Facebook Parent Meta Fined $102 Million by Irish Regulators Over Password Security Breach

Facebook parent Meta’s operations in Ireland have been hit with a $102 million fine and formal reprimand for failing to protect users’ passwords, Ireland’s Data Protection Commission (DPC) announced at the conclusion of a four-year investigation into the social media giant’s handling of sensitive user data.
The DPC said in a Sept. 27 announcement that Meta had failed to implement appropriate security measures for user passwords, resulting in an inadvertent storage of these sensitive details in plaintext—rather than with cryptographic protection—in the company’s internal systems.
“It is widely accepted that user passwords should not be stored in plaintext, considering the risks of abuse that arise from persons accessing such data,” Graham Doyle, DPC deputy commissioner, said in a statement. “It must be borne in mind that the passwords subject of consideration in this case are particularly sensitive, as they would enable access to users’ social media accounts.”…