Close Menu
Gossips Today
  • Tech & Innovation
  • Healthcare
  • Personal Finance
  • Lifestyle
  • Travel
  • Business
  • Recipes
What's Hot

Disney Has Asian American Culture Hidden in Plain Sight—How to Find the Best Eats, Experiences, and More

Rite Aid store closures update: Latest list includes doomed locations in California, Washington, and Oregon

Court denies Apple’s request to pause ruling on App Store payment fees

Facebook X (Twitter) Instagram
Friday, June 6
Gossips Today
Facebook X (Twitter) Instagram
  • Tech & Innovation

    Court denies Apple’s request to pause ruling on App Store payment fees

    June 6, 2025

    Cursor’s Anysphere nabs $9.9B valuation, soars past $500M ARR

    June 6, 2025

    Toma’s AI voice agents have taken off at car dealerships – and attracted funding from a16z

    June 5, 2025

    iOS 19: All the rumored changes Apple could be bringing to its new operating system

    June 5, 2025

    Bolttech closes Series C at $147M with a $2.1B valuation to bolster its embedded insurance offerings

    June 4, 2025
  • Healthcare

    Healthcare organizations could be unprepared to adopt generative AI: survey

    June 6, 2025

    Nearly 11M would become uninsured under GOP reconciliation bill: CBO

    June 6, 2025

    Amazon Pharmacy’s PillPack expands to Medicare patients

    June 5, 2025

    Appeals court to rehear No Surprises case in bright spot for providers

    June 5, 2025

    Trump administration names national coordinator for health IT

    June 4, 2025
  • Personal Finance

    16 Budgeting Tips to Manage Your Money Better

    May 28, 2025

    How to Stick to a Budget

    May 20, 2025

    4 Steps to Navigate Marriage and Debt

    May 11, 2025

    Buying a Fixer-Upper Home: What to Know

    May 10, 2025

    How to Talk to Your Spouse About Money

    May 10, 2025
  • Lifestyle

    16 Father’s Day Gift Ideas He (or You) Will Love

    June 4, 2025

    The Getup: Sand

    May 25, 2025

    Your Summer Style Starts Here: 17 Memorial Day Sale Picks to Grab Now + 4 Getups

    May 24, 2025

    3 Fixes If You Hate the Way Your Pants Fit (That Have Nothing to Do with Your Waist Size)

    May 14, 2025

    On Sale Now: 9 Nike Sneakers Under $100 You’ll Want to Wear All Summer

    May 10, 2025
  • Travel

    Disney Has Asian American Culture Hidden in Plain Sight—How to Find the Best Eats, Experiences, and More

    June 6, 2025

    Birkenstock Sandals and Comfy Clarks Shoes Are Up to 74% Off in This Secret Summer Sale

    June 6, 2025

    This Small Town in Virginia Is a U.S. Dupe for the English Countryside—Here's How to Visit

    June 5, 2025

    Yes, You Can Buy a Golf Cart at Amazon—and We Found an Electric, 4-seat Option for $8K

    June 5, 2025

    This Airline Route to Europe Was Just Revived After a 16-year Pause—and I Snagged a Seat On the First Flight

    June 4, 2025
  • Business

    Rite Aid store closures update: Latest list includes doomed locations in California, Washington, and Oregon

    June 6, 2025

    We can reshore American manufacturing

    June 6, 2025

    How AI is reshaping the fields of African farmers

    June 5, 2025

    AI isn’t coming for your job—it’s coming for your company

    June 5, 2025

    What to know about the CBO—the office calling out Trump’s tax bill

    June 4, 2025
  • Recipes

    slushy paper plane

    June 6, 2025

    one-pan ditalini and peas

    May 29, 2025

    eggs florentine

    May 20, 2025

    challah french toast

    May 6, 2025

    charred salt and vinegar cabbage

    April 25, 2025
Gossips Today
  • Tech & Innovation
  • Healthcare
  • Personal Finance
  • Lifestyle
  • Travel
  • Business
  • Recipes
Technology & Innovation

Meta fined $263M over 2018 security breach that affected ~3M EU users

gossipstodayBy gossipstodayDecember 17, 2024No Comments5 Mins Read
Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
Meta Fined $263m Over 2018 Security Breach That Affected ~3m
Share
Facebook Twitter LinkedIn Pinterest Email

Meta has been fined €251 million (around $263 million) in the European Union for a Facebook security breach that affected millions of users which the company disclosed back in September 2018.

The penalty, issued on Tuesday by Ireland’s Data Protection Commission (DPC) — enforcing the bloc’s General Data Protection Regulation (GDPR) — is far from being the largest GDPR fine Meta has been hit with since the regime came into force over five years ago but is notable for being a substantial sanction for a single security incident.

The breach it relates to dates back to July 2017 when Facebook, as the company was still known then, rolled out a video upload function that included a “View as” feature which let the user see their own Facebook page as it would be seen by another user. 

A bug in the design allowed users making use of the feature to invoke the video uploader in conjunction with Facebook’s ‘Happy Birthday Composer’ facility to generate a fully permissioned user token that gave them full access to the Facebook profile of that other user. They could then use the token to exploit the same combination of features on other accounts — gaining unauthorized access to multiple users’ profiles and data, per the DPC.

Between September 14 and September 28, 2018, the watchdog said unauthorised persons used scripts to exploit this Facebook vulnerability and gained the ability to log on as the account holder to approximately 29 million Facebook accounts globally — around 3 million of which were based in the EU/European Economic Area, meaning they fall under the DPC’s enforcement powers.

Categories of personal data impacted by the breach included Facebook users’ full names; email addresses; phone numbers; location; places of work; dates of birth; religion; gender; posts on timelines; groups of which they were a member; and children’s personal data.

The broad sweep of impacted personal data is likely to have influenced the size of the fine.

Two enforcement decisions

On Tuesday the Irish regulator issued final decision on two inquiries it opened into the 2018 incident: one decision covers Meta’s breach notification, as the GDPR requires prompt and comprehensive reporting of major security incidents — the second concerns the rules on data protection by design and default.

In both cases the DPC found Meta infringed the bloc’s GDPR.

The full sanction breaks down as follows: Meta has been fined €11 million in relation to its first decision, with the DPC finding that Meta’s breach notification did not include all the information it “could and should have”; nor did the company fully document the facts of the breach and the steps taken to remedy the issue.

On top of that, Meta has been fined €240 million in relation to the second decision where the DPC confirmed the company violated GDPR principles of data protection by design as it did not have appropriate measures in place to protect people’s data from unintended processing.

Commenting in a statement, DPC deputy commissioner Graham Doyle said: “This enforcement action highlights how the failure to build in data protection requirements throughout the design and development cycle can expose individuals to very serious risks and harms, including a risk to the fundamental rights and freedoms of individuals.

“Facebook profiles can, and often do, contain information about matters such as religious or political beliefs, sexual life or orientation, and similar matters that a user may wish to disclose only in particular circumstances. By allowing unauthorised exposure of profile information, the vulnerabilities behind this breach caused a grave risk of misuse of these types of data.”

Another notable element of the enforcement under the DPC’s two commissioners, Dr. Des Hogan and Dale Sunderland — who took over from (formerly the sole) commissioner Helen Dixon earlier this year — is that no objections were raised to Ireland’s draft decision by peer authorities.

“The DPC is grateful for the cooperation and assistance of its peer EU/EEA supervisory authorities in this case,” the regulator wrote in a press release.

Critics of the DPC under Dixon accused the regulator of routinely under-enforcing the GDPR on Meta and other tech giants. And many of its draft decisions on Big Tech at that time were disputed by its peers. A number of enforcements against Meta specifically entailed very lengthy dispute proceedings — with some requiring binding decisions from the European Data Protection Board to conclude the process.

So it’s notably that this latest enforcement against Meta, which the DPC says was submitted as a draft decision to the GDPR cooperation mechanism in July 2024, pass through unscathed.

Reached for a response to the penalty, Meta spokeswoman Emily Westcott emailed a statement in which the company wrote: “This decision relates to an incident from 2018. We took immediate action to fix the problem as soon as it was identified, and we proactively informed people impacted as well as the Irish Data Protection Commission. We have a wide range of industry-leading measures in place to protect people across our platforms.” 

Back in September, the DPC issued another decision against Meta vis-a-vis a 2019 security breach — in that instance the company was fined €91 million in relation to an incident in which “hundreds of millions” of users’ passwords had been stored in plaintext on its servers. 

The 10 largest GDPR fines on Big Tech

263M affected Breach fined Meta Security users
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleEmployers can help reduce parental burnout with virtual care, new study finds
Next Article VW and unions may reach a deal soon or they’ll adjourn until next year
admin
gossipstoday
  • Website

Related Posts

Court denies Apple’s request to pause ruling on App Store payment fees

June 6, 2025

Cursor’s Anysphere nabs $9.9B valuation, soars past $500M ARR

June 6, 2025

Toma’s AI voice agents have taken off at car dealerships – and attracted funding from a16z

June 5, 2025
Leave A Reply Cancel Reply

Demo
Trending Now

Disney Has Asian American Culture Hidden in Plain Sight—How to Find the Best Eats, Experiences, and More

Rite Aid store closures update: Latest list includes doomed locations in California, Washington, and Oregon

Court denies Apple’s request to pause ruling on App Store payment fees

Healthcare organizations could be unprepared to adopt generative AI: survey

Latest Posts

Disney Has Asian American Culture Hidden in Plain Sight—How to Find the Best Eats, Experiences, and More

June 6, 2025

Rite Aid store closures update: Latest list includes doomed locations in California, Washington, and Oregon

June 6, 2025

Court denies Apple’s request to pause ruling on App Store payment fees

June 6, 2025

Subscribe to News

Subscribe to our newsletter and stay updated with the latest news and exclusive offers.

Advertisement
Demo
Black And Beige Minimalist Elegant Cosmetics Logo (4) (1)
Facebook X (Twitter) Pinterest Vimeo WhatsApp TikTok Instagram

Categories

  • Tech & Innovation
  • Health & Wellness
  • Personal Finance
  • Lifestyle & Productivity

Company

  • About Us
  • Contact Us
  • Advertise With Us

Services

  • Privacy Policy
  • Terms & Conditions
  • Disclaimer

Subscribe to Updates

© 2025 Gossips Today. All Right Reserved.

Type above and press Enter to search. Press Esc to cancel.