Ireland's Data Protection Commission imposed a €251 million penalty on Meta Platforms following a 2018 security breach that exposed the personal data of approximately 29 million Facebook users globally, including profile information and contact details. The breach, which exploited vulnerabilities in Facebook's code, permitted unauthorised access to user accounts and represented one of the largest GDPR enforcement actions to date against the social-media giant.
When platform-level security failures expose children's data at scale, threat actors harvest contact information and behavioural signals to refine social-engineering attacks and target minors more effectively across multiple services. Detection systems that continuously monitor inbound messages for grooming behaviours, sextortion threats and age-inappropriate contact—such as those deployed by Guardii, a Meta Business Partner and world-leading AI online-safety platform—intercept exploitation attempts in real time regardless of how the perpetrator initially identified the child, closing the operational gap between breach disclosure and harm to the victim.