Meta hit with $263m fine over 2018 Facebook data breach

GDPR
Image Credit: Pixabay (Image credit: Pixabay)

  • Meta has been hit with a €251 million GDPR fine
  • Punshment follows Facebook data breach incident in 2018
  • Ireland's Data Protection Commission is yet to collect many of the fines

Meta has received yet another GDPR fine, with the parent company of Facebook, Instagram and WhatsApp facing a €251 million (around $263 million) hit following a 2018 data breach which exposed around 29 million Facebook accounts globally, 3 million of which were EU-based users.

Ireland’s Data Protection Commission (DPC) has been one of Europe’s leading regulatory bodies when it comes to holding tech firms to account, handing out huge penalties for GDPR violations, including the largest ever GDPR fine, a $1.3 billion charge, also against Meta, for data handling.

The most recent violations refer to the attack in which malicious actors used the ‘view as’ feature, which ordinarily allows users to see what their account looks like to their friends and family, to steal access tokens in order to take over the users account.

Millions of users affected

Of the users whose tokens were stolen, 15 million had their phone numbers and email addresses exposed, and a further 14 million also had their usernames, gender, relationship status, and location check-ins accessed. One million lucky users targeted had no data stolen.

Following the breach, the DPC found Facebook infringed GDPR by not including enough information in its breach notification, failing to properly document the facts of the incident. The DPC also found the company failed to ensure the data protection principles were protected, and that Facebook had failed in its ‘obligation as controllers’ to ensure that only necessary personal data is processed.

“This enforcement action highlights how the failure to build in data protection requirements throughout the design and development cycle can expose individuals to very serious risks and harms, including a risk to the fundamental rights and freedoms of individuals,” said DPC Commissioner Graham Doyle.

This may seem like a hefty fine, and it is, but the reality of these GDPR fines is not quite what it seems. So far, only 1% of these DPC fines have been collected, so there's a chance this fine could also get tied up in the appeals process indefinitely.

You might also like

Ellen Jennings-Trace
Staff Writer

Ellen has been writing for almost four years, with a focus on post-COVID policy whilst studying for BA Politics and International Relations at the University of Cardiff, followed by an MA in Political Communication. Before joining TechRadar Pro as a Junior Writer, she worked for Future Publishing’s MVC content team, working with merchants and retailers to upload content.

Read more
European Union
European Commission hit by EU court fine after breaking own data privacy rules
Europe
Apple and Meta set to face fines for alleged breaches of EU DMA
European Union technical background
Trump blasts EU regulators for targeting Meta, Apple and other US tech giants
Zuckerberg Meta AI
Zuckerberg asks Trump to stop US companies from having to pay EU fines
 In this photo illustration, the big tech companies Google, Apple, Meta, Amazon, Microsoft logos seen displayed on a mobile phone screen.
Big tech needs less than three weeks to pay off over $8 billion in 2024 fines
In this photo illustration, the Meta Platforms, Inc. logo is displayed on a smartphone screen.
Meta says it has fired several employees for leaking internal data
Latest in Pro
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
An AI face in profile against a digital background.
Smarter, faster, better: how AI is elevating the customer experience industry
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
Latest in News
Zotac Gaming RTX 5090 Graphics Card
Nvidia Blackwell stock woes are compounded by price hikes as more RTX 5090 GPUs soar in pricing, and I’m sick and tired of it all at this point
A collage of Elizabeth Olsen's Scarlet Witch and Tatiana Maslany's She-Hulk
Marvel fans are already tired of Doomsday and Secret Wars cast gossip as two more superheroes get linked with roles in the next two Avengers movies
Four operators survey Verdansk. One holds a sniper rifle, one binoculars, another holds is landing with their parachute, while the last wears a skull mask
New Call of Duty: Warzone trailer shows a beautiful rebuilt Verdansk, but some fans want more: 'it won't be the same unfortunately'
An Apple Music pink/pixellated poster advertising DJ with Apple Music
DJ with Apple Music lands, allowing subscribers to build and mix DJ sets directly from its +100 million-song catalog
The Meta Quest 3 and controllers on their charging station which is itself on a wooden desk next to a lamp
Forget Android XR, I've got my eyes on Vivo's new Meta Quest 3 competitor as it could be the most important VR headset of 2025
Samsung Galaxy S25 from the front
The Now Bar on Samsung One UI 7 is about to get a lot more useful – and could soon match Live Activities on iOS