Inside the Facebook Marketplace Breach: How a Contractor Leak Exposed 200,000 Users
HEROIC analysts found a significant data exposure tied to Facebook Marketplace that first appeared on a major hacking forum in February 2024. The data was allegedly taken from a Meta contractor in October 2023 and covered approximately 200,000 records. Among those, around 77,000 unique email addresses were identified, along with full names, phone numbers, Facebook profile IDs, geographic locations, and bcrypt password hashes. The source of this breach points to a potential insider threat or compromised third-party vendor access, raising serious concerns about how personal data moves through contractor networks.
Why a Meta Contractor Breach Is Especially Dangerous
When a breach originates from a contractor rather than directly from a company's systems, it means the data moved through at least one extra set of hands before being secured. Contractors who have legitamate access to user data can sometimes take copies of that data or have their own systems compromised. In this case, the combination of real names, phone numbers, and email addresses creates a highly usable package for phishing and social engineering. Attackers can send convincing messages that reference real Facebook account activity, tricking people into clicking malicious links or giving up login credentials.
What Was Exposed in the Facebook Marketplace Breach
- Email addresses (approximately 77,000 unique)
- First and last names
- Phone numbers
- Facebook profile IDs
- Geographic locations
- Password hashes (bcrypt)
Why This Breach Feeds Identity Theft and Account Takeover
Social media account credentials are among the most valuable assets on the dark web because people use them to log into other services through single sign-on. If any of the bcrypt password hashes in this dataset correspond to passwords that were weak or commonly used, they can be cracked and tested across other platforms. Phone numbers are now used as a primary form of two-factor authentication, so having a number linked to a name and email address allows attackers to attempt SIM-swapping, a technique where they convince a phone carrier to transfer your number to a device they control. Once they have your number, they can bypass many security checks. The combination of location data and personal identifiers also makes victims accessable to targeted physical threats in rare but serious cases.
How Contractor-Based Database Breaches Work
Large companies like Meta routinely share data with third-party contractors for tasks like moderation, analytics, and customer service. These contractors are supposed to follow strict data handling policies, but enforcement is difficult. A contractor breach can occur through a malicious insider who steals data, a phishing attack on the contractor's employees, or a misconfigured system that leaks data to unauthorized parties. In this Facebook Marketplace case, the records are beleived to have been taken by someone with legitamate contractor-level access before being posted on a hacking forum. This type of breach is particularly difficult to detect because the initial data access looks normal from a technical standpoint, and it only becomes visible when the data appears somewhere it should not be.
Check If Your Facebook Marketplace Data Was Exposed
If you have a Facebook account and have used Facebook Marketplace, your name, phone number, email address, and location may be part of this dataset. HEROIC's free breach scanner checks your email against more than 400 billion breach records, including data from incidents like this one. It is completely free, takes only seconds, and requires no account to use. Scan your email at HEROIC now and find out if your information is already circulating among threat actors on the dark web.
Breach Breakdown
60,933 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds