The encyclopedia · Legal & Compliance · Legal decision · 2018–2024
Meta's 2018 breach exposed 29M accounts — a €251M fine six years later
Ireland's DPC fined Meta €251M for the 2018 breach in which attackers grabbed access tokens for ~29M accounts — six years after the fact.
Meta · 2024-12-17
What happened
On 17 December 2024 Ireland's Data Protection Commission, Meta's lead regulator in the EU, fined the company €251 million over the September 2018 breach that exposed the accounts of about 29 million users worldwide, including roughly 3 million in the EU and EEA.
Attackers exploited a flaw in Facebook's video upload function, gaining access tokens that let them log in as account holders. Over a two-week period in 2018 they reached personal data including email addresses, phone numbers, locations and places of work.
The DPC found multiple GDPR infringements: failures on breach notification and documentation, and failures to build data protection into the design and default settings of the service. The regulator said the flaws behind the breach posed a grave risk of misuse of the exposed data.
Meta remedied the breach shortly after it was discovered and reported it to the regulator in September 2018. The company said it would appeal the decision. The case had run since 2018, and the gap between breach and fine showed how slowly cross-border GDPR enforcement can move.
Why it happened
- Fixing the leak before telling anyone is not the same as notifying without undue delay — the sequence of discovery and notification is itself judged.
- Security by design is a continuing obligation, not a one-off fix; the largest share of the fine came from feature design, not from the breach response.
The lesson
Hardening a system is not a project you finish; it is a bar every release must clear. A breach found by attackers, not by you, is the bill for features shipped without data protection built in.
Aftermath
Meta said it would appeal the decision. The case had been open since 2018, and the six-year path from breach to fine became a reference point for how slowly cross-border GDPR enforcement can move. The DPC's ruling also cited the importance of building data-protection requirements into design and development cycles, echoing its earlier fine of Meta over password storage and delayed breach notification.
Sources
- Irish Data Protection Commission fines Meta €251 million — Irish Data Protection Commission
- Irish Data Protection Commission fines Meta €251m over Facebook data hacks — The Journal
spotted an error? The club wants to know.
More like this
Google stacked its ad exchange against rivals — €2.95B EU fine
TikTok let staff in China access EEA user data — €530M GDPR fine
Netflix fined €4.75M for not telling customers what it does with their data
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.