and I haven't been in touch with some old friends because of that since then. Even if you had the time to transfer your contacts, etc, something will inevitably get missed. Hell, I've updated family and friends to an email address I've been using for closer to a decade and they still email the old one...
- 6y ago
- rpaddock 6y agoAfter my wife's suicide (See the documentary Pain Warriors) I took over Karen's FB account as my own, and I changed the name on the account. Long before this breach I have been getting SMS Spam addressing me as Karen, on a number that did not exist when she was alive. FB data can be the only possible source of that spam. The spam is always trying to sell male enhancement products to 'Karen'. Anyone know how to stop this SMS spam crap?
- atlanta90210 6y agoVery sorry for your loss and thank you for sharing.
- ct0 6y agoMy phone has an option called Do Not Disturb mode. I have set a schedule to turn it on everyday from 12AM to 11:59PM. What Do Not Disturb will do is block (silence the notification or ringer) every message or call from someone that is not in your phone book. While unfortunately you'll still get the spam SMS, but you wont get the alert. The only way I can see striking back at these spam calls is to pick up the call and waste their time, because its expensive. Also if I pick up that means someone else is not getting scammed. I try to get as far along in the scam process as possible.
- GoblinSlayer 6y agoAt least here human operators apparently are paid for call duration and they will prolong the call up to 15 minutes and you don't need to say anything.
- officeplant 6y agoI enjoy the pixel line of phones having google assistant answer spam calls for me. Sometimes its fun to watch the conversation they attempt to have with the assistant.
- efreak 5y agoThis isn't just pixel phones anymore, and it hasn't been for a while. You can also tell that it's not a person sometimes (specifically extended car warranty for me) if you have a cheap phone like mine, because you can hear the message on the other end start as soon as the line opens, before the phone shuts off the speaker and starts playing it's own message; once the assistant finishes talking, you can see the transcript start in the middle because the other end doesn't recognize Google assistant like it (probably) would an answering machine.
- intrasight 6y agoHonest question: Why would you give your phone number to FB? Related to their app perhaps (which I don't have)?
- invalidusernam3 6y agoI haven't used facebook in years, but if I remember correctly it was part of your account verification in some cases.
- Black101 6y agoI don't know but I never gave my phone number to Facebook (but I also never used the app, only the website).
- newscracker 6y agoOver the years, many people who were stuck in the Facebook platform have been coerced by Facebook into providing a phone number to “verify” their account. The other choice given to them was (and is) to lose access to the account because Facebook believes it’s a fake account or a spam account or a “violation of its community policy”. In other cases, Facebook may get the phone number because someone uploaded their address book/contacts to it. This information shouldn’t be in the user’s public/private profile (even though Facebook would store it internally, use it to figure out other connections and “show relevant ads”).
- KMnO4 6y agoHm, I already know phone number is leaked, but searching for it (XXXxxxXXXX) doesn’t work. Once I prepended Canada’s country code: (1XXXxxxXXXX) it worked. Maybe this can be fixed with some simple communication? Ie “No result —- ensure you enter your full phone number including country code”
- ricardobayes 6y agohow do you know it was leaked? got spam?
- KMnO4 6y agoI downloaded the list.
- fatnoah 6y agoI guess the good news is that I still have identity monitoring from that time where the federal government gave up my information, including SSN, phone numbers, finger and toe prints, etc.
- sb636 6y agoI tried fully deleting my Facebook account multiple times about 5 years ago. Each time, it became clear that my information was never leaving. Friends were still able to pull up my account. My credentials were still being recognized and allowing me to login to an account I was told was now nonexistent. Now I see my phone number was part of the breach. I am so fed up with Facebook.
- notyourday 6y agoThis is very strange. I definitely have a phone number associated with a facebook account because at some point in the past I used FB 2FA. I have not deleted that number. I have tried it in several different formats, including + country code, leading country code, with and without dashes and I am getting "Good news" message.
- Madzen__ 6y agoConsidering Facebook has ~2.7 billion users and this breach only contains 533million there are many people not in it. Troy also mentioned not having processed all numbers yet aswell, but you could check the dump yourself. Downloading country spesific dumps does not take a long time.
- adler0901 6y agoI'm supposed to go to a random website and enter my phone number?
- luplex 6y agoIt's not at all a random website. haveibeenpwned is renowned. Your phone number is not uploaded to the server, instead your browser asks for a whole range of (hashed) phone numbers and checks locally if yours was one of them. The process is spelled out here: https://haveibeenpwned.com/Privacy https://haveibeenpwned.com/Privacy
- beervirus 6y agoHIBP is indeed probably just fine, but I'm not sure how the phone number searching works. "There's no k-anonymity implementation for phone numbers at this point in time." https://www.troyhunt.com/the-facebook-phone-numbers-are-now-searchable-in-have-i-been-pwned/ https://www.troyhunt.com/the-facebook-phone-numbers-are-now-...
- beervirus 6y ago> Facebook: In April 2021, a large data set of over 500 million Facebook users was made freely available for download. Encompassing approximately 20% of Facebook's subscribers, the data was allegedly obtained by exploiting a vulnerability Facebook advises they rectified in August 2019. The primary value of the data is the association of phone numbers to identities; whilst each record included phone, only 2.5 million contained an email address. Most records contained names and genders with many also including dates of birth, location, relationship status and employer. > Compromised data: Dates of birth, Email addresses, Employers, Genders, Geographic locations, Names, Phone numbers, Relationship statuses This is annoying, but I just can't get too worked up about it. I assume that anything I tell Facebook is already more or less public.
- floatingatoll 6y agoIf your phone number begins with 40% of the digits 0-9, then you’ll have a chance to find it on the site. Please review the footnote of the post, just above the comments, before assuming that your HIBP negative result is valid.
- adamrezich 6y agomy Facebook account got hacked/stolen a few months ago (didn't notice since I hardly ever use it), and Facebook won't give me back access to it even after providing photo ID etc., citing coronavirus-related labor shortages or some such bullshit. but hey, at least now HIBP has the hacker's phone number instead of any of mine!
- xibalba 6y agoI've been pwned. Is it known when this breach occurred? I have seen a huge spike in spam calls over the last 3-4 months and now I'm wondering if it was bc of this breach.
- MangoCoffee 6y agoi've stop using FB for 10 yrs now. i just check my number. not pwned.
- coatmatter 6y agoNon-technical speculation, but based on my own experience as an ordinary Facebook user: I'm increasingly confident that this breach/leak has come about mostly through the privacy search setting (buried in Facebook's privacy settings - https://www.facebook.com/settings?tab=privacy https://www.facebook.com/settings?tab=privacy -) which allows "Everyone" to search for a number in order to find your profile if so enabled. This is a bit like an option that PayID/Osko (instant bank transfers) in Australia allows - one could bash through random mobile numbers and discover more information than just the number. I've always found this option to be creepy because I don't people who might otherwise have my phone number legitimately to be able to facestalk me. Please note that this is separate to displaying contact info publicly on one's profile page - yes, there is a dizzying array of different privacy settings on Facebook. Would Mark Zuckerberg provide have ever displayed his phone number publicly? I doubt it. But would he have allowed others who already have his phone number to search for him on Facebook? I'd say almost certainly yes. I used to use Facebook more than I like to admit and I have provided my phone number to Facebook in the past, yet have managed to avoid being in this breach, whereas some people I know are in the data set. This means I'm quite sure that I'm not returning false negatives with the search.
- hendersoon 6y agoOnly ~32m of ~190m US FB accounts were in this breach, so it's not surprising if you live in that country and are not in the breach.
- coatmatter 6y agoThis statistic isn't applicable to me.
- ehsankia 6y agoLooking at the full breakdown [0], a bunch of middle eastern countries have near 100% breach. It seems like they were the target, and all the other countries were just collateral damage maybe? Canada, US, UK, all sitting around 10-20%. [0] https://datastudio.google.com/u/0/reporting/afa08373-621e-4e45-990e-bd631fd3b27a/page/Cn9AC https://datastudio.google.com/u/0/reporting/afa08373-621e-4e...
- uyt 6y agoThe previous thread had an amazing trick that worked for me: https://news.ycombinator.com/item?id=26682325 https://news.ycombinator.com/item?id=26682325 tl;dr; search your real phone number but exclude consecutive numbers to filter out auto-generated pages: "(212)555-1239" -1240 -1238 Using this I was able to find all my info (and much more) on sites like: https://www.fastpeoplesearch.com/ https://www.fastpeoplesearch.com/ I expect many of these "people search" sites to link to your fb profile soon using this breach. I expect the more sophisticated ones to crawl all your social media accounts (twitter, chat apps, etc) by abusing the reverse look up using your phone number.
- IG_Semmelweiss 6y agoCurious if anyone had success in avoiding this, by inserting a fake number in their FB profile.
- riscy 6y agoHas Facebook made any public comments about this breach yet?
- argv_empty 6y agohttps://about.fb.com/news/2018/04/restricting-data-access/ https://about.fb.com/news/2018/04/restricting-data-access/
- deleted 6y ago[deleted]
- tartoran 6y agoI searched the database and haven’t been pawned but of course I know why, I never shared my phone number with FB and this confirms my idea that sharing anything with FB is a terrible idea, even the real name with correct spelling can cause issues. I urge everyone who wants to still hold a social media account to add an alternative spelling for their name. When info leaks or one gets unsolicited messages of any kind out it becomes very easy to backtrack to which social media account the leak is coming from. Perhaps one more reason (from the many) to disable that account.
- Maxburn 6y agoThis is excellent advice. Years ago I had a misspelling of my name on my drivers license. Very easy to find the source of all my junk mail after that!
- fudged71 6y agoCool. Facebook leaked my Canadian phone number. As if I didn’t get enough spam calls already. Time to declare phone call bankruptcy?
- ada1981 6y agoI was pwned.
- Sommer 6y agoOne other attack vector with this data that I've not seen much chatter about is that the phone numbers (and other leaked data) are sufficient to create a Facebook Custom Audience and directly target the associated people with ads. Cross referencing these numbers (or pivot through names) with any external data source and you've got the capability to target specific voters, for example. Facebook made a lot of changes [eventually] to their Custom Audience abilities via user ID as a result of the Cambridge Analytica scandal, this leak makes it not too dissimilar in terms of how you could at least segment and direct target ads.
- harmeswoul12 6y agoThe data would have been either from abuse of API's by third party apps or find your friend. From the dataset, it seems to be exclusively limited to the data immediately viewable on your profile, hence the reason so few emails appeared in this leak.
- chrischen 6y agoI’m so confused. I intentionally refused to give my phone number to facebook and it is not set in my profile, yet my number was pwned in this facebook breach. Is FB associating or storing my number without permission? I have a different number set for 2-factor and amazingly it was not pwned!
- coatmatter 6y agoI think you may have allowed Facebook to allow other Facebook users to search for your profile via your number. Can you check my earlier comment at https://news.ycombinator.com/item?id=26712835 https://news.ycombinator.com/item?id=26712835 and let us know whether or not this is/was the case? > "Facebook Settings > Privacy > How people can find and contact you > Who can look you up using the phone number you provided?" Is/was it set to "Everyone"?
- chrischen 6y agoYes, but my number is not set to the one that was pwned!
- cjflog 6y agoI have been pwned. Also of note, while my phone number was on my Facebook account, it has had its visibility set to "only me" for years. Still leaked.
- weird-eye-issue 6y agoNot really surprising. That just sounds like a UI option. You realize they still have to store it right?
- vladmiller 6y agoI deleted my facebook account almost two years ago and my number still show up on the search... too bad GDPR does not spread on my country.
- jaypeg25 6y agoI permanently deleted my Facebook account September 2019. My phone number was included in this data breach, which was apparently August 2019. So close. If only I got rid of it sooner.
- langell_367 6y ago7742873234