{"id":25274,"date":"2024-10-01T03:10:07","date_gmt":"2024-10-01T11:10:07","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2024\/10\/01\/news-19004\/"},"modified":"2024-10-01T03:10:07","modified_gmt":"2024-10-01T11:10:07","slug":"news-19004","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2024\/10\/01\/news-19004\/","title":{"rendered":"Facebook and Instagram passwords were stored in plaintext, Meta fined"},"content":{"rendered":"\n<p>Ireland\u2019s privacy watchdog Data Protection Commission (DPC) has <a href=\"https:\/\/www.dataprotection.ie\/en\/news-media\/press-releases\/DPC-announces-91-million-fine-of-Meta\">fined Meta \u20ac91M<\/a> ($101M) after the discovery in 2019 that Meta had stored 600 million Facebook and Instagram passwords in plaintext.<\/p>\n<p>The DPC ruled that Meta was in violation of GDPR on several occasions related to this breach. It determined that the company failed to \u201cnotify the DPC of a personal data breach concerning storage of user passwords in plaintext\u201d without delay, and failed to \u201cdocument personal data breaches concerning the storage of user passwords in plaintext.\u201d<\/p>\n<p>The DPC also said that Meta violated GDPR by not using appropriate technical measures to ensure the security of users\u2019 passwords against unauthorized processing.<\/p>\n<p>While the DPC does not disclose the number of passwords, several <a href=\"https:\/\/krebsonsecurity.com\/2019\/03\/facebook-stored-hundreds-of-millions-of-user-passwords-in-plain-text-for-years\/\">sources<\/a> at the time quoted internal sources at Facebook who said 600 million password were freely accessible to employees. Most of these passwords belonged to Facebook Lite users, but it affected other Facebook and Instagram users as well.<\/p>\n<p>Facebook found out that it logged the passwords in plaintext by mistake during a code review.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-an-ongoing-issue\">An ongoing issue<\/h2>\n<p>Over the years, several data sets belonging to Facebook users have circulated on <a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2017\/07\/explained-dark-web\">Dark Web<\/a> marketplaces. We&#8217;ve seen country-specific sets for Iran, Sudan, and Hong Kong. The largest data set that is still publicly accessible contains 303,081,505 records and was shared on a Telegram channel in February 2022. The data contains email addresses, names, phone numbers and additional personal information.<\/p>\n<p>In April 2021, a cybercriminal posted over half a billion scraped Facebook profiles for free on a hacking forum. The data encompassed profiles from over 100 countries and included emails, Facebook IDs, birthdays, phone numbers, and other <a href=\"https:\/\/www.malwarebytes.com\/cybersecurity\/basics\/pii\">Personally Identifiable Information (PII)<\/a>. Several other forums mirrored this data set.<\/p>\n<p>Last February, we <a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2024\/02\/facebook-marketplace-users-stolen-data-offered-for-sale\">reported<\/a> how personal data belonging to Facebook Marketplace users was published online. That leak consisted of around 200,000 records that contained names, phone numbers, email addresses, Facebook IDs, and Facebook profile information.<\/p>\n<p>In 2019, a private security researcher reported finding a database with the names, phone numbers, and unique user IDs of over 267 million Facebook users. The hosting company took the database offline after a tip off from the security researcher.<\/p>\n<p>Social media accounts container a lot of personal information which combined with our email addresses provides cybercriminals with information they can use to add credibility to their phishing attempts.<\/p>\n<p>It&#8217;s a good idea to check what personal information of yours is out there, and for that you can use our\u00a0<a href=\"https:\/\/www.malwarebytes.com\/digital-footprint\">free Digital Footprint scan<\/a>. Fill in the email address you use most frequently to sign up for sites and services, and we\u2019ll give you a free report.<\/p>\n<div class=\"wp-block-malware-bytes-button mb-button\" id=\"mb-button-7ba16f0b-04e8-4679-9512-2f21a0971dcf\">\n<div class=\"mb-button__row u-justify-content-center\">\n<div class=\"mb-button__item mb-button-item-0\">\n<p class=\"btn-main\"><a href=\"https:\/\/www.malwarebytes.com\/digital-footprint?utm_source=blog&amp;utm_medium=social&amp;utm_campaign=b2c_pro_acq_fy25dfplaunch_171269600960&amp;utm_content=V1\"><\/a><a href=\"https:\/\/www.malwarebytes.com\/digital-footprint\">SCAN NOW<\/a><\/p>\n<\/div>\n<\/div>\n<\/div>\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\" \/>\n<p><strong>We don&#8217;t just report on threats &#8211; we help safeguard your entire digital identity<\/strong><\/p>\n<p>Cybersecurity risks should never spread beyond a headline. Protect your\u2014and your family&#8217;s\u2014personal information by using <a href=\"https:\/\/www.malwarebytes.com\/identity-theft-protection\">identity protection<\/a>.<\/p>\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2024\/10\/facebook-and-instagram-passwords-were-stored-in-plaintext-meta-fined\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> The Data Protection Commission has fined Meta $101M because 600 million Facebook and Instagram passwords were stored in plaintext. <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[21015,3589,11529,2143,32,10602,31170,5897],"class_list":["post-25274","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-dpc","tag-facebook","tag-facebook-lite","tag-instagram","tag-news","tag-passwords","tag-plaintext","tag-privacy"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/25274","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=25274"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/25274\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=25274"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=25274"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=25274"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}