Ireland's Data Protection Commission imposed a €91 million fine on Meta Platforms on 10 August 2024 for storing hundreds of millions of user passwords in plaintext, accessible to internal engineers, in breach of the General Data Protection Regulation. The Commission found that Meta failed to notify the DPC promptly when it discovered the issue in 2019 and had not implemented appropriate technical measures to protect credentials. While the investigation did not quantify how many affected accounts belonged to children, the DPC noted that minors' data was included in the compromised dataset and that the failure to secure authentication credentials heightened the risk of account takeover and secondary abuse.
Account-security failures create opportunities for unauthorized access, but the harm to a child occurs when an offender uses a compromised account to send grooming messages, sextortion threats or abuse imagery, or when a takeover exposes the child's private communications. Detection systems that operate within the message layer—identifying grooming, sextortion and child sexual abuse material in real time—protect the child whether the sender is an external offender or someone who has gained control of a trusted contact's account. Guardii monitors direct messages across Instagram, Snapchat, Discord and Roblox, flagging hostile or exploitative contact by pattern rather than sender identity, and surfaces the risk to parents, schools or safeguarding professionals with the context needed for immediate intervention.