EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/facebook-data-leak-2021
185/430

File EL-0246CriticalResolvedData Breach / API Vulnerability Exploitation

Facebook IDOR Phone Number Scrape

Also filed as Facebook Phone Number Leak · Facebook API Vulnerability Leak

This incident involved the unauthorized scraping of personal phone numbers from Facebook's public API, exploiting an Insecure Direct Object Reference (IDOR) vulnerability. The leak exposed the phone numbers of hundreds of millions of users globally. The vulnerability allowed attackers to bypass intended access controls, demonstrating a critical failure in Facebook's API security architecture.

  • #idor
  • #api-vulnerability
  • #data-leak
  • #phone-number
  • #meta
  • #privacy
Notoriety9/10
Event
3 Apr 2021
Disclosed
3 Apr 2021
Target
Facebook (Meta Platforms, Inc.)
Scale
533.0M people
Status
Resolved

01Summary

The vulnerability was discovered when researchers found that Facebook's API endpoints were insufficiently protected, allowing an attacker to query user data simply by manipulating the user ID parameter. This flaw, classified as an IDOR, meant that if an attacker knew or could guess a valid user ID, they could access associated data—specifically phone numbers—without needing proper authentication or authorization. The scraping operation was highly efficient, allowing the exfiltration of data belonging to an estimated 533 million users over a period of months. The leak highlighted systemic weaknesses in how major platforms manage and secure their public-facing APIs, leading to immediate and widespread privacy concerns.

02Background

The incident occurred within the context of increasing scrutiny on major technology platforms' data handling practices and API security. Prior to this, Facebook had faced multiple high-profile leaks, including the Cambridge Analytica scandal, which established a precedent for the value and vulnerability of user data. The general industry trend was moving toward stricter data governance, making this API flaw particularly damaging.

03Key revelations

  1. 01The vulnerability demonstrated a systemic failure in Facebook's API authorization layer.
  2. 02The sheer scale of the leak (533 million users) highlighted the global reach of the platform's data collection.
  3. 03The leak confirmed that phone numbers, considered highly sensitive PII, were accessible via a simple API query.

04Technical analysis

The core vulnerability was an IDOR flaw in the API endpoint responsible for retrieving user profile details. Instead of enforcing strict authorization checks (e.g., 'Is the requesting user the owner of this ID?'), the API merely checked for the existence of the ID. By iterating through sequential or predictable user IDs, an attacker could programmatically scrape the phone number associated with each account, bypassing the intended access controls.

Attack vector
API Endpoint Manipulation (IDOR)
Attack method
Automated Scraping / Enumeration
Initial access
Public API Endpoint
Lateral movement
Enumeration of User IDs
Exfiltration
Automated API Calls
Tool / malware
Custom Scraper Script
Malware type
Stealer

Vulnerabilities exploited

  • Insecure Direct Object Reference (IDOR)

MITRE ATT&CK techniques

  • T1083

05Threat actor

The perpetrators were not a known organized group, but rather individual hackers or automated scripts leveraging a systemic API flaw. This type of attack highlights the danger of poorly maintained, publicly exposed infrastructure rather than sophisticated zero-day exploits.

Aliases

  • API Exploiter

MITRE groups

  • T1046

Attribution sources

  • Security Researchers
  • Media Outlets

06Victims and impact

Countries affected

  • Global

07Data exposed

Data types

  • Phone Numbers
  • PII

Notable documents

  • API Request Logs (Hypothetical)
  • User Profile Data Dump

08Financial damage

Damage estimate is based on potential identity theft, marketing misuse, and regulatory fines.

09Timeline

  1. 2019-01-01Initial vulnerability exploitation begins (estimated)
  2. 2021-04-03Vulnerability publicly disclosed and patched

10Reaction and fallout

Public reaction

The public reaction was characterized by widespread alarm regarding the lack of control over personal data and the perceived negligence of major tech companies. Privacy advocates used the incident to push for stricter global data protection regulations.

Political impact

The leak intensified political debates surrounding data sovereignty and the necessity of comprehensive federal privacy legislation in the US. It contributed to a more skeptical public view of social media platforms' business models.

Geopolitical consequences

The incident reinforced the global trend of data localization and increased regulatory scrutiny from international bodies, particularly in the EU (GDPR).

11Legal

While no specific class-action lawsuit was immediately cited solely for this leak, it contributed to the overall legal pressure leading to increased regulatory fines and mandatory security audits for Meta.

Civil lawsuits

  • Class-action lawsuits related to data privacy violations (general trend)

12Aftermath

Policy changes

  • Increased industry focus on API authorization and IDOR prevention.

Regulatory changes

  • Reinforcement of GDPR principles regarding data minimization and purpose limitation.

Security improvements

  • Mandatory implementation of granular access controls (Role-Based Access Control) on all API endpoints.
  • Rate limiting and anomaly detection systems for API usage.

13Significance and legacy

Significance

This incident is a textbook example of how a seemingly minor API vulnerability (IDOR) can lead to catastrophic data exposure at massive scale. It underscored that the sheer volume of data collected by platforms creates an enormous, unmanageable security liability, regardless of the initial intent of data collection.

Legacy

The leak accelerated the industry shift toward 'Privacy by Design' principles. It forced major tech companies to overhaul their API security models, moving away from simple ID checks to complex, multi-layered authorization protocols.

14Disclosure and media

Authentication
Technical Proof of Concept (PoC)

Media partners

  • The Hacker News
  • Security Blogs

Publishing organisations

  • Security Researchers

15Related files

Related events

  • Cambridge Analytica Scandal
  • Facebook Pixel Data Leak

16Field notes

  1. 01The vulnerability was not a zero-day exploit, but rather a failure to implement basic authorization checks.
  2. 02The sheer number of records affected made it one of the largest single data leaks in social media history.

17Resolution

Facebook reportedly patched the specific API endpoint vulnerability, requiring developers to implement proper authorization checks for all data retrieval requests.

18Sources

Official documents

  • Meta Security Advisory (Hypothetical)

References

  1. [1]Security Research Reports (2021)
  2. [2]Tech News Outlets Coverage
Fact sheetEL-0246

Dates

Event
3 Apr 2021
Started
1 Jan 2019
Ended
3 Apr 2021
Duration
731 days
Discovered
3 Apr 2021
Disclosed
3 Apr 2021
Resolved
3 Apr 2021
Ongoing
No

Target

Organisation
Meta Platforms, Inc.
Type
Technology Company
Sector
Social Media
Country
United States

Actor

Type
Individual Hacker
Motivation
Financial gain, data aggregation, and sale of personal information.
Arrested
No
Convicted
No

Data

People
533,000,000
Records
533,000,000
Volume
533 million records (phone numbers)
Sensitivity
Confidential
Published
Yes

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.