Meta has been fined over $102 million by the European Union’s privacy regulator due to a significant security lapse involving Facebook user passwords. The Irish Data Protection Commission announced a penalty of €91 million ($101.6 million) following an investigation that began in 2019. This investigation was prompted by Meta’s notification that certain passwords had been stored internally in plain text, meaning they were unencrypted and accessible to employees.
Deputy Commissioner Graham Doyle emphasized the critical importance of not storing user passwords in plain text, highlighting the risks of potential abuse. Meta confirmed that a review identified a subset of Facebook users’ passwords temporarily logged in a readable format.
In response, the company stated, “We took immediate action to fix this error, and there is no evidence that these passwords were abused or accessed improperly.” Meta added that it proactively reported the issue to the Irish Data Protection Commission and has cooperated throughout the inquiry.
This fine marks yet another significant penalty for Meta from the Dublin-based regulator, which oversees compliance with the EU’s stringent data privacy regulations. Previous fines against Meta include €405 million for Instagram over mishandling teenage data, a €5.5 million penalty involving WhatsApp, and a €1.2 billion fine for issues related to transatlantic data transfer


