The social media giant ‘Meta‘ has been fined €265 million ($275.5 million) by the Data Protection Commission of Ireland. The fine comes after a massive leak of Meta’s data exposing the personal data of millions of users worldwide.
This brings the DPC’s investigation on the potential GDPR violations by Meta that was first filed on April 14, 2021 once the data of 533 million Meta users were disclosed on a hacker forum.
The data exposed had details on mobile number, Facebook ID, gender, location, occupation, dates of birth, name, relationship status and email address.
A disclosure of this sensitive data on a hacker forum was an invitation to malicious threat actors to use the data for further infiltration and attacks.
As per Meta, the data has been exploited and stolen by hackers using a flaw in their Contact Importer tool to match mobile numbers with a Facebook profile/ID, and further improving the same for complete profile.
Albeit mentioning that the bug has been fixed in 2019, Meta did collect users data before that, and after investigation from DPC it was found that Meta infringed Article 25(1) and 25(2) of GDPR,
Here’s what the Article 25(1) and 25(2) states,
Data Scrapers are bots that manipulate the open APIs from various platforms to extract data that is publicly available and accumulating volumes of data to form user profile databases.
However, as per Meta the hackers exploited the Contact Importer from Facebook and Instagram to match the phone numbers with their publicly scraped data giving them access to create profile containing private and public data.
Linkedin also faced a similar situation recently and made a legal proceeding to prevent data scraping on their platform to prevent its user data extraction.
Regarding the stance of DPC on Meta’s data leakage incident, since DPC is considered to be a spearhead of GDPR Compliance other data protection authorities may scrutinize things further by making sure the data controllers making them to reevaluate their anti-scraping mechanisms.
Subscribe to our newsletter for daily alerts on cyber events, you can also follow us on Facebook, Linkedin, and Twitter.
You can reach out to us via Twitter/ Facebook or mail us at admin@thecybersecuritytimes.com for advertising requests.
Explore the top 5 best Microsoft Intune alternatives, comparing key features, user reviews, and capabilities…
Discover the top 7 smartphones of 2024 with best security features, offering privacy, performance, and…
Discover the top 11 log management tools for efficient system management and monitoring. Learn about…
Explore the top 5 threat intelligence tools, their features, and how they enhance cybersecurity against…
Explore the top 5 best PAM Tools, market trends, and expert insights to secure the…
Explore the top solutions for Apple Device Management including to iOS Device Management and macOS…