Meta Fined €251M for 2018 Facebook Breach

Dec 2024 · €251M fine

By Karim El Labban · ZERO|TOLERANCE

Meta Fined EUR 251M for 2018 Facebook Breach

The Irish Data Protection Commission (DPC) fined Meta Platforms Ireland Limited EUR 251 million in December 2024 for the September 2018 Facebook data breach that exploited a vulnerability in the "View As" feature.

The breach allowed attackers to steal access tokens for approximately 29 million Facebook accounts globally, including roughly 3 million EEA accounts, exposing names, phone numbers, email addresses, and detailed personal information.

The DPC found Meta in violation of Article 25 (data protection by design and by default), Article 33 (breach notification), and Article 32 (security of processing).

01

KEY FACTS

  • .What: Facebook "View As" bug let attackers steal access tokens for 29M accounts.
  • .Who: 29M Facebook users globally, including 3M in the EEA.
  • .Data Exposed: Names, phone numbers, emails, and detailed personal profile data.
  • .Outcome: Irish DPC fined Meta EUR 251M for design and security failures.
02

WHAT WAS EXPOSED

  • .User access tokens for approximately 29 million accounts stolen through the "View As" feature exploit chain
  • .For 15 million accounts: names, and either phone numbers, email addresses, or both
  • .For 14 million accounts: extensive personal details including name, phone number, email, username, date of birth, gender, language, relationship status, religion, hometown, current city, education, work, device types, pages followed, last 10 places checked in, and 15 most recent searches
03

REGULATORY ANALYSIS

The breach resulted from the interaction of three distinct software bugs. The "View As" feature incorrectly generated a user access token for the profile being viewed. A 2017 video uploader change caused it to appear within "View As" and generate tokens with full permissions.

The DPC found violations of Article 25(1) (data protection by design), Article 25(2) (data protection by default--tokens should have used minimum permissions), Article 33 (insufficient initial breach notification), and Article 32 (failure to implement appropriate technical measures).

The fine comprised EUR 210 million for Article 25 violations and EUR 41 million for Article 33 violations.

04

SOURCES

Irish DPC Decision IN-18-8-7, EDPB Guidelines 9/2022, Facebook Security Update September 2018, GDPR Articles 25, 32, 33, 83

RELATED ANALYSIS

USPTO GovDelivery Scam: How Fraudsters Weaponize Real .gov Emails to Steal From Trademark Filers
Apr 1, 2026 · 77K+ victims · 60+ domains · First-person investigation
Free Mobile Fined EUR 42M After 24.6 Million Customer Records Stolen
Jan 16, 2026 · EUR 42M fine
Illuminate Education: FTC Action Over 10.1 Million Student Records Breach
Dec 1, 2025 · $5.1M settlement
Capita Fined £14M After Black Basta Ransomware Exposes 6.6M Records
Oct 1, 2025 · £14M fine
SHEIN Fined €150M for Cookie Consent Violations
Jan 23, 2025 · €150M fine
MORE REGULATORY ENFORCEMENT →