No no no. That's not the hack.
The real hack will be using Facebook to infect people with malware. Which will probably be staggeringly easy once they get inside.
It will be impossible to remove, it will hijack legitimate connections to non-FB accounts with injection attacks, it will expose all the credentials of all the users of all the services of these 1 billion people. The compromise of sites that rely on Facebook for authentication tokens will pale in comparison.
Attack vectors: app upgrades, browser exploits, e-mail/messenger/comment phishing, 3rd party comment section or ad-network injection, desktop integration, and of course, all the mobile networks that provide Facebook data access for free (which are largely non-smartphone and have rudimentary interfaces).
One billion people will be prompted in some way, or immediately exploited using 0-days, and I would wager around 20% of users would be infected within a few hours of actually starting the attack. That's 200 million infected devices (edit: users; number of devices may be many times more). Depending on the point of entry and the access gained (let's say 20 percent of the infections lead to compromise of the whole system), that's 40 million accounts compromised in a few hours.
Banks, email accounts (which lead to everything else), online shopping, e-wallets, etc all stolen. Then the data extortion packages will encrypt all the phones and wipe any usable data and demand payment or destruction of data. There'll be a very short timer, too, because the bank and other financial account session data may be reset quickly. There is a potential that markets could crash worldwide as financial balances get shifted around at the speed of the internet.
Screw the Facebook data. This is a compromise that organized crime and state actors would invest millions of dollars to set up. And it's a virtual certainty that it will happen one day.