On Saturday 3rd 2021, a leak of Facebook records (533 million users) became publicly accessible on a leak-market forum. The leak contains information such as mobile phone numbers, Facebook ID, first names, last names, location and additional information such as date of birth or work place. There are 188201 entries for Luxembourg. Facebook mentioned that the vulnerability used to extract the information was reported and fixed in 2019
Such leaks can be useful to many criminals or threat actors in order to conduct various attacks or fraud, such as phishing, vishing or social-engineering. Vishing is a technique using voice or SMS services to conduct phishing attacks. Phones are also used in various services for password recovery and this could be used to gather additional information from the existing data leak.
Read the full Technical Report TR-62 issued by CIRCL here.