The Irish Data Protection Commission (DPC) has fined Meta €265 million ($275.5 million) for a massive data breach that exposed the information of hundreds of millions of Facebook users worldwide (after data scraping). The incident took place in 2021.

The decision on the fine concludes the DPC's investigation into possible GDPR violations by Meta, an investigation that began on April 14, 2021, following the publication of data belonging to 533 million Facebook users.
The exposed data included personal informationsuch as mobile phone numbers, Facebook IDs, names, genders, locations, relationship statuses, occupations, dates of birth, and email addresses. The data was exposed on a well-known hacking forum, allowing various cybercriminals to use it for targeted attacks.
See also: BianLian: Harry Rosen data breach with ransomware
Facebook said at the time that the attackers collected the data by exploiting a bug in its “Contact Importer” tool, which allowed them to associate phone numbers with a Facebook ID and then grab the rest of the information to create a profile for the user.
The platform also said it had fixed the bug in 2019 and that the data was collected before.
The DPC investigation concluded that Meta (then Facebook) breached Articles 25(1) and 25(2) of the GDPR, which are summarised as follows:
25(1) – The data controller must implement appropriate technical and organizational measures, such as pseudonymization, and incorporate necessary safeguards into the processing to meet the requirements of this Regulation and to protect the rights of individuals.
25(2) – The controller must implement appropriate technical and organisational measures to ensure that, by definition, only personal data which are necessary for each processing purpose are processed. In particular, such measures shall ensure that, by definition, personal data are not made accessible without the intervention of the individual to an indeterminate number of natural persons.
“ There was a comprehensive investigation process, including cooperation with all other data protection supervisory authorities within the EU ,” the DPC statement said
See also: TikTok “Invisible challenge”: How do hackers exploit it?
According to the Irish Data Protection Commission, the other supervisory authorities also agreed with its decision to fine Meta for violating the GDPR and leaking Facebook users' data.
Data scraping
Data scraping is the process of extracting data from sources that are not intended to be accessed or used in this way. It can be used for various purposes, such as research, marketing, and creating new datasets, but it can also be used for malicious purposes.

Data scrapers are automated bots that exploit open network APIs of platforms that maintain user, such as Facebook, to collect publicly available information and create huge databases of user profiles.
Although no hacking is involved, the data collected can be combined with data from multiple sources (websites), creating complete profiles for users. This makes it much more effective for marketers to track or target by threat actors.
See also: Whoosh data breach: Hacker leaked customer details
In the case of Meta, attackers used a bug in the Contact Importer on Facebook and Instagram to link phone numbers to this public information that had been collected, and were thus able to create user profiles that contained private and public information.
Scraping is against the policies of most online platforms.
According to techcrunch, Meta said of the fine: “Protecting people’s privacy and data security is fundamental to how we operate our business. That’s why we have fully cooperated with the Irish Data Protection Commission on this important matter. We have made changes to systems during this time, including removing the ability to scrape in this way using phone numbers. Unauthorized data scraping is unacceptable and against our rules, and we will continue to work with our colleagues on this industry challenge. We are reviewing this decision carefully.”
Source: www.bleepingcomputer.com
