Close Menu
Gossips Today
  • Tech & Innovation
  • Healthcare
  • Personal Finance
  • Lifestyle
  • Travel
  • Business
  • Recipes
What's Hot

Groww, backed by Satya Nadella, set to become first Indian startup to go public after U.S.-to-India move

Doctors slam specialty cuts in 2026 Medicare pay proposal

Utah’s Largest Resort Just Opened in Greater Zion With 7 Bars and Restaurants—Here's a First Look Inside

Facebook X (Twitter) Instagram
Wednesday, September 17
Gossips Today
Facebook X (Twitter) Instagram
  • Tech & Innovation

    Groww, backed by Satya Nadella, set to become first Indian startup to go public after U.S.-to-India move

    September 17, 2025

    Rivian breaks ground on $5B Georgia factory ahead of construction in 2026

    September 16, 2025

    Nothing closes $200M Series C led by Tiger Global, plans AI-first device launch

    September 16, 2025

    Apple’s iOS 26 with the new Liquid Glass design is now available to everyone

    September 15, 2025

    Vibe coding has turned senior devs into ‘AI babysitters,’ but they say it’s worth it

    September 15, 2025
  • Healthcare

    Doctors slam specialty cuts in 2026 Medicare pay proposal

    September 17, 2025

    More than half of healthcare workers are considering taking new jobs next year: survey

    September 16, 2025

    The best AI models for behavioral health will ultimately be owned by health plans, not vendors

    September 16, 2025

    A key CDC panel meets this week to discuss vaccines. Here’s what to know.

    September 15, 2025

    Pacs Group CFO resigns amid allegations of improper conduct

    September 15, 2025
  • Personal Finance

    How to Stop Living Paycheck to Paycheck

    September 10, 2025

    Real Estate Report 2024 – Ramsey

    September 9, 2025

    How Much Car Can I Afford?

    September 9, 2025

    21 Cheap Beach Vacations for 2025

    August 5, 2025

    Car Depreciation: How Much Is Your Car Worth?

    August 4, 2025
  • Lifestyle

    Why Some Linen Sucks

    September 4, 2025

    We Dug Through the Labor Day Sales So You Don’t Have To

    September 3, 2025

    What Terms on Alcohol Labels Really Mean: The Words You Trust and the Tricks You Miss

    August 28, 2025

    18 Higher-Quality Sale Finds at Lower Prices from Todd Snyder, Madewell, and L.L. Bean

    August 24, 2025

    The Late Summer Weekend Uniform That Works Inside and Out

    August 22, 2025
  • Travel

    Utah’s Largest Resort Just Opened in Greater Zion With 7 Bars and Restaurants—Here's a First Look Inside

    September 17, 2025

    7 Charming U.S. Small Towns That Are Perfect for a Fall Getaway

    September 16, 2025

    This Luxe New Spa in Canada's Banff National Park Lets You Soak in Glacier-fed Waters With Views of Lake Louise

    September 16, 2025

    American Express Just Made It Easier to Plan and Book Trips With Its New Travel App

    September 15, 2025

    5 Best Hotel Stores in the World—With Perfect Gifts and Exclusive Merch

    September 15, 2025
  • Business

    Oracle, Andreessen Horowitz consortium will control 80% of TikTok in U.S.: Report

    September 17, 2025

    Markets rally as the Fed meets to decide on what could be 2025’s first interest rate cut

    September 16, 2025

    Corporate social impact is experiencing a market correction

    September 16, 2025

    The Federal Reserve faces these 3 unknowns ahead of its September meeting

    September 15, 2025

    How to watch the 2025 Emmy Awards live, including free options

    September 15, 2025
  • Recipes

    cabbage and halloumi skewers

    September 10, 2025

    double chocolate zucchini bread

    August 21, 2025

    grilled chicken salad with cilantro-lime dressing

    August 7, 2025

    chipwich ice cream cake

    July 26, 2025

    focaccia with zucchini and potatoes

    July 12, 2025
Gossips Today
  • Tech & Innovation
  • Healthcare
  • Personal Finance
  • Lifestyle
  • Travel
  • Business
  • Recipes
Technology & Innovation

Meta fined $263M over 2018 security breach that affected ~3M EU users

gossipstodayBy gossipstodayDecember 17, 2024No Comments5 Mins Read
Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
Meta Fined $263m Over 2018 Security Breach That Affected ~3m
Share
Facebook Twitter LinkedIn Pinterest Email

Meta has been fined €251 million (around $263 million) in the European Union for a Facebook security breach that affected millions of users which the company disclosed back in September 2018.

The penalty, issued on Tuesday by Ireland’s Data Protection Commission (DPC) — enforcing the bloc’s General Data Protection Regulation (GDPR) — is far from being the largest GDPR fine Meta has been hit with since the regime came into force over five years ago but is notable for being a substantial sanction for a single security incident.

The breach it relates to dates back to July 2017 when Facebook, as the company was still known then, rolled out a video upload function that included a “View as” feature which let the user see their own Facebook page as it would be seen by another user. 

A bug in the design allowed users making use of the feature to invoke the video uploader in conjunction with Facebook’s ‘Happy Birthday Composer’ facility to generate a fully permissioned user token that gave them full access to the Facebook profile of that other user. They could then use the token to exploit the same combination of features on other accounts — gaining unauthorized access to multiple users’ profiles and data, per the DPC.

Between September 14 and September 28, 2018, the watchdog said unauthorised persons used scripts to exploit this Facebook vulnerability and gained the ability to log on as the account holder to approximately 29 million Facebook accounts globally — around 3 million of which were based in the EU/European Economic Area, meaning they fall under the DPC’s enforcement powers.

Categories of personal data impacted by the breach included Facebook users’ full names; email addresses; phone numbers; location; places of work; dates of birth; religion; gender; posts on timelines; groups of which they were a member; and children’s personal data.

The broad sweep of impacted personal data is likely to have influenced the size of the fine.

Two enforcement decisions

On Tuesday the Irish regulator issued final decision on two inquiries it opened into the 2018 incident: one decision covers Meta’s breach notification, as the GDPR requires prompt and comprehensive reporting of major security incidents — the second concerns the rules on data protection by design and default.

In both cases the DPC found Meta infringed the bloc’s GDPR.

The full sanction breaks down as follows: Meta has been fined €11 million in relation to its first decision, with the DPC finding that Meta’s breach notification did not include all the information it “could and should have”; nor did the company fully document the facts of the breach and the steps taken to remedy the issue.

On top of that, Meta has been fined €240 million in relation to the second decision where the DPC confirmed the company violated GDPR principles of data protection by design as it did not have appropriate measures in place to protect people’s data from unintended processing.

Commenting in a statement, DPC deputy commissioner Graham Doyle said: “This enforcement action highlights how the failure to build in data protection requirements throughout the design and development cycle can expose individuals to very serious risks and harms, including a risk to the fundamental rights and freedoms of individuals.

“Facebook profiles can, and often do, contain information about matters such as religious or political beliefs, sexual life or orientation, and similar matters that a user may wish to disclose only in particular circumstances. By allowing unauthorised exposure of profile information, the vulnerabilities behind this breach caused a grave risk of misuse of these types of data.”

Another notable element of the enforcement under the DPC’s two commissioners, Dr. Des Hogan and Dale Sunderland — who took over from (formerly the sole) commissioner Helen Dixon earlier this year — is that no objections were raised to Ireland’s draft decision by peer authorities.

“The DPC is grateful for the cooperation and assistance of its peer EU/EEA supervisory authorities in this case,” the regulator wrote in a press release.

Critics of the DPC under Dixon accused the regulator of routinely under-enforcing the GDPR on Meta and other tech giants. And many of its draft decisions on Big Tech at that time were disputed by its peers. A number of enforcements against Meta specifically entailed very lengthy dispute proceedings — with some requiring binding decisions from the European Data Protection Board to conclude the process.

So it’s notably that this latest enforcement against Meta, which the DPC says was submitted as a draft decision to the GDPR cooperation mechanism in July 2024, pass through unscathed.

Reached for a response to the penalty, Meta spokeswoman Emily Westcott emailed a statement in which the company wrote: “This decision relates to an incident from 2018. We took immediate action to fix the problem as soon as it was identified, and we proactively informed people impacted as well as the Irish Data Protection Commission. We have a wide range of industry-leading measures in place to protect people across our platforms.” 

Back in September, the DPC issued another decision against Meta vis-a-vis a 2019 security breach — in that instance the company was fined €91 million in relation to an incident in which “hundreds of millions” of users’ passwords had been stored in plaintext on its servers. 

The 10 largest GDPR fines on Big Tech

263M affected Breach fined Meta Security users
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleEmployers can help reduce parental burnout with virtual care, new study finds
Next Article VW and unions may reach a deal soon or they’ll adjourn until next year
admin
gossipstoday
  • Website

Related Posts

Groww, backed by Satya Nadella, set to become first Indian startup to go public after U.S.-to-India move

September 17, 2025

Rivian breaks ground on $5B Georgia factory ahead of construction in 2026

September 16, 2025

Nothing closes $200M Series C led by Tiger Global, plans AI-first device launch

September 16, 2025
Leave A Reply Cancel Reply

Demo
Trending Now

Groww, backed by Satya Nadella, set to become first Indian startup to go public after U.S.-to-India move

Doctors slam specialty cuts in 2026 Medicare pay proposal

Utah’s Largest Resort Just Opened in Greater Zion With 7 Bars and Restaurants—Here's a First Look Inside

Oracle, Andreessen Horowitz consortium will control 80% of TikTok in U.S.: Report

Latest Posts

Groww, backed by Satya Nadella, set to become first Indian startup to go public after U.S.-to-India move

September 17, 2025

Doctors slam specialty cuts in 2026 Medicare pay proposal

September 17, 2025

Utah’s Largest Resort Just Opened in Greater Zion With 7 Bars and Restaurants—Here's a First Look Inside

September 17, 2025

Subscribe to News

Subscribe to our newsletter and stay updated with the latest news and exclusive offers.

Advertisement
Demo
Black And Beige Minimalist Elegant Cosmetics Logo (4) (1)
Facebook X (Twitter) Pinterest Vimeo WhatsApp TikTok Instagram

Categories

  • Tech & Innovation
  • Health & Wellness
  • Personal Finance
  • Lifestyle & Productivity

Company

  • About Us
  • Contact Us
  • Advertise With Us

Services

  • Privacy Policy
  • Terms & Conditions
  • Disclaimer

Subscribe to Updates

© 2025 Gossips Today. All Right Reserved.

Type above and press Enter to search. Press Esc to cancel.