Back to the archive

The encyclopedia · Legal & Compliance · Legal decision · 2018–2024

Meta's 2018 breach exposed 29M accounts — a €251M fine six years later

Ireland's DPC fined Meta €251M for the 2018 breach in which attackers grabbed access tokens for ~29M accounts — six years after the fact.

Meta · 2024-12-17

What happened

On 17 December 2024 Ireland's Data Protection Commission, Meta's lead regulator in the EU, fined the company €251 million over the September 2018 breach that exposed the accounts of about 29 million users worldwide, including roughly 3 million in the EU and EEA.

Attackers exploited a flaw in Facebook's video upload function, gaining access tokens that let them log in as account holders. Over a two-week period in 2018 they reached personal data including email addresses, phone numbers, locations and places of work.

The DPC found multiple GDPR infringements: failures on breach notification and documentation, and failures to build data protection into the design and default settings of the service. The regulator said the flaws behind the breach posed a grave risk of misuse of the exposed data.

Meta remedied the breach shortly after it was discovered and reported it to the regulator in September 2018. The company said it would appeal the decision. The case had run since 2018, and the gap between breach and fine showed how slowly cross-border GDPR enforcement can move.

Why it happened

  • Fixing the leak before telling anyone is not the same as notifying without undue delay — the sequence of discovery and notification is itself judged.
  • Security by design is a continuing obligation, not a one-off fix; the largest share of the fine came from feature design, not from the breach response.
What it cost€251M GDPR fine and a 2018-breach reckoningcostly

The lesson

Hardening a system is not a project you finish; it is a bar every release must clear. A breach found by attackers, not by you, is the bill for features shipped without data protection built in.

Aftermath

Meta said it would appeal the decision. The case had been open since 2018, and the six-year path from breach to fine became a reference point for how slowly cross-border GDPR enforcement can move. The DPC's ruling also cited the importance of building data-protection requirements into design and development cycles, echoing its earlier fine of Meta over password storage and delayed breach notification.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →