Between MongoDB, Jenkins and Elasticsearch, thats a whole ecosystem of pwnability that is probably just starting to be exploited.
..including any private data they can gather on you, via search, maps, analytics, browser..
I wouldn't put it past Google to be already indexing exposed databases (or continue indexing ftp), just not making it publicly available.
The probability of your phone number not being uploaded to Facebook is basically 0.
Whether or not that information was part of this database isn't clear, but it also isn't something the parent comment claimed.
[0] https://slate.com/technology/2018/04/facebook-collects-data-...
> You are likely in this database if even a single one of your contacts uploaded their contacts to Facebook.
Shadow profiles are old news. The suspect claim is that the parent comment is more informed on this database than the source that published it.
> Whether or not that information was part of this database isn't clear
Yes it is. According to the source this particular public data dump consists only of entries with IDs linked a Facebook account.
> Each record contained a user’s unique Facebook ID and the phone number listed on the account. A user’s Facebook ID is typically a long, unique and public number associated with their account
For the parent comment saying they were in the data set: My initial interpretation was they meant if one Facebook user had done so, and you were also a Facebook user, whether or not you had provided your #, it was now associate with you. Your interpretation might be correct though.
As with anything like this, consult a lawyer who knows this area of the law of you find yourself in this situation.
If the vendor refuses to fix the issue, providing the media with enough redacted info to have them publish a story will force the vendors hand.