The 2019 Facebook breach exposed over 533 million records — phone numbers, account IDs, and personal data — scraped from Meta's systems where it was used for two-factor authentication. When the dataset resurfaced on hacking forums in 2021, it fueled a wave of SIM-swapping attacks affecting users worldwide. Ireland's DPC imposed a €265 million fine, yet this penalty is only fractionally higher than the average GDPR fine for breaches of this scale. The incident remains a stark reminder that even the largest social networks can fail to protect authentication data.

Comments on "Facebook (2019)"
Create a free account or sign in to join the discussion.
Sign in to join the conversation