Someone scraped some public profiles. Someone then brute forced a poorly implemented "look up by phone number" feature. They linked the two datasets on the unique facebook user id.
Leaking data that is or was in the public domain is not much of a leak. The only noteworthy thing would be the leak of the non-public phone number, however that vulnerability has been widely known since 2019 (and has been resolved by Facebook), so there's nothing new here?