Looking for a complete Meta data breaches list? This page answers common searches like "Meta hacked," "Meta breach history," and "list of Meta data breaches" with a verified timeline, record counts, root causes, and step-by-step guidance if you may have been affected.
Meta data breach history: Cambridge Analytica-era culture meets billion-row API leaks—Meta (Facebook) owns some of the largest verified breach counts ever filed. BreachHistory indexes 25 verified or attested incidents tied to Meta, spanning 2005–2026. This page is a complete, searchable timeline—not a single event—linking every catalog row with context on scale, root cause, and what users should do when a new Meta notice drops.
Why Meta stays on breach trackers
Global tech brands combine massive user bases, high-value intellectual property, and complex supply chains. Attackers target Meta for credentials, source code, CRM exports, and employee directories. When you read headlines about "Meta hacked," the incident may be a consumer PII leak, a developer artifact exposure, or a third-party SaaS tenant breach—each with different remediation steps.
Data breaches list — Meta
Below are the major incidents in our catalog, newest first. Record counts use company, regulator, or Have I Been Pwned attestation where available; actor-only marketing shows as "Unverified / not disclosed."
- 2026 — Meta / Instagram — AI support bot abused for high-profile account takeovers (June 2) (Unverified / not disclosed records)
- 2025 — Infostealer subset — 17M Facebook logins (17M+ records)
- 2025 — Infostealer credential dump — 16B+ (16B+ records)
- 2025 — Alleged API scraping — 1.2B records (1.2B+ records)
- 2024 — MOAB — 26B records aggregated (26B+ records)
- 2024 — A threat actor leaked 200,000 records on a hacker… (200K+ records)
- 2023 — $725M Cambridge Analytica settlement opens for applications (Unverified / not disclosed records)
- 2021 — 530M+ user records leaked via contact importer scraping (530M+ records)
- 2020 — Developers access inactive user data (90-day policy bug) (Unverified / not disclosed records)
- 2019 — 267M–309M Facebook accounts on dark web (309M+ records)
- 2019 — 419M user records on exposed server (419M+ records)
- 2019 — FTC $5B penalty and new privacy restrictions (Unverified / not disclosed records)
- 2019 — April 2019 user data exposed on public servers (533M+ records)
- 2019 — 1.5M users' email contacts uploaded without permission (1.5M+ records)
- 2019 — Up to 600M passwords stored in plaintext (600M+ records)
Biggest and most consequential incidents
2024 MOAB — 26B records aggregated
The Mother of All Breaches (MOAB) consolidated decades of leaks into a 12TB database. Contains millions of Facebook credentials reused from older breaches or stolen via phish kits. Full incident record →
2025 Infostealer credential dump — 16B+
Aggregation of Stealer Logs published. Data stolen from users browsers (cookies/saved passwords) using Lumma/RedLine malware. Facebook logins were a primary target, enabling widespread session hijacking. Full incident record →
2025 Alleged API scraping — 1.2B records
A threat actor claimed to have bypassed modern Meta rate-limits to scrape 1.2 billion records. Meta contested the claim, but security firms confirmed much of the data was fresh (not in previous 2021 leaks). Full incident record →
Up to 600M passwords stored in plaintext
Up to 600M user passwords stored in plaintext, some since 2012; ~2k employees could view. Instagram passwords also stored in plaintext. Full incident record →
By the numbers (catalog snapshot)
- 25 incidents indexed under Meta on BreachHistory
- 46B+ combined attested records across rows with disclosed numerators (many incidents overlap or count emails—not unique people)
- 2024 — year of the largest attested row in our catalog
Patterns in Meta's breach history
- Credential and session theft — Phishing, stuffing, and OAuth token abuse recur across tech platforms.
- Cloud misconfiguration — S3 buckets, misconfigured APIs, and file shares expose data without a traditional "hack."
- Extortion without precise counts — Ransomware and leak-site actors often publish before victims confirm scope.
- Supply-chain spillover — npm, SDK, and CRM tenant breaches affect Meta customers even when corporate HQ databases stay intact.
What to do if you used Meta
- Enable multi-factor authentication on every Meta account and linked SSO identity.
- Check Have I Been Pwned when new Meta headlines appear.
- Rotate passwords that were reused on email, banking, or work SSO.
- Watch for phishing that cites real breach details (order numbers, usernames) to appear legitimate.
- Follow official Meta security communications—not SMS links from unknown numbers.
Related searches
- Meta data breach list
- Has Meta been hacked?
- Meta hack history
- Meta data leak timeline
- How many times has Meta been breached?
- Meta breach records on BreachHistory
FAQ
How many data breaches has Meta had?
BreachHistory indexes 25 verified or attested Meta data breaches spanning 2005–2026. Counts vary when researchers merge scraping, misconfiguration, and ransomware as separate events.
What is the biggest Meta data breach?
The largest attested incident in our catalog is 26B+ records (MOAB — 26B records aggregated). See the full timeline for sources and remediation details.
Has Meta been hacked?
Yes — Meta appears on breach trackers with 25 indexed incidents including MOAB — 26B records aggregated. This page links every catalog row with primary sources and what users should do if affected.
Does Meta send data breach notifications?
Regulated markets require consumer notices for many PII events. Not every source-code or scraping story triggers email alerts—read each incident row for notification status.
Explore every Meta incident on BreachHistory
Browse the full catalog: Meta breach records
Compiled from BreachHistory data/breaches.json and primary sources linked on each incident page. Updated 2026-06-15.