Meta fined 91m euro over password breach

27 September 2024, 12:54

Meta logo on sign outside building
WhatsApp age limit change. Picture: PA

The issue applied to millions of Facebook and Instagram users.

Facebook parent company Meta has been fined 91 million euro by the Data Protection Commission.

It follows an investigation into Meta inadvertently storing certain user passwords in plaintext on its internal systems, meaning they were not protected by encryption.

The issue applied to millions of Facebook and Instagram users.

Meta Ireland notified the DPC of the breach in March 2019. The passwords were not made available to external parties.

The DPC found a range of infringements of GDPR rules including failing to notify the commissioner of the data breach, failing to document the data breach, not using appropriate security measures to protect the passwords, and not implementing appropriate organisational measures around the confidentiality of the passwords.

Deputy Commissioner Graham Doyle said: “It is widely accepted that user passwords should not be stored in plaintext, considering the risks of abuse that arise from persons accessing such data.

“It must be borne in mind that the passwords the subject of consideration in this case are particularly sensitive, as they would enable access to users’ social media accounts.”

By Press Association

More Technology News

See more More Technology News

Google screen

Google brings more AI to search engine in ‘significant’ update

UK Information Commissioner John Edwards

Accountability comes in many forms – Information Commissioner

The ChatGPT website

OpenAI raises ÂŁ5 billion in largest ever funding round

A woman using a laptop as she holds a bank card

Meta partners with UK banks to combat fraud

The word Google in white on dark glass at the company's offices

Google breached TV company trademark through YouTube Shorts service, court told

The Vodafone logo on a smartphone

Vodafone and Three UK promise ÂŁ10-a-month price cap for some mobile deals

An Asda store

Asda apologises after stores open later than planned due to till issue

The game developer has been fighting big tech firms for years over anti-competitive behaviour on their app stores (AP)

Epic Games sues Google and Samsung over anti-competition collusion claims

A woman using a mobile phone

Nearly a quarter of adults feel digitally excluded, survey finds

Minister for Justice Helen McEntee

Internet companies could face huge fines over content glorifying terrorism

GCHQ

UK issues alert over threat from cyber attackers working for Iranian state

An Amazon sign at the fulfillment centre in Hemel Hempstead, Hertfordshire

Competition regulator clears Amazon’s partnership with AI firm Anthropic

Revolut, Chase and Modulr have agreed to join the 159 short-code phone service that people can call to speak to their bank when they are worried about a potential scam (Yui Mok/PA)

Revolut, Chase and Modulr agree to join 159 anti-scam service

Network Rail ‘cyber security incident’

Man arrested after cyber vandalism hit wifi at UK’s biggest railway stations

Passengers waiting for trains at London King’s Cross Station

‘Cyber vandalism’ shuts down wifi at 19 Network Rail stations

Passengers milling about at London King's Cross

‘Cyber security incident’ hits wifi at Network Rail stations