Have I Been Pwned Adds Search For Leaked Facebook Phone Numbers

Have I Been Pwned Adds Search For Leaked Facebook Phone Numbers

Facebook users can now use the Have I Been Pwned data breach notification site to check if their phone number was exposed in the social site’s recent data leak.

Last weekend, a threat actor released a data leak containing information for 533 million Facebook users. This information includes phone numbers and Facebook IDs for almost all exposed accounts and other optional information such as a member’s name, gender, relationship status, location, occupation, date of birth, and email address.

This data was initially collected in 2019 and sold privately at the time. Over time, the data was traded and sold between different threat actors for lower and lower prices until it was eventually released for free on the hacker forum this weekend.

Facebook data leak released on a hacking forum

When it was released, the data was added to the Have I Been Pwned data breach notification service so that users can look up whether their emails were in the Facebook data leak.

However, this leak’s main component is a Facebook user’s phone number, rather than an email address, and thus Have I Been Pwned could not accurately alert a user if they were exposed in the breach.

“There’s over 500M phone numbers but only a few million email addresses so >99% of people were getting a “miss” when they should have gotten a “hit”,” Have I Been Pwned creator Troy Hunt explained in a blog post.

To more accurately alert users, Hunt has updated Have I Been Pwned so that users can now search for their phone numbers on the site to determine if the leak exposed their Facebook info.

Also Read: 4 Best Practice On How To Use SkillsFuture Credit

When searching for phone numbers, users must include their country code as that is how the data leak stored the number.

For example, in the sample of exposed New York users below, the phone numbers start with the country code of 1, followed by the person’s full number.

Sample of leaked Facebook users from New York

For example, if you wanted to check if your phone number was part of the Facebook data leak, you would need to use a search in the format ‘19175555555.’ If you are in the UK, you would need to include your country code as well, so a searchable phone number format would be ‘+442071838750.’

Hunt states that the + symbol is optional and will be stripped when searching, as shown below.

Searching Have I Been Pwned with a phone number

With this new feature added, Have I Been Pwned has become a valuable tool for Facebook members to determine if the data leak exposed their data.

Unfortunately, when data leaks such as this one are released, it is common for other threat actors to use this information in their own attacks.

Also Read: 3 Reasons Why You Must Take A PDPA Singapore Course

If your data was exposed, you should be on the lookout for Facebook phishing emails or smishing (phishing texts) attacks that attempt to harvest more information from you.

Privacy Ninja

Recent Posts

Role of Enhanced Access Controls in Safeguarding Personal Data in Telecommunications

Role of Enhanced Access Controls in Safeguarding Personal Data in Telecommunications that every Organisation in…

1 week ago

Role of Effective Incident Response Procedures in Strengthening Data Security

Effective Incident Response Procedures in Strengthening Data Security that every Organisation in Singapore should know…

2 weeks ago

Strengthening Your Cyber Defenses: The Crucial Role of Regular Vulnerability Scanning

Crucial Role of Regular Vulnerability Scanning that every Organisation in Singapore should know. Strengthening Your…

2 weeks ago

Enhancing Data Security with Multi-Factor Authentication

Enhancing Data Security with Multi-Factor Authentication that every Organisation in Singapore should know. Enhancing Data…

3 weeks ago

A Strong Password Policy: Your Organization’s First Line of Defense Against Data Breaches

Strong Password Policy as a first line of defense against data breaches for Organisations in…

3 weeks ago

Enhancing Website Security: The Importance of Efficient Access Controls

Importance of Efficient Access Controls that every Organisation in Singapore should take note of. Enhancing…

4 weeks ago