DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowFall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
Blog

Meta fined €91 million over plaintext passwords stored in internal logs

By TheFinanceBase Team7 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Meta was fined €91 million on September 27, 2024, after Ireland’s Data Protection Commission (DPC) found that some Facebook, Facebook Lite and Instagram passwords had been stored in readable form in internal logging systems. The incident was discovered and disclosed in 2019. The DPC said the passwords were not made available to external parties, and the public findings do not establish that hackers stole or used them.

The fine covered more than a technical mistake. The DPC found failures in password security, breach notification and breach documentation. For users, the practical lesson is clear: change old or reused passwords, enable multifactor authentication and treat unexpected Meta security messages cautiously.

What happened to Meta users’ passwords?

During a security review in January 2019, Meta found that some user passwords had been written into internal logs in readable form. The DPC’s final decision describes the problem as an unintended consequence of Meta’s data-logging operations, rather than the deliberate design of its ordinary password-authentication system.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Meta announced the issue on March 21, 2019. Its statement said it expected to notify hundreds of millions of Facebook Lite users, tens of millions of other Facebook users and tens of thousands of Instagram users. Meta later said that additional readable password logs affected millions more Instagram users.

#1 Best Overall
Sale
Password Safe
  • Requires 3 "AAA" batteries (included)
  • Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs

The widely repeated estimate of up to approximately 600 million passwords came from contemporaneous reporting attributed to a senior Meta employee. It should not be described as 600 million unique people. The figure generally refers to password records or credentials, and may include records belonging to accounts that were no longer active.

Sources: Meta’s 2019 statement and the DPC final decision.

What does “plaintext” mean?

A plaintext password is stored in a readable form. Someone with access to the relevant log, file, backup or administrative interface may be able to see the original password directly.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Protection method What it means
Plaintext The original password is readable.
Encryption Data is scrambled but can be restored with a key.
Hashing A one-way transformation used to verify a password without retaining the original.
Salting A unique random value added before hashing to make password-cracking attacks harder.

Normal password systems should use a slow, salted password-hashing scheme such as Argon2id, scrypt or bcrypt. Meta said its standard password process used hashing and salting, including scrypt and a cryptographic key. The incident occurred in logging systems outside that normal authentication path.

Rank #2
Atlancube PasswordPocket Offline Hardware Password Keeper with Bluetooth Auto-Fill for iPhone and Android, Stores 1,000 Logins, Military-Grade AES-256 Encryption (Black)
  • Auto-Fill Feature: Say goodbye to the hassle of manually entering passwords! PasswordPocket automatically fills in your credentials with just a single click.
  • Internet-Free Data Protection: Use Bluetooth as the communication medium with your device. Eliminating the need to access the internet and reducing the risk of unauthorized access.
  • Military-Grade Encryption: Utilizes advanced encryption techniques to safeguard your sensitive information, providing you with enhanced privacy and security.
  • Offline Account Management: Store up to 1,000 sets of account credentials in PasswordPocket.
  • Support for Multiple Platforms: PasswordPocket works seamlessly across multiple platforms, including iOS and Android mobile phones and tablets.

That distinction matters, but it does not make the failure minor. Debug logs, traces, analytics events, crash reports and exported datasets can contain sensitive information unless they are designed and monitored carefully. Plaintext credentials are especially dangerous when people reuse the same password for email, banking, shopping, work or other important accounts.

Were Meta’s passwords hacked?

The public findings do not establish that an outside attacker obtained and used the passwords. The DPC said the passwords were stored on Meta’s internal systems and were not made available to external parties. Meta said it found no evidence that employees improperly accessed or abused them.

That is not the same as proving that there was no risk. Readable passwords could have enabled account takeover if an unauthorized person had accessed the logs. A compromised social-media account can expose private messages and photos, enable impersonation, abuse advertising or business accounts, and provide material for convincing social-engineering attacks.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The DPC treated the incident as engaging GDPR personal-data-breach obligations. In this context, “breach” describes a failure involving the security of personal data; it does not necessarily mean that investigators established a criminal intrusion.

Rank #3
Sale
Elegant Password Book with Alphabetical Tabs - Hardcover Password Book for Internet Website Address Login - 5.2" x 7.6" Password Keeper and Organizer w/Notes Section & Back Pocket (Turquoise)
  • NEVER FORGET A PASSWORD AGAIN: Almost every App. has a password, it is almost impossible to remember all the password log in details. This password book is specifically designed to help you create secure passwords and store all your passwords safely in one place. You will never forget your password log-in details again with this password keeper.
  • ALPHABETICAL A-Z TABS FOR QUICK ACCESS: Alphabetical tabs design allows you to store your passwords alphabetically so you can find what you want faster, no more annoying searches!
  • ANONYMOUS WITHOUT ANY TITLE: On the outside, this password notebook organizer looks just like those writing journals, there is no title listed on the cover, so no one would know it's a password book. But we still recommend keeping the internet password logbook in a safe place such as a locked drawer or a shelf full of books.
  • THICK NO-BLEED PAPER: This 5.2" x 7.6" password book contains 74 sheets of thick 120gsm paper that resists ink smearing, say goodbye to those cheap password books that bleed ink!
  • PREMIUM QUALITY & PERFECT MEDIUM SIZE: This password journal comes with a high-quality leatherette hardcover, an elastic band, pen holder, ribbon bookmarker, and inner accordion pocket. It measures 5.2 inches wide and 7.6 inches long, which is the perfect size for your needs.

Why did the fine arrive five years later?

The password problem was discovered in 2019. The €91 million penalty was the result of a later regulatory process.

  1. January 7, 2019: Meta identified an initial smaller set of password records during its internal review.
  2. January 31, 2019: Meta identified a larger set, including Facebook Lite users in the EU and EEA.
  3. March 21, 2019: Meta notified Ireland’s DPC and publicly disclosed the issue.
  4. April 2019: The DPC opened its inquiry.
  5. June 27, 2024: The DPC submitted a draft decision to other concerned EU and EEA supervisory authorities under GDPR’s cross-border process.
  6. September 26–27, 2024: Meta was notified of the final decision, and the DPC announced a reprimand and €91 million fine.

Cross-border GDPR cases can involve a lead supervisory authority, other concerned authorities, draft decisions and a consistency process. The DPC said no objections were raised by the other concerned supervisory authorities. Thus, 2024 was the date of the final regulatory decision—not the date the password exposure was discovered.

Read the DPC announcement for the regulator’s account of the timeline and penalty.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which GDPR rules did Meta violate?

The DPC identified four principal infringements:

  • Article 5(1)(f): Meta failed to use appropriate technical and organizational measures to protect password security against unauthorized processing.
  • Article 32(1): Meta failed to implement security measures appropriate to the risk, including measures supporting ongoing confidentiality.
  • Article 33(1): Meta failed to notify the DPC of the personal-data breach as required.
  • Article 33(5): Meta failed to properly document the breach.

In plain English, the case concerned both the underlying security failure and the governance around it. A company must protect credentials, but it must also identify, assess, document and report security incidents properly.

Rank #4
Sale
Clever Fox Password Book with Alphabetical Tabs, 4"x5.5" Keeper Black
  • NEVER FORGET A PASSWORD AGAIN - Clever Fox password journal will help you create secure passwords and keep them safe and organized. This password book allows you to store all your passwords and other computer information in one place to find it easily.
  • ALPHABETICAL A-Z TABS - Alphabetic tab system makes it easy to find any password you need. The book also has sections for most important passwords, wireless & email settings, software license information & additional notes.
  • ELEGANT, SMART, PRACTICAL & SECURE PASSWORD ORGANIZATION - This password keeper book has been designed to be anonymous without an obvious title on the cover. For added security there is space to write hints instead of the password itself.
  • POCKET SIZE & PREMIUM QUALITY - This internet address and password logbook with tabs comes in pocket size (4.0x5.5 inches). The password notebook has an eco-leahter hardcover, elastic band, pen loop, bookmark, pocket for notes, and thick 120gsm paper.
  • 60-DAY MONEY-BACK GUARANTEE - We will exchange or refund your password organizer if you aren’t satisfied with your password organization for any reason. Reach out to us via message to refund your internet password logbook.

The DPC emphasized that passwords are particularly sensitive because they can provide access to social-media accounts. The potential consequences include account takeover, impersonation, exposure of private content, misuse of advertising accounts and attacks against other services where the same password was reused.

What did Meta say it did afterward?

Meta said it fixed the logging-related problem, notified affected users and reviewed other categories of stored information, including access tokens. It also said its ordinary password systems continued to use hashing and salting, and that it used suspicious-login detection and additional verification controls.

Those are measures described by Meta; the public record does not independently verify every remediation step. The important design lesson is that protecting the main login database is not enough if credentials can leak through a separate logging or debugging system.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Do not confuse this fine with Meta’s $5 billion FTC penalty

The €91 million DPC fine was a separate proceeding from the U.S. Federal Trade Commission’s $5 billion penalty against Facebook.

Best Value
RecZone LLC Password Safe Electronic Storage Organizer Keeper Device and Stylus Bundle
  • Securely Remember All Your Passwords, Log-in's, User Names, ATM PIN Numbers and More
  • Large Back-lit LCD Screen, QWERTY Keyboard - So Easy to Use
  • Enter one PIN number and have access to 400 accounts. Search function included.
  • Unit auto locks for 30 minutes after 5 consecutive incorrect PIN attempts
  • Includes mini stylus for easier keypad entry
Proceeding Amount and timing What it concerned
Ireland’s DPC €91 million, announced September 2024 Plaintext password storage, security controls, breach notification and documentation
U.S. FTC $5 billion, announced July 2019 and effective April 2020 Alleged violations of Facebook’s 2012 privacy order and inadequate privacy controls

The FTC order separately required Facebook to encrypt user passwords and regularly scan for plaintext passwords. That requirement does not mean the FTC’s $5 billion penalty was imposed for this same plaintext-password incident. The two cases involved different regulators, allegations and legal theories. See the FTC announcement.

Meta also faced a separate U.S. consumer privacy class-action settlement of $725 million, which became final on May 14, 2025, according to Meta’s 2026 SEC filing. That settlement was not an additional penalty for the plaintext-password incident.

What Facebook and Instagram users should do

  1. Change an old Facebook or Instagram password. This is especially important if you have not changed it since the affected period or if you reused it elsewhere.
  2. Change reused passwords on high-value accounts. Prioritize email, banking, work, shopping and cloud-storage accounts. A historical exposure cannot be reversed, but replacing the old credential reduces its value.
  3. Use a unique generated password for every service. A password manager can make this practical. Its benefit is reducing reuse—not making an account or vault “unhackable.”
  4. Turn on multifactor authentication. An authenticator app or security key is generally preferable to SMS where available. Passkeys are also worth using when Facebook, Instagram or another service offers them.
  5. Review active sessions. Sign out devices and locations you do not recognize.
  6. Check recovery information. Confirm that the recovery email address and phone number are yours and have not been replaced.
  7. Watch for phishing. Be suspicious of unexpected password-reset messages, login alerts and messages claiming to be “Meta support.” Open the app or type the official website address yourself instead of following an unsolicited link.

There is no evidence in the cited public findings that every Meta user needs to assume their account was taken over. These steps are still sensible because they address password reuse, account recovery and ongoing phishing risk.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What developers and security teams should learn

  • Never write raw passwords to application logs, traces, crash reports or analytics events.
  • Redact sensitive fields before data reaches the logging pipeline, not only after logs are stored.
  • Review structured logs, debug output, backups, exports, staging environments and test data—not just production databases.
  • Apply least-privilege access controls to logs and monitor administrative access.
  • Use a modern, slow, salted password-hashing scheme such as Argon2id, scrypt or bcrypt with appropriate parameters.
  • Keep encryption keys separate from the data they protect. Encryption can be appropriate for API keys, access tokens and private documents, but it is not a substitute for password hashing.
  • Deploy automated detection for plaintext passwords and secrets in source code, CI/CD pipelines and production monitoring.
  • Test incident-alerting, breach-notification and documentation procedures before an incident occurs.
  • Maintain an incident register and evidence of remedial actions.

The FTC’s 2019 order specifically required password encryption and regular scans for plaintext passwords, reinforcing the value of automated detection and repeatable compliance controls.

What the €91 million fine does—and does not—mean

The penalty is a regulatory fine and reprimand, not a €91 million compensation fund paid directly to affected users. It does not prove that all Meta passwords were stored in plaintext, that approximately 600 million unique people were affected, or that hackers stole the credentials.

It also does not show that Meta’s current password systems have the same flaw. The documented issue involved readable credentials in internal logging systems in 2019. The lasting lesson is broader: security controls must cover every system that can receive sensitive data, and companies must be able to detect, document and report failures promptly.

Quick Recap

SaleBestseller No. 1
Password Safe
Password Safe
Requires 3 "AAA" batteries (included); Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs
$30.80
Bestseller No. 5
RecZone LLC Password Safe Electronic Storage Organizer Keeper Device and Stylus Bundle
RecZone LLC Password Safe Electronic Storage Organizer Keeper Device and Stylus Bundle
Securely Remember All Your Passwords, Log-in's, User Names, ATM PIN Numbers and More; Large Back-lit LCD Screen, QWERTY Keyboard - So Easy to Use
$37.84

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.