Meta hit with major fine over password storage

In this photo illustration, the Meta Platforms, Inc. logo is displayed on a smartphone screen.
(Image credit: Photo Illustration by Rafael Henrique/SOPA Images/LightRocket via Getty Images)

Meta has been fined €91 million for incorrectly storing social media account passwords in unencrypted databases.

Meta notified the Irish Data Protection Commission it had unintentionally stored the passwords in plain text within its internal systems.

Not the first time

Storing passwords in plain text is frowned upon for obvious reasons, especially as it makes them vulnerable to attackers if a data breach occurs.

This isn’t the first time the company has been fined for violating GDPR. In January 2023, Meta was hit by a €390 million fine by the DPC for serving personalized ads without the option to opt-out and its data handling practices.

Then in May 2023, Meta was fined the highest possible GDPR fine of €1.2 billion for transferring data from the EU to the US outside of GDPR guidelines. EU data remains protected by GDPR even when moved outside of the EU.

Meta was also fined €265 million by the DPC in 2022 after data that had been scraped from Facebook was leaked on a hacking forum. The leak contained the data of 533 million people across 106 countries.

Speaking on Meta’s most recent fine, DPC deputy commissioner Graham Doyle said, “It is widely accepted that user passwords should not be stored in 'plaintext' considering the risks of abuse that arise from persons accessing such data.”

"It must be borne in mind, that the passwords the subject of consideration in this case are particularly sensitive, as they would enable access to users’ social media accounts,” Doyle concluded.

Via BBC

More from TechRadar Pro

Benedict Collins
Senior Writer, Security

Benedict has been with TechRadar Pro for over two years, and has specialized in writing about cybersecurity, threat intelligence, and B2B security solutions. His coverage explores the critical areas of national security, including state-sponsored threat actors, APT groups, critical infrastructure, and social engineering.

Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the Centre for Security and Intelligence Studies at the University of Buckingham, providing him with a strong academic foundation for his reporting on geopolitics, threat intelligence, and cyber-warfare.

Prior to his postgraduate studies, Benedict earned a BA in Politics with Journalism, providing him with the skills to translate complex political and security issues into comprehensible copy.