Meta Platforms—Facebook, Instagram, WhatsApp, Threads—stores identity graphs for billions of people. Few companies trigger more Facebook data breach searches. BreachHistory indexes 12 Meta-linked incidents, from 2013 accidental publications through 2026 employee surveillance exposure. This timeline separates confirmed breaches, scraping leaks, and policy failures.
Meta's unique breach dynamics
Meta incidents include classic access-token theft, mass scraping repackaged as breaches, misconfigured databases, and—in 2026—self-inflicted internal privacy disasters from AI productivity monitoring. Scale is measured in hundreds of millions of profiles.
Timeline through 2026
2026 — Employee MCI surveillance exposure
Meta confirmed it paused the Model Capability Initiative after an internal program meant to measure AI productivity instead stored sensitive data accessible to all staff. The June 2026 MCI incident exposed full AI prompts, tax information, medical data, and performance reviews—an insider privacy catastrophe without external hackers.
2026 — Instagram AI support abuse
Attackers abused Meta's AI-powered account recovery flows to hijack high-profile Instagram accounts on June 2, 2026—automation meant to help users became an takeover vector.
2024 — Threat actor leak claim
BreachHistory indexes a 2024 row citing 200,000 records on hacker forums—treat provenance carefully; Meta's public confirmation level varies by row.
2021 — 533 million scraped users
The 533 million user dataset (phone numbers, names, locations) circulated freely—Facebook said it was scraped via contact importer abuse before 2019 patches, but regulators disagreed on accountability.
2019 — The half-billion-profile year
Multiple catastrophic rows: 540 million records on exposed servers, 267 million, 41.9 million, and 1.5 million accidentally published. UpGuard found Facebook datasets on public AWS buckets—misconfiguration at social-graph scale.
2018 — Token hacks and Cambridge era fallout
Indexed rows include 50 million misconfiguration exposure, 29 million account hack, and 5 million hacking row—overlapping the period Facebook reset 90 million tokens after a View As feature vulnerability.
2013 — Early accidental publication
6 million users' data accidentally published—early signal of Meta's recurring theme: internal tools + data export = leak risk.
WhatsApp and Threads
Most indexed rows predate Meta renaming; WhatsApp end-to-end encryption limits server-side breach classes, but metadata, backups, and social graph on Facebook/Instagram remain high-value targets. Monitor Meta security advisories for cross-app token issues.
User protection guide
- Remove phone numbers from public Facebook profiles to reduce scraping value.
- Enable 2FA on Facebook and Instagram; use authenticator apps.
- Review logged-in devices monthly.
- Limit third-party Facebook apps (legacy contact importer lesson).
- High-profile accounts: disable automated recovery where Meta offers manual verification.
Regulatory context
Meta's breach history drove GDPR fines, FTC consent decrees, and EU DMA scrutiny. Even "scraping not hacking" arguments failed with regulators when personal data was publicly downloadable.
Full index: breachhistory.com/meta · 2026 MCI: Meta MCI employee exposure · Instagram: Instagram AI takeover 2026