Back to the archive

The encyclopedia · Legal & Compliance · Legal decision · 2019–2024

Meta left some user passwords in plaintext — the Irish DPC fined it €91M

Hundreds of millions of passwords sat readable inside Meta's own systems; the Irish DPC fined it €91M even though no outsider ever got hold of them.

Meta Platforms · 2024-09-27

What happened

On 27 September 2024 Ireland's Data Protection Commission fined Meta Platforms Ireland €91 million ($102M) after a subset of user passwords was stored in plaintext — unencrypted and readable — inside the company's internal systems. Hundreds of millions of Facebook Lite users, tens of millions of other Facebook users and millions of Instagram users were affected.

The fine came even though no passwords ever reached outsiders and no abuse was found. The regulator ruled that Meta had failed GDPR's security duties by not assessing the risks of how passwords were processed, and had also failed to formally report the matter as a personal data breach or document it as required.

Meta itself had brought the issue to the DPC in March 2019, saying the passwords were temporarily logged in a readable format and the error was fixed. The inquiry opened the following month and the decision landed five and a half years later. The DPC said storing passwords in plaintext is widely accepted as unacceptable, because anyone reaching the data reaches the accounts.

Why it happened

  • Internal logging pipelines are built for debugging, not for secrets — passwords ended up readable because nobody decided otherwise.
  • The GDPR punishes the state of the data, not only the harm done: unencrypted passwords are a sanctionable breach even if no outsider ever touches them.
  • Disclosure starts the clock but is not the obligation itself — formal breach notification and documentation are separate duties, and both were missed.
What it cost€91M ($102M) finecostly

The lesson

Secrets that land in logs or internal stores by accident are still personal data — reviewing what your systems record costs less than explaining plaintext passwords to a regulator five years on.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →