April 2019 user data exposed on public servers
Data compromised
Phone numbers, Personal identifiable information
Technical writeup
Facebook user data including phone numbers and other PII was found on public servers, likely scraped via a vulnerability that allowed enumeration of user IDs and associated data. The dataset was from before mid-2019 and included users from multiple countries.
Root cause
Scraping vulnerability allowing bulk collection of user data linked to phone numbers; data later exposed on public servers.