Skip to content
Support Us

We need your help now

Support from readers like you keeps The Journal open.

You are visiting us because we have something you value. Independent, unbiased news that tells the truth. Advertising revenue goes some way to support our mission, but this year it has not been enough.

If you've seen value in our reporting, please contribute what you can, so we can continue to produce accurate and meaningful journalism. For everyone who needs it.

Niall Carson

Irish data watchdog launches probe into Facebook password storage as millions left exposed

Ireland’s Data Protection Commissioner is Facebook’s lead regulator in the European Union.

IRELAND’S DATA PROTECTION Commissioner has launched a statutory inquiry into Facebook’s password storage after the social media giant revealed that it stored millions of accounts’ passwords in plain text on its internal servers.

In March Facebook announced in a blog post that a routine security review carried out in January found the passwords were being stored in a readable format on its data storage systems.

It said it would be contacting “hundreds of millions” of users to make them aware that their password was involved in the glitch. Last week the company updated the post to say that it now estimates that the issue has also impacted “millions” of Instagram users.

A Facebook source told cyber security blog KrebsOnSecurity that more than 20,000 Facebook employees had access to the passwords.

Today the DPC announced it would be investigating whether Facebook broke EU data rules by storing users’ passwords in this manner.

As Ireland hosts Facebook’s European headquarters, under the EU’s General Data Protection Regulation’s (GDPR) the DPC is Facebook’s lead regulator in Europe.

facebook 869_90567861 Facebook CEO Mark Zuckerberg outside Government Buildings on his way to meet members of the Oireachtas Communications Committee in Dublin. Sam Boal Sam Boal

“The Data Protection Commission was notified by Facebook that it had discovered that hundreds of millions of user passwords, relating to users of Facebook, Facebook Lite and Instagram, were stored by Facebook in plain text format in its internal servers,” it said in  a statement.

We have this week commenced a statutory inquiry in relation to this issue to determine whether Facebook has complied with its obligations under relevant provisions of the GDPR. 

Earlier this year the DPC said it is conducting seven statutory inquiries into Facebook and three-more into Whatsapp and Instagram. It said it expects to wrap up the first of these probes in the summer and the rest by the end of the year.

A firm found to have broken EU data processing and handling rules can be fined up to 4% of their global revenue from the prior financial year.

Readers like you are keeping these stories free for everyone...
A mix of advertising and supporting contributions helps keep paywalls away from valuable information like this article. Over 5,000 readers like you have already stepped up and support us with a monthly payment or a once-off donation.

Close
20 Comments
This is YOUR comments community. Stay civil, stay constructive, stay on topic. Please familiarise yourself with our comments policy here before taking part.
Leave a Comment
    Install the app to use these features.
    Mute wattsed56
    Favourite wattsed56
    Report
    Apr 25th 2019, 9:34 PM

    The watchdog in Dublin has neither the competencies or capability to handle this. Not even sure they have the willingness or political freedom to punish them if needed.

    115
    Install the app to use these features.
    Mute Deirdre O'Byrne
    Favourite Deirdre O'Byrne
    Report
    Apr 26th 2019, 1:35 AM

    @wattsed56: actually they aren’t in Dublin. They are in a pokey office above a Centra shop in Portarlington

    http://www.broadsheet.ie/tag/data-protection-commissioner/

    13
    Install the app to use these features.
    Mute wattsed56
    Favourite wattsed56
    Report
    Apr 26th 2019, 11:23 AM

    @Deirdre O’Byrne: Appalling. Surprised they haven’t been given rent free office suite in FB’s Dublin HQ.

    3
    Install the app to use these features.
    Mute Tony Donoghue
    Favourite Tony Donoghue
    Report
    Apr 25th 2019, 10:01 PM

    Do facebook really care about anything other than revenue?

    49
    Install the app to use these features.
    Mute Tweety McTweeter
    Favourite Tweety McTweeter
    Report
    Apr 25th 2019, 10:02 PM

    @Tony Donoghue: Does any business?

    34
    Install the app to use these features.
    Mute Tony Donoghue
    Favourite Tony Donoghue
    Report
    Apr 25th 2019, 10:12 PM

    @Tweety McTweeter: Tayto

    14
    Install the app to use these features.
    Mute TechBuzz Ireland
    Favourite TechBuzz Ireland
    Report
    Apr 25th 2019, 9:37 PM

    Yawn. Only now. Worst case scenario is a hand slap here. Nothing to see..

    35
    Install the app to use these features.
    Mute Albert Brennerman
    Favourite Albert Brennerman
    Report
    Apr 25th 2019, 10:15 PM

    Email password eitherway is not good enough anymore. Would you put a box outside your house with all your political views, friends, pictures, rants accessible to anyone that can provide the correct eight character password. A digital identity blockchain type thing.
    Unfortunately I am stuck at “hello world” .

    13
    Install the app to use these features.
    Mute Shougeki
    Favourite Shougeki
    Report
    Apr 26th 2019, 10:16 AM

    @Albert Brennerman: How do you authenticate with the block chain to prove it is you?

    1
    Install the app to use these features.
    Mute chris c
    Favourite chris c
    Report
    Apr 25th 2019, 9:40 PM

    What are they going to do about it? Eh nothing. Because they can’t.Silly rubbish news.

    27
    Install the app to use these features.
    Mute Tweety McTweeter
    Favourite Tweety McTweeter
    Report
    Apr 25th 2019, 10:02 PM

    For the most serious infringements (for example, not having sufficient customer consent to process data or violating the core of privacy by design concepts) organisations can be fined up to 4% of their annual global turnover or €20 million, whichever is greater.

    11
    Install the app to use these features.
    Mute LYNDALAND
    Favourite LYNDALAND
    Report
    Apr 25th 2019, 10:59 PM

    @Tweety McTweeter: I suppose the real question is what was the exposure here? Were the passwords stored in an quadruple encrypted cyber vault that lara croft would have difficulty penetrating or were they on a server acessible to staff members ?

    5
    See 1 more reply ▾
    Install the app to use these features.
    Mute Tony Donoghue
    Favourite Tony Donoghue
    Report
    Apr 25th 2019, 11:20 PM

    @LYNDALAND: Indeed or Ethan Hunt dangling from the ceiling!

    1
    Install the app to use these features.
    Mute Conor Normile
    Favourite Conor Normile
    Report
    Apr 25th 2019, 11:51 PM
    6
    Install the app to use these features.
    Mute Sonic
    Favourite Sonic
    Report
    Apr 26th 2019, 12:25 AM

    3 words.
    Horse. Bolted. Incompetent.

    5
    Install the app to use these features.
    Mute Duncan Paul
    Favourite Duncan Paul
    Report
    Apr 26th 2019, 9:28 AM

    Mr Zuckerberg wont get a wink o sleep tonight

    1
    Install the app to use these features.
    Mute Duncan Paul
    Favourite Duncan Paul
    Report
    Apr 26th 2019, 9:28 AM

    Mr Zuckerberg wont get a wink of sleep tonight

    1
    Install the app to use these features.
    Mute Duncan Paul
    Favourite Duncan Paul
    Report
    Apr 26th 2019, 9:27 AM

    Mr Zuckerberg will wont get a wink of sleep tonight.

    1
    Install the app to use these features.
    Mute Duncan Paul
    Favourite Duncan Paul
    Report
    Apr 26th 2019, 9:24 AM

    Mr Zuckerberg wont sleep a wink tonight.

    1
    Install the app to use these features.
    Mute Duncan Paul
    Favourite Duncan Paul
    Report
    Apr 25th 2019, 9:50 PM

    Mr Zuckerberg won’t sleep a wink tonight

    1
Submit a report
Please help us understand how this comment violates our community guidelines.
Thank you for the feedback
Your feedback has been sent to our team for review.

Leave a comment

 
cancel reply