NewsBite

Meta handed $147m fine in Ireland over password storage

Facebook and Instagram parent company Meta has been fined almost $150m by Irish authorities over its storage of passwords without proper safeguards.

A Meta spokesman confirmed the group had found a subset of Facebook users’ passwords were temporarily logged in a readable format. Picture: AFP
A Meta spokesman confirmed the group had found a subset of Facebook users’ passwords were temporarily logged in a readable format. Picture: AFP

Ireland’s data protection watchdog fined Meta Platforms 91m ($147m) after the Facebook and Instagram owner stored passwords of some social media users on its internal systems without proper safeguards.

The Irish Data Protection Commission launched a probe in 2019 after it said Meta notified officials it had inadvertently stored certain passwords in plain text, without cryptographic protection or encryption. The inquiry focused on whether Meta was complying with the European Union’s General Data Protection Regulation, the bloc’s strict data-privacy and security law.

“It is widely accepted that user passwords should not be stored in plain text, considering the risks of abuse that arise from persons accessing such data,” said Graham Doyle, deputy commissioner at the Irish Data Protection Commission.

In their decision, Irish officials said Meta had failed to notify the commission of a personal data breach and document breaches in relation to the storage of user passwords in plain text, in breach of the GDPR.

A Meta spokesman confirmed the group had found a subset of Facebook users’ passwords were temporarily logged in a readable format in its internal data systems, saying the company took immediate action to address the issue and there was no evidence those passwords were accessed improperly.

“We proactively flagged this issue to our lead regulator, the Irish Data Protection Commission, and have engaged constructively with them throughout this inquiry,” the spokesman added.

The Wall Street Journal

Read related topics:Facebook

Add your comment to this story

To join the conversation, please Don't have an account? Register

Join the conversation, you are commenting as Logout

Original URL: https://www.theaustralian.com.au/business/media/meta-handed-147m-fine-in-ireland-over-password-storage/news-story/2be206513c91ba2680b01747fee3154f