Ireland fines Meta €251mil over Facebook hacks


Over a two-week period in 2018, unauthorised users were able to hack into around 29 million Facebook accounts globally, including three million based in the EU. — AFP

DUBLIN: An Irish regulator helping police European Union data privacy on Tuesday said it had fined Facebook-owner Meta €251mil (RM1.1bil) for a data protection failure that saw users' accounts hacked.

The Data Protection Commission (DPC) criticised Meta for a security flaw in its video upload function which hackers were able to exploit to gain full access to other users' Facebook profiles.

Over a two-week period in 2018, unauthorised users were able to hack into around 29 million Facebook accounts globally, including three million based in the EU.

The personal data involved included email addresses, phone numbers, locations and places of work.

"The failure to build in data protection requirements throughout the design and development cycle can expose individuals to very serious risks and harms, including a risk to the fundamental rights and freedoms of individuals," said Graham Doyle, the regulator's head of communications.

"By allowing unauthorised exposure of profile information, the vulnerabilities behind this breach caused a grave risk of misuse of these types of data," he added.

Meta Ireland and its US parent company remedied the breach shortly after its discovery, the DPC said, and reported the issue to the regulator in September 2018.

"We took immediate action to fix the problem as soon as it was identified, and we proactively informed people impacted as well as the Irish Data Protection Commission," a Meta spokesperson said.

Big tech crackdown

It is the latest fine in a series issued to the US social media giant and its rivals, as global regulators seek to rein in big tech firms over privacy, competition, disinformation and taxation.

The EU has been at the forefront of this regulation, with its strict General Data Protection Regulation, launched in 2018 to protect European consumers from personal data breaches.

Many global tech companies including Google, Apple and Meta, base their European operations in Dublin, attracted by Ireland's corporate tax rate.

As a result, Ireland's data protection agency is the lead regulator responsible for holding them to account.

The series of fines by the DPC against Meta over data breaches by its Instagram, WhatsApp and Facebook services have been dwarfed by the tech giant's multi-billion-dollar earnings.

In September, the DPC hit Meta with a 91-million-euro fine for failing to put measures in place to protect users' password data and for taking too long to alert the regulator about the issue.

It came after the European Commission scored two major legal victories in separate cases that left Apple and Google owing billions of euros.

The regulator also recently hit Microsoft-owned LinkedIn with its first EU fine, a €310mil (RM1.4bil) penalty for personal data breaches over targeted advertising. – AFP

Follow us on our official WhatsApp channel for breaking news alerts and key updates!

Next In Tech News

Can Apple’s AirPod translation get you through Tokyo? We tested it
Worn down by worry, parents look longingly at Australia’s social media ban
Fitbit vs. Apple Watch: Which one should you get?
How a man in the US lost US$500,000 in savings to an elaborate scam on the rise
Meta to acquire Chinese startup Manus to boost advanced AI features
Britain's Octopus Energy to spin out Kraken at $8.65 billion valuation
Verisk pulls plug on $2.4 billion AccuLynx deal after FTC review delay
Nvidia takes $5 billion stake in Intel under September agreement
Russian billionaire Potanin acquires minority stake in cloud provider Selectel
Google co-founder explains one of the company’s most infamous failures

Others Also Read