Meta, the parent company of Facebook, has been fined €251 million by European Union privacy regulators following an investigation into a 2018 data breach that exposed millions of user accounts. The penalties, announced Monday by Ireland’s Data Protection Commission (DPC), highlight multiple violations of the EU’s stringent General Data Protection Regulation (GDPR).
The breach, which occurred in 2018, allowed hackers to exploit vulnerabilities in Facebook’s “View As” feature to steal digital access tokens—keys that enable users to remain logged into their accounts. This flaw enabled attackers to gain unauthorized control over approximately 29 million accounts globally, including 3 million in Europe.
Investigation Findings
The DPC, serving as Meta’s primary EU privacy regulator due to the company’s regional headquarters in Dublin, concluded that Meta had committed several GDPR infringements. The regulatory body imposed the significant fine alongside issuing formal reprimands.
Facebook initially estimated the breach impacted 50 million accounts but later revised the figure to 29 million. The compromised data included access credentials, making the breach particularly severe in terms of user vulnerability.
Meta Responds
Meta expressed its intent to appeal the decision. In a statement, the company said, “This decision relates to an incident from 2018. We took immediate action to fix the problem as soon as it was identified.” The company also emphasized its transparency, noting that it “proactively informed people impacted” and promptly notified regulators and law enforcement, including the FBI.
Meta has since patched the bugs in the “View As” feature and discontinued the tool to prevent similar vulnerabilities.
The Attack Mechanism
The breach stemmed from three specific bugs in the “View As” feature, which allowed users to preview how their profiles appeared to others. Hackers leveraged these flaws to obtain access tokens from accounts appearing in search results. These tokens then granted attackers the ability to control the accounts, spreading the breach from one user’s network of friends to another.
Broader Implications
The fine underscores the EU’s commitment to enforcing GDPR regulations, which aim to protect user data and hold companies accountable for lapses. The Irish DPC has been increasingly active in regulating tech giants, given Dublin’s role as a hub for several multinational tech firms.
This penalty is one of several recent actions taken against Meta over data privacy issues, reflecting growing scrutiny of the company’s practices. As the appeal process unfolds, the decision further highlights the mounting challenges faced by tech companies navigating Europe’s robust regulatory landscape.