533 million Facebook users’ data was leaked.
In April 2021, the personal data of 533 million Facebook users appeared on a hacking forum — for free. It was not a breach of Facebook’s servers. It was abuse of a feature, at scale, and that distinction is the whole lesson.
The dataset — phone numbers, Facebook IDs, names, locations and some email addresses across 106 countries — was assembled by abusing a contact-import feature. By feeding enormous lists of phone numbers to the tool that matched contacts to profiles, attackers harvested the profile data tied to each match. Facebook has said the underlying issue was addressed in 2019, but the data, once collected, could not be recalled, and it recirculated freely in 2021.
Scraping is a breach in everything but name
Because no server was “hacked,” this kind of event is easy to wave away — but the victims experience it as a breach. Phone numbers fuel SIM-swapping, smishing and credential-stuffing; combined with names and locations they make social engineering devastatingly effective. The damage does not depend on how the data left; it depends on the data being out.
The defense is rate, not just identity
Every individual lookup here was “authorized.” The attack lived in the aggregate: millions of legitimate-looking requests that, together, drained a dataset. That is why authentication alone does not stop it. The controls that do are about rate and behavior — per-identity throttling, anomaly detection on access patterns, and the ability to revoke an identity’s access the moment its behavior turns abusive, without shipping a release.
Where B5 stands
B5 Secure is built for exactly this seam. Authentication and data-element activity-data authorization decide who may touch what; the suspension stage adds the when-to-stop — instant revocation of a user, or of a single operation on a single entity, in response to a fraud or abuse signal. Posture is measured continuously and fed back into the decision, so an identity that starts behaving like a scraper loses access while it is still scraping, not after the data is already on a forum.
Authorized, at scale, is still an attack.
B5 Secure pairs data-element authorization with instant suspension, so abusive behavior is cut off the moment posture degrades — not after the export is complete.
Explore Never Trust →