Ireland fines Meta 91 million euros over EU data breach

Ireland fines Meta 91 million euros over EU data breach
In this file photo taken on October 28, 2021, the Meta logo on a laptop screen in Moscow as Facebook chief Mark Zuckerberg announced the parent company’s name is being changed to “Meta” to represent a future beyond just its troubled social network. (Photo by Kirill KUDRYAVTSEV / Agence France-Presse)

DUBLIN — An Irish regulator helping to police European Union (EU) data privacy said Friday it had fined Facebook owner Meta 91 million euros ($102 million) for password-security breaches.

The Data Protection Commission criticised Meta for failing to put in place appropriate security measures to protect users’ password data and for taking too long to alert the regulator over the issue.

An inquiry was launched in April 2019 after Meta Ireland informed the regulator that it had “inadvertently stored certain passwords of social media users” in a readable format on its internal system, the DPC said in a statement.

“It is widely accepted that user passwords should not be stored in plaintext, considering the risks of abuse that arise from persons accessing such data,” said Graham Doyle, the regulator’s head of communications.

Doyle told  Agence France-Presse that the breach, which took place in January 2019, affected 36 million Facebook and Instagram users across the European Economic Area, which comprises the EU plus Iceland, Liechtenstein, and Norway.

The regulator criticised Meta for not alerting the DPC of the problem until March 2019.

READ: Meta hit with record $1.3-B fine over data transfers

In a statement to  Agence France-Presse, Meta acknowledged that some Facebook users’ passwords were “temporarily stored in a readable format in our internal data systems.”

“We took immediate action to fix this error, and there is no evidence that these passwords were abused or accessed improperly.

“We proactively flagged this issue to our lead regulator, the Irish Data Protection Commission, and have engaged constructively with them throughout this inquiry,” a Meta spokesperson added.

Tech crackdown: Google, Apple, Meta

Many global tech companies including Google, Apple, and Meta, base their European operations in Dublin.

As a result, Ireland’s data protection agency is the lead regulator responsible for holding them to account.

The fine issued Friday, dwarfed by Meta’s multi-billion-dollar earnings, is the latest in a series issued to the US social media giant and its rivals, as global regulators seek to rein in big tech firms over also taxation, competition, and disinformation.

READ: EU scores ‘big win’ in court against Apple and Google

Ireland this month launched an investigation in Google’s artificial intelligence development.

It came as the European Commission scored two major legal victories in separate cases that left Apple and Google owing billions of euros.

At the same time, an EU court scrapped a 1.49-billion euro fine imposed by Brussels against Google over abuse of dominance in online advertising.

Tech giants are also seeking out each other over alleged breaches.

Google on Wednesday said it had filed a complaint against Microsoft at the European Commission, accusing its rival of “anticompetitive” licensing practices to force customers to use its cloud service.

Read more...