The Facebook phone numbers are now searchable in Have I Been Pwned
troyhunt.com
troyhunt.com
> And finally, one last note on the data load process: At the time of publishing this blog post, all phone numbers beginning with international codes 4, 6, 8 and 8 have completed loading. The other codes are in progress and may take several hours more before they're searchable.
US numbers begin with international code 1, and it seems that they aren't yet searchable.
I was surprised that mine hadn't come up, since I've had a few Facebook accounts over the years with my phone number, and this explains it.
For anybody getting a miss and wondering if they messed up the formatting, my US number is coming up now, formatted with a vanilla +1-123-456-7890.
I think that's a better approach than suing them and getting the $10 from a class action.
I would not be surprised if FB kept that phone number with a "deleted" flag to this day though.
If I give someone's social security number to a company that doesn't mean they can publish it on the front page just because the person it belongs to didn't hand it over.
Another option would be that someone else has that number listed for their account. Has Facebook always required confirmation that a number is valid? I saw one my friends' numbers in the data except the account had a different name.
As I understand, deactivation is temporary, deletion erases all data.
But if people did delete their accounts and Facebook didn't erase the private data, aren't there consequences to this?
That's the problem, what we or regulators understand may well be very different to what actually happens
> aren't there consequences to this
A slap on the wrist at best, I'd bet my house on it
"What should I do if I think that my personal data protection rights haven’t been respected? "
https://ec.europa.eu/info/law/law-topic/data-protection/refo...
"European Data Protection Board Members"
I also wish we could do more to put pressure on Facebook and other bad players. Can’t help thinking this is viewed internally as just more work for the legal department followed by an X billion euro “cost of doing business” fine after so many years.
2. You don't negotiate with Facebook, you norify the regulators so they can asses another billion-euro fine.
Answer under the GDPR is probably: 0EUR.
It would be hard to argue that privacy is a human right and then limit the protections to citizens.
The former is for citizens, the latter for everyone.
In the US, privacy falls in something like the former: there are supposed to be legal safeguards to keep US citizens from being spied on, but eg the NSA wiretapping foreigners is fine and even encouraged.
That is my experience in a couple of other European countries as well. Of course, some rights are reserved to citizens: vote (although that is changing for local elections), things like service at embassies and consulates abroad, and some aspects of immigration.
But except for these narrow aspects, the law should be the same for everyone: we are not a caste system.
> But except for these narrow aspects, the law should be the same for everyone: we are not a caste system.
I agree that it should, but the biggest factor in most people's life is not silly things like voting, but the right to work.
Billions of people would like to live and work in the EU and the US, but are not allowed.
[0]. https://www.eff.org/deeplinks/2019/10/twitter-uninentionally...
Lots of likes, no RTs or posts though.
https://www.buzzfeednews.com/article/alexkantrowitz/how-saud...
Collecting this data is an accident (or murder?) waiting to happen.
Even more frustratingly, there is a form to appeal a ban. After filling out that form, I got a confirmation mail stating that Twitter will "respond as soon as possible", or in other words, never.
I do not understand why they bothered to implement all that hijinks to waste my time. Simply disallowing signups without phone number would have been much simpler and less dishonest.
Edit: this happens with Google and Yandex as well, requiring phone number to sign up (Yandex can unlock you if you contact support). Microsoft isn't as bad and can work with just a secondary email instead of a phone number. Also the whole country is banned from downloading the Lynx web browser at https://lynx.invisible-island.net/
Same thing happened to me last year in the US. The kicker was that they automatically opt you in to product update, daily digest, etc. emails. But those emails don't have a 1-click unsubscribe - the unsubscribe link takes you to your account settings, which you can't access when your account is disabled. So you can't unsubscribe from the emails or delete the account.
You can either add a phone number to stop the spam, or search around to find the page where you can submit a ticket (because there's not a support link on the disabled account page) and hope someone gets to it eventually. They never even replied to my ticket, they just silently unlocked the account after a week or two.
> At the time of publishing this blog post, all phone numbers beginning with international codes 4, 6, 8 and 8 have completed loading. The other codes are in progress and may take several hours more before they're searchable.
So I was like: what about another 8?
Edit: Actually, it is "4, 6, 7 and 8"! cf. https://twitter.com/troyhunt/status/1379377818618884098
Ive had to wildcard block my area code (since I don't live there anymore) which captures 95% of my daily spam calls - but people can still leave a message to break through my wall if it's truly urgent. I don't see how this could work with SMS.
Even message requests on facebook/messenger have problems where you are unlikely to even see the request unless you check regularly.
You could likely get a far off area coded number.
Email has decent spam filtering, and I think that kind of cat-mouse system will persist. That said, there's "room" for more whitelisting.
In principle, "pay me a small fee if you're not on my list, if I put you on my list now it's free" would work well (optionally refund someone who contacts you out of the blue that you approve of), but there's a lot of both engineering and social details between where we are now and such a system.
It doesn't take much cost friction to deter mass spamming. I don't think much problem would be left behind from the handful of overconfident spammers who think that they can bust the odds and it's worth 25 cents a message or something.
"Anyone not on your contact list will take $1 off your monthly bill for each phone call, SMS, or eMail they send to you (through our phone line & email servers)"
Artificially or intentionally aligning interests tends to be a "genie, make me a sandwich^" problem. There are lots of places where "reversing the charges," seems good in theory... but it never happens.
Anyway, linkedin have something like this. In practice, it feels like a better quality of spam, rather than a solution to spam.
^Poof. you are now a sandwich.
A few months ago some criminals social engineered themselves past my bank's security as well. The first I learned about this was a funny conversation (by phone!) from an actual Deutsche Bank employee asking me if I recently changed my address and phone number and whether I opened ten new accounts. "eh no?!..." Basically their fraud detection system kicked in before these people did any damage. I made a point of not doing anything else than confirming information they already knew (like my old address, email address) and asked for an on site meeting to discuss things in more detail. I realized instantly I had no way of verifying anything I was being told on the phone and might very well be talking to a scammer. As it turns out this was for real and the person actually managed to find my "old phone number" in some archive. Otherwise all my contact information had already been changed by the scammers. Thankfully I answered that call. Apparently, this happened to several people.
Basically, what happened was some persons just called the bank's help desk, asked them to reset my online banking access codes, and then somehow intercepted the pin codes (thanks Deutsche Post) before they reached me. The theory is that somehow the security of the distribution system was compromised. As far as I an tell, nobody broke into my building or mailbox. Then started they using them to change my address, etc. They got caught only when they created sub accounts and started transferring money.
The criminals that got into my account got too greedy. The bank's fraud detection system kicked in and rolled back the transactions. But at that point they had complete control over my account. Very scary. If they had been more subtle, they could have likely stolen quite a bit. So, also not criminal master minds probably.
There are a lot of these little edge-cases. Journalists, lawyers representing class action suits, government id expiring, and so on.
Just wait for the deepfaked voice call scammers. Their best bet is to work up the hierarchy; a tiny local police station knows how to get in touch with a bigger police station that can contact an embassy, etc.
> There are a lot of these little edge-cases. Journalists, lawyers representing class action suits, government id expiring, and so on.
All of these use-cases allow someone to spend the time to contact you via your preferred contact method, whatever that might be.
I've read that people not answering their phones is the number one reason that COVID contact tracing doesn't work.
But your comment makes me think that you've never had food delivered. Never used an Uber. Never owned a business. Never bought or sold real estate. Never rented a place to live. Never went to a restaurant with a wait list. Never done a lot of things that are perfectly ordinary, and require allowing people to contact you when they have questions.
For all those other things, though, I'm not sure why you need to answer unknown numbers. I've never owned my own business, but did manage a small business and we had dedicated business lines. No one needed to call my personal phone. For buying and selling real estate, there are agents that act as go-betweens and you can put their number on your contacts list. For renting, put the management company on your contacts list.
I've used dozens and dozens of delivery companies over the years, and the only delivery company I've found that doesn't have its people calling on phones is DoorDash, and even that uses SMS. Plus, most of the best places don't use services, they have their own people.
we had dedicated business lines
Doesn't help you when someone needs to contact you in an emergency, like the alarm company, or the landlord, or security, or the police, thousand other things.
For buying and selling real estate, there are agents that act as go-betweens and you can put their number on your contacts list.
Sounds good in theory, but doesn't work in practice. There can be dozens and dozens of people and companies involved in such a transaction, and you can't predict who they all are.
For renting, put the management company on your contacts list.
When the management company sends a vendor over to fix something, you don't know what number they'll call from.
To "never" get an unexpected, important call sounds like a side effect of a quiet life. I envy you.
I know that we deserve something better than what we have now. I know we shouldn't have to put up with spammers calling constantly, but we don't live in a perfect world yet. We live in a messy world where sometimes people need to make a phone call and hope their loved ones pick up. I can think of a plethora of possible technical solutions, but that's besides the point. We need phone numbers to work. Let's focus on solving that problem, not trying to imagine it doesn't exist.
I'm increasingly confident that this breach/leak has come about mostly through the privacy search setting (buried in Facebook's privacy settings - https://www.facebook.com/settings?tab=privacy -) which allows "Everyone" to search for a number in order to find your profile if so enabled.
This is a bit like an option that PayID/Osko (instant bank transfers) in Australia allows - one could bash through random mobile numbers and discover more information than just the number. I've always found this option to be creepy because I don't people who might otherwise have my phone number legitimately to be able to facestalk me.
Please note that this is separate to displaying contact info publicly on one's profile page - yes, there is a dizzying array of different privacy settings on Facebook. Would Mark Zuckerberg provide have ever displayed his phone number publicly? I doubt it. But would he have allowed others who already have his phone number to search for him on Facebook? I'd say almost certainly yes.
I used to use Facebook more than I like to admit and I have provided my phone number to Facebook in the past, yet have managed to avoid being in this breach, whereas some people I know are in the data set. This means I'm quite sure that I'm not returning false negatives with the search.
[0] https://datastudio.google.com/u/0/reporting/afa08373-621e-4e...
But I too noticed the breach rate in the Middle East seemed unusually high, except my initial assumption was that perhaps the way Facebook was introduced there led to different behaviours in how one finds each other on Facebook. Perhaps it could be even something as simple as small differences in translation that lead to different behaviours when it comes to setting up a Facebook account.
The reason this is my initial hunch (rather than any kind of targeted campaign) is because different parts of the world interact differently with different communications platforms. For example, iMessage is very popular in USA whereas other parts of the world favour WhatsApp, or Telegram, or WeChat, etc. Is there any one concrete reason why one population might choose one "less secure" app over another "more secure" chat app/social network? I'd say probably not and yet, we see large variations depending on which border surrounds a user.
So perhaps a similar 'benign' explanation could explain the high breach rate in certain countries. Perhaps phone numbers are treated differently there too? Other than that, I have no idea. Unfortunately, I know very little about the Middle East let alone the languages there, so this is mostly just a guess.
FB data can be the only possible source of that spam.
The spam is always trying to sell male enhancement products to 'Karen'. Anyone know how to stop this SMS spam crap?
The only way I can see striking back at these spam calls is to pick up the call and waste their time, because its expensive. Also if I pick up that means someone else is not getting scammed. I try to get as far along in the scam process as possible.
But I have a similar, but unrelated to FB, problem in that every month I get an offer to work as a nurse in Norway from different agencies. I figured they scraped some "find the number"-site here in Sweden long ago and since my mothers name was on my bill I guess my number somehow came up under her name.
It's been annoying for years but since my mother had a some (non-corona) medical problems last year it has been downright infuriating at times. Anyone know how to make it stop when there is a bunch of different agencies messaging you?
Right now my profile picture is a plastic duck, there are no photos and no information apart from my name and my throwaway-email adress (which I hope is hidden from the world via settings).
There is also a "privacy page" there where you can check what information they have saved about you and if you forgot to delete something. I would probably have done it this way first if I where to delete my FB-account but for now I need messenger.
If you are running firefox you should also install "facebook container" even if you don't have an account. :)
I think it's pretty hard to stop incoming spam when the number itself has been made public.
The only options I know would be: a. Play whack and mole, report the number to the authority in your country that handles this kind of spam activity. b. Use some kind of mobile application that filter out the spam SMS. This one is kinda hit and miss, since the number data is coming from community reports, so some spam might pass the filter. And there might be some false positives from the spam filter.
I also would like to hear if there's alternative solution for this problem, other than changing the phone number itself.
It's not perfect, but it has had an impact on the amount of spam I receive.
> they bear the moral responsibility for all the people who will be affected by this
Facebook should not be held responsible for dictatorships and totalitarian regimes killing people - even if they use Facebook's leaked data to do so. It's quite unfortunate, but the responsible party to blame is still the people actually doing the killing.
Anyway it's probably good practice to recycle your number every few years, and not use it for 2FA to make switching numbers a lot easier. Who knows what services I'll be locked out of once I change, let's hope not too many.
A good chunk of people will probably communicate mostly on platforms like WhatsApp/Telegram/Discord/whatever that don't need numbers at all or facilitate switching of numbers without your contacts having to do anything. I don't think that will constitute anywhere near the majority of people across the world though, switching numbers will definitely be a pain for most.
I'll never do that again. It happened shortly after ditching social media and I just about all of my contact info and I haven't been in touch with some old friends because of that since then.
Even if you had the time to transfer your contacts, etc, something will inevitably get missed.
Hell, I've updated family and friends to an email address I've been using for closer to a decade and they still email the old one...
Really?
Every phone number is already known to anyone who wants to get it.
Ironically Twilio of all places forced SMS 2FA on all accounts earlier this year.
As in, one day you could no longer log into your twilio account without giving them a phone number. You are locked out until you do.
Ironic in a few ways ...
First, twilio numbers are not mobile numbers - they are voip numbers - and cannot be used for most 2FA authentication services because they cannot receive messages from short codes. So it's ironic that twilio forces you to use a non-twilio number for their 2FA.
Second, many twilio use-cases (like mine) involve building a twilio infrastructure to replace my existing phones/numbers ... and now that is broken from the bottom up because I have to use a mobile phone with a fixed provider just to use twilio.
The bottom line is: none of this is for me or my safety and security. Twilio has a spam problem and that spam problem is very hard to solve. Forced pairings of physical phones and SIM cards is just a desperate way to throw sand in those gears to slow it down a little bit.
But that doesn't seem hard to prove at all. At the very least, you could claim that Facebook's leak forced you to pay for identity theft protection/monitoring as a very reasonable precaution, and whatever that cost you would be the damages.
Then of course there's the possibility that someone did actually steal your identity and used it to drain money from your accounts, or simply caused you to waste a bunch of time hunting down for example fake accounts opened using your information, credit cards, etc.
And I'm not a lawyer, but I'm pretty sure somewhere in all this fuckupery you can throw in some punitive damages.
I've gotten spam calls since the breach, sometimes in the middle of the night while trying to sleep. That's distress.
[1] https://ec.europa.eu/info/law/law-topic/data-protection/refo...
I wonder if the benefits of haveibeenpwned outweights this.
e: To be clear, the Ashley Madison, and Adult Friend Finder (both breaches) are denoted on the list as not being publicly searchable.
My phone number isn't in here anywhere, so lucky me, but it doesn't make a difference. The State of Texas finally forced me to get a Texas driver's license in order to continue being able to vote, and the State of Texas sells your address and phone number to marketers once they have it, so my number is trash now anyway. 99 out of 100 texts and calls are either politicians or people claiming to want to buy one of my houses. I basically no longer use a phone except when my dad calls.
I guess the plus side there is I'm somewhat immune from whatever location tracking can't be disabled since I don't even take my phone with me most of the time when I go anywhere, but that was an old habit from when I worked in a SCIF and couldn't bring a phone with me anyway.
Now I'm wondering how this actually plays with legislation such as CCPA or GDPR, as it is quite revealing even without the more delicate sites mentioned here.
Some of the leaks are from companies I don't even know, that work behind the scenes aggregating information. Particularly for those I'd like to see what was leaked. For the services I actually used directly I have a clearer idea.
Not it would not solve that since HIBP would have to store that data (which they currently don't) and thus might be subject to leaks themselves.
Now I see my phone number was part of the breach. I am so fed up with Facebook.
> Compromised data: Dates of birth, Email addresses, Employers, Genders, Geographic locations, Names, Phone numbers, Relationship statuses
This is annoying, but I just can't get too worked up about it. I assume that anything I tell Facebook is already more or less public.
Interestingly, several cellphone numbers I know to be present in one set of leak data which start with international code 4 are not detected by HaveIBeenPwned.
When ordering online, always, always, always use a fake number, it's not required. Always use a fake name where possible. Sure, you need to provide that as a 'billing' address, but in some cases it stops other third parties getting that info (on eBay you can type a random name to ship to, I've had fun with this :) ).
But lastly, LOL. Giving your data to facebook this is what you deserve, and for society accepting facebook as a standard part of life.
When do we protest to delete the website?
Until something's gone wrong in the process and they need to call you to clarify/fix it. (happens regularly to me due to address suffixes not propagating correctly through crappy systems)
Don't do this if you order anything that doesn't ship small parcel. The freight company may need to contact you and it will complicate matters and delay your final delivery.
Websites that use my real DOB are usually linked to my identity, so I’m much more concerned with protecting them from, eg social engineering attacks [0].
[0]: https://gizmodo.com/how-i-lost-my-50-000-twitter-username-15...
Huge shoutout to/for privacy.com. Been using for over a year now and it's been a fantastic service.
My wife's number isn't in there, either. I'm just really surprised, because I checked facebook the other day and it said I was searchable by email and phone number.
I even searched my email address, and a lot of other breaches show, but not Facebook.
I guess I got lucky?
Thanks!
Looks like its worked here.
When I make a Facebook account, usually for my living complex's community or a bunch of Gen-Xer's doing a burning man thing, I use a new email or new phone number for signup and one time passwords.
I don't let it get access to my contacts, assuming I inadvertently installed the Facebook app on a phone.
Doesn't look like they meaningfully go deeper than that.
I find the social graph to be very fungible, so if I really ever want to recreate it I can just add my phone number or give any app access to my contacts. This knowledge also lets me not be married to any of these services.
I'm very content downloading the account data and then deleting the account.
Obviously, the platform has radically changed since then, but they have gotten a lot of mileage out of the illusion that you could freely share what you wanted because the only people who were going to see it were people who already knew you anyway, which was at least somewhat true at first.
In fact Facebook used to show creepy suggestions when such cross-pollination of data occured, like “Click here to confirm that XXXXXX is your phone number!”, but they stopped doing that a few years ago.
> "Facebook Settings > Privacy > How people can find and contact you > Who can look you up using the phone number you provided?"
Is/was it set to "Everyone"?
Please review the footnote of the post, just above the comments, before assuming that your HIBP negative result is valid.
In other cases, Facebook may get the phone number because someone uploaded their address book/contacts to it. This information shouldn’t be in the user’s public/private profile (even though Facebook would store it internally, use it to figure out other connections and “show relevant ads”).
tl;dr; search your real phone number but exclude consecutive numbers to filter out auto-generated pages:
"(212)555-1239" -1240 -1238
Using this I was able to find all my info (and much more) on sites like: https://www.fastpeoplesearch.com/I expect many of these "people search" sites to link to your fb profile soon using this breach.
I expect the more sophisticated ones to crawl all your social media accounts (twitter, chat apps, etc) by abusing the reverse look up using your phone number.
The process is spelled out here: https://haveibeenpwned.com/Privacy
https://www.troyhunt.com/the-facebook-phone-numbers-are-now-...
It does show up for companies I've trusted more though - Dropbox, Linux Mint, XKCD (md5 really?), Forbes, etc.
Once I prepended Canada’s country code: (1XXXxxxXXXX) it worked.
Maybe this can be fixed with some simple communication? Ie “No result —- ensure you enter your full phone number including country code”
I have used it a few times to contact people for whom immediate contact was preferable to facebook post/message.
It'll be fun if/when any of these numbers can prove they requested Facebook to delete their data under GDPR.
Why not? When I grew up, we had a phone book listing everyone’s name and address and phone number so you could find them to contact.
I consider all of this essentially public information and would rather make it easier for people I know to contact me. If it gets lost in a breach, whatever. I already get plenty of junk mail because I give to charities and they sell my address.
I also don't consider my phone number "sensitive" information I want to keep secret - it's already quasi-public and something I give out when I want people to be able to contact me.
I grew up looking people up in the physical phone book when I lost their number, fwiw.
Turns out the phone number is the best unique identifier and is the perfect key for joining up lots of disparate sources of data. It's the kind of thing that you could either sell directly or use as an index to determine things like your estimated income.
It wouldn't surprise me if Facebook has had multiple technical methods for devising/stealing and disingenuous "protect your account" campaigns for willingly turning over users phone numbers.
The only information exposed to me is that the person with that number, has a FB profile. If I am to trust FB (which I don't - for nothing) is that FB has this person's number and lost it. I place no reliance to anything that FB states. For all I know that person is a WhatsApp user and the FB branch 'stole' the number and added that to their FB account (yes, I know this is not how data works, but this is how FB works).
(semi-rant follows - apologies)
There is a mention of 2FA/MFA in another comment. I wouldn't be surprised if FB already has a 'super profile', where all data by FB-WA-IG are merged. I believe that would be a nightmare to do, but hey, FB is good at nightmares.
Edit: I feel this is a semi "Ashley Madison" moment. People who have a 'secret' FB profile may get busted by their BFs/GFs.