EnforcementThursday 12 September 2024via Reuters

EU Commission Fines Meta €91 Million for Storing Passwords in Plain Text

Guardii Analysis

The European Union on 12 September 2024 fined Meta €91 million for storing hundreds of millions of user passwords in plain text on internal servers, in breach of the General Data Protection Regulation. The Irish Data Protection Commission, acting as lead regulator for Meta in the EU, found that the company failed to implement appropriate technical measures to protect user credentials, leaving them accessible to thousands of employees between 2012 and 2019. While the Commission stated there was no evidence of external access or misuse, the breach increased the risk of unauthorised account access and could have facilitated targeting of vulnerable users including children if credentials had been compromised.

When foundational data-security controls fail, children's accounts become more vulnerable to takeover by offenders seeking to impersonate a trusted contact, harvest personal information or access private conversations. Detection systems that monitor the content and dynamics of direct messages provide a second line of defence by identifying coercion, sexual solicitation or impersonation tactics in real time, even if an account's perimeter has been breached. Guardii, backed by Startmate and operating across Instagram, Snapchat, Discord, Roblox and other platforms, deploys real-time grooming and sextortion detection that flags escalating threat patterns to parents, schools and safeguarding professionals, enabling intervention before harm materialises and reducing reliance on upstream access controls that this enforcement action shows can be inadequate.

Related Articles