Facebook password security lapse probed by privacy regulator

An investigation into a Facebook error that left hundreds of millions of user passwords exposed in an internal plain text file has been launched by the company’s main privacy regulator.

Last month, the social network admitted to the security lapse which meant company employees could have seen the passwords of users which are usually stored in an unreadable format.

The Data Protection Commission, the lead supervising authority for Facebook in the EU, confirmed it had been notified of the incident and has started an inquiry to determine whether the social network breached GDPR (General Data Protection Regulation) laws designed to protect people’s data.

“The Data Protection Commission was notified by Facebook that it had discovered that hundreds of millions of user passwords, relating to users of Facebook, Facebook Lite and Instagram, were stored by Facebook in plain text format in its internal servers,” the authority said in a statement.

“We have this week commenced a statutory inquiry in relation to this issue to determine whether Facebook has complied with its obligations under relevant provisions of the GDPR.”

The social network warned that the incident could have affected hundreds of millions of Facebook Lite users, a downscaled version of the app for people with older phones or slow internet connections, as well as millions of main Facebook and Instagram users.

Facebook fixed the flaw after uncovering it January.

(Dominic Lipinski/PA)

Its own investigation found no evidence that anyone outside Facebook got hold of the passwords, or that were they abused by staff internally.

The development is the latest in a string of headaches for Facebook chief executive Mark Zuckerberg in recent years, including rampant misinformation spread on the network, breaches of user data and allegations of political manipulation.

In a sign of the growing pressure on the platform from governments to change its business practices, Facebook revealed in its latest quarterly results that it had put aside $3 billion (€2.7bn) to cover potential fines issued by the US Federal Trade Commission’s ongoing inquiry into the firm, related to the Cambridge Analytica data scandal.

A Facebook spokesman said: “We are working with the IDPC on their inquiry.

“There is no evidence that these internally stored passwords were abused or improperly accessed.”

- Press Association

More on this topic

Facebook takes action against campaign aimed at disrupting foreign elections

Facebook changes live streaming rules following New Zealand attack

WhatsApp users urged to update app following spyware vulnerability

Facebook sues South Korean analytics firm over allegations of data misuse

More in this Section

Taxi driver gets five years for sexually assaulting three young women in two weeks

Zappone 'committed to' affordability, quality and safety in child care services

Pensioner who fractured arm in fall has award of damages increased to more than €56k

Three Irish beaches fail to retain Blue Flag status


Irish Examiner Sustainability Month special: Are retailers meeting customer expectations for sustainable products?

Making the most of Irish strawberries - Michelle Darmody shares her recipes

Making Cents: Help protect the planet and occupy the kids

Good Omens and great expectations

More From The Irish Examiner