back
173 comments
The creator of HaveIBeenPwned clarified on Twitter that there's no plans to add "search by phone number," so odds are that, if your data is in this leak, you won't see it through HaveIBeenPwned.

>500m Facebook records were leaked and <10m records have an email address — far more records are phone number but no email.

[1] https://twitter.com/troyhunt/status/1378463581604220931

I'm working on exactly that, using k-anonymity too. I expect to release my tool within 24h
I created https://www.thenewseachday.com/facebook-phone-numbers-us and https://www.thenewseachday.com/facebook-phone-numbers-austra... to check if phone numbers are in the data. (The data is split by country and I've made them for the US and Australia so far.)
Is there any (legal) way to see the leak? or at least to know if your data is among the leaked set?

No interest in seeing other people's info, but I want to know if I'm affected.

Looks like he's considering adding phone number search. There's a poll further down in the thread.
Indeed I found my name and phone number in the new Facebook leak, but my email address wasn't listed.

I would recommend people check for themselves.

Is there a problem with searching by email to confirm you're in the breach? It seemed to work for me.
How easy would it be to implement a new field? very.
Interestingly, Russia files are missing huge range of phone codes, from +7(910) to +7(929).

There are 3 top mobile operators in Russia: MTS, Beeline and Megaphone. Each of them has its own set of phone codes. Majority of MTS and better half of Megaphone numbers are not affected, but all Beeline codes are exposed.

Interesting agreed.

Have you checked the other entries to see if they are mis-categorized?

One thing that really keeps annoying me about HaveIBeenPwned is the fact that I can enter anyone's email and get their status immediately. This way I can anonymously check if that email had an account at a breached site at the time of the breach. The obvious solution would be sending out a link via email before results can be looked up, but this might not be in HaveIBeenPwned's interest.
This isn't universally true, the site does have a notion of "sensitive breaches" which will not be visible to someone who cannot confirm ownership of the email address.

https://haveibeenpwned.com/FAQs#SensitiveBreach

Some kind of "prove it's you" function would be great.

When you register for notifications it sends out a verification email. That would be a good time to let you disable public lookup of your email address.

I also wish HIBP could securely disclose the snippet of information from a leak that's relevant to you. Knowing the password or hash characteristics, phone number, etc. could aid in mitigation, and seeing the raw impact might help motivate ordinary users to improve their security hygiene.

Suggested that idea to Troy in the past, and got the impression he's not amenable, largely due to the risks of hosting PII. Can't really blame him.

It’s not HIBP that caused that data leak. The fact of which emails have accounts on which sites is public following the breach/leak of that site’s data.
On the other hand, that means I don't have to do an annoying verification dance to look up my pwnages, and can help others look up their breach information without having to explain to them over the phone how to click a link in an e-mail.
Yes then they could also show the actual data leaked. I'm supposedly in 11 breaches that include things like my date of birth and physical address. Maybe. But I don't really know.

Did I give a fake DOB. Is it a previous address? Do they actually even have an address or is it just NULL for me? HIBP won't tell me.

The point of hibp is this information is now public. Putting it behind some kind of identity check would be security by obscurity. The bad guys have the raw data and can look up any address at will.
But only due to HIBP integration in browser's password manager many come to know about their account leak even when the company which was breached didn't disclose it (as is the case in most countries).

There's still a need gap to detect leaked file data online, Say after a ransomware attack our files end-up in pastebin[1]; currently there seems to be no way to know unless manually monitoring sites where leaked data is posted or for the attacker to themselves let you know.

[1] Added in my profile.

It's possible to opt out. But that does require knowing HIBP exists.
The percentage of breaches in this database which is “Mongdo DB instance exposed to internet without a password”... yikes. Why on earth is no password the default?
It's even better, for years the default was no password /and/ binding on 0.0.0.0.
The popularity of MongoDB was a direct result of how simple it was to set up.
My tin-foil-hat wants to believe it has something to do with MongoDB’s CIA funding.

https://en.wikipedia.org/wiki/MongoDB_Inc.

PS Hello from the south island

I want the dump. I don't trust those pwn websites and I hold a multi gigabyte large breach dump myself for the last 15 years.

Dumps should be made public, like exploits.

found it a minute later on btdb. The data is really not interesting. It's like a 2021 version of a phonebook, that was common when I was younger. Where it becomes a slight bit dangerous, is that names and sometimes birthdates and emails are linked to it.

username and SHA/MD5 password dumps are more interesting to analyze though.

I also wanted the dumps but it seems only big players are allowed to "find" these dumps
Indeed, people assume haveibeenpwned is trustworthy when it seems to be a centralised place of valid emails from people that care about security and thus might have or control something of value?
It's hard to say definitively how old this data is due to this being a partial breach, but at one time I had two separate login email addresses for facebook.

Email address A was a gmail address and is a single dictionary word. I moved away from it as a login email due to the tendency of people to blindly spam it and it being used as a throwaway email address when people sign up for accounts. At this point I've had to purge a half dozen accounts people created on Facebook using my gmail address. The most recent one was created 4 months ago. Due to a rapid succession of logins (South Africa and United States) geometrically far apart, it was flagged and disabled.

I started using a different email address for my Facebook login a little less than 2 years ago. It is a custom domain name.

Neither showed up in the Have I Been Pwned lookup tool under this Facebook breech.

I just searched myself and found that my "Apollo" information was leaked in 2018. I don't know what "Apollo" is though and don't think they should have my details. Does anyone know details about that leak?
It was a company that scraped public LinkedIn profiles and then got their database popped.
In this leak every entry has a phone number and a name. But only a few have an email address connected.

So it would be nice to have a service where you put in a phone number and it will list what information is available for it. Like this:

  [X] Phone Number
  [X] Name 
  [X] Current location
  [ ] Previous location
  [ ] Current employer
  [ ] Email address
  [X] Birthday
  [ ] Full date of birth (with year)
I have a question: I was wondering if my old fb details might be part of this (I haven't had fb for about 4 to 5 years), so I searched for my email on hibp. No results for the fb leak, but hibp says my email is in the "Lead Hunter" leak from March 2020, and that "The data was provided to HIBP by dehashed.com.".

So I did the same search on dehashed.com, and got no hits (the part before "@" gets hits, but I don't care about that).

If the data comes from dehashed.com, why don't I find my email there?

I'm interested in knowing what, if anything other than my email is in there, because if anything significant is there, maybe I can figure out where the leak originated.

If it's just my email, I don't care at all.

That was quick! Hopefully he can put up the Ubiquity breach soon too
I don't believe that's been leaked. Ubiquiti is still claiming that they have no evidence that any data was stolen. While that seems improbable, and it seems that's just because they didn't have proper logging, it would be harder to maintain if the data was available.
“yesterday’s Facebook breach”? This data has been on sale for many months.
I wonder if this includes WhatsApp data and in what form. It would give me some extra ammo to get people to switch to Signal ;)
Not that I can tell

The cols (ive only loaded the US version) seem to be cell_phone | fb_id | first_name | last_name | gender | lives | from | releationship_status? | works_at | ?some year month maybe date sms was given | email | bday?

In the details it says there are only 2,529,621 compromised accounts added?
There were very few email addresses in the data, and that is what HaveIBeenPwned keys on.
Was there a new breach yesterday or is this the 2019 one?
If you click on the link you will see the description.

> Breach date: 1 August 2019

> Date added to HIBP: 4 April 2021

Tunisia population is 12 millions but there is 39 millions users in the breach. very strange!!
Not that strange at all. A lot of people all over the world have multiple email addresses. Myself for instance, I have an email address from my telecom provider, I have a Yahoo! email address from when I signed up years ago, my Google account has about two or three different ways of referring to the email address, plus I have my own domain; so I have about five different personal email addresses, plus my work email address.
From the leak, its only 6 million and there are many duplication accounts (you will see two entry for the same account if it have 2 phone number )
Given that this may include data about EU residents and the GDPR has strict rules about data breaches and may even impose fines in cases of negligence I wonder if anything will come from this.
Did they acted on this like GDPR requires them to? Who should be reporting it?
how can i access the entire DB?
How is it legal for HIBP to keep copies of breach corpuses on their servers? For me personally, having corpuses on my hard-drive is like dealing with radioactive waste. There's so much PII to mull over that it feels naughty to sift through. There's even people on social media bragging about 'self doxing' their own info (just like with using HIBP), but using a local copy instead.