Hacking

Meta Fined €91 Million for Storing User Passwords in Plaintext

Published  ·  2 min read

The Irish Data Protection Commission (DPC) has fined Meta €91 million ($101.56 million) following an investigation into a security breach in March 2019. Meta had disclosed that it mistakenly stored users' passwords in plaintext on its systems.

The DPC launched its investigation a month later and found that Meta violated four articles of the European Union's General Data Protection Regulation (GDPR). The commission criticized Meta for failing to promptly report the breach, for not documenting the incident properly, and for neglecting to implement adequate technical measures to safeguard users' passwords.

Meta initially admitted that a subset of Facebook users' passwords had been exposed in plaintext but claimed there was no evidence the data had been improperly accessed or abused internally.

According to Krebs on Security, some of these passwords date back to 2012, with a senior employee revealing that "some 2,000 engineers or developers made approximately nine million internal queries for data elements that contained plaintext user passwords."

In the following month, Meta acknowledged that millions of Instagram passwords had been stored similarly, prompting the company to notify affected users.

"It is widely accepted that user passwords should not be stored in plaintext, considering the risks of abuse that arise from persons accessing such data," said Graham Doyle, deputy commissioner at the DPC. "It must be borne in mind that the passwords in this case are particularly sensitive, as they would enable access to users' social media accounts."

Meta shared with the Associated Press that it took "immediate action" to rectify the issue and that it "proactively flagged this issue" to the DPC.

Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067