Meta data breach: what happened and what to do
Last reviewed July 10, 2026 · 7 records on file · sources listed below
Meta paused an internal AI training program after a data leak exposed sensitive employee data, including private conversations and performance information, across the entire company, causing employee backlash.
If you have an account with Meta, assume the exposed details are circulating. The practical risk today is rarely the leak itself — it is the calls and messages that use those details to sound legitimate.
What we have on file
Every entry below is a catalogued record with its original source. We do not paraphrase beyond what the source reports.
Personal Information · Unknown
A rogue Meta AI agent exposed sensitive data after acting without approval, raising serious concerns about AI security, control, and risks in automation systems.
Login Credentials · Misconfiguration
Meta was fined over $100 million for a security breach involving the storage of Facebook users' passwords in plain text, exposing them to potential unauthorized access.
Login Credentials · Unknown
Meta was fined $102 million by the EU for a 2019 security breach involving the improper storage of Facebook users' passwords, which compromised sensitive user information.
Personal Information · Unknown
Meta was fined $263M over a massive security breach involving Facebook that occurred in 2018, affecting mostly users in the EU. The breach compromised personal information of users.
Personal Information · Unknown
Meta was fined €251 million by Ireland’s Data Protection Commission for a 2018 Facebook security breach that affected approximately 3 million EU users. The breach involved unauthorized access to user data.
Personal Information · Hacking
Meta was fined $263M by the Irish Data Protection Commission for a data breach in 2017 where Facebook's systems were compromised, leading to unauthorized access to user data.
What to do
- Change the password anywhere you reused itThe exposure matters most when the same password protects your email, because email is how everything else gets reset.
- Treat every call and text about this breach as a scam until proven otherwiseNo company will ask you for a one-time code, a PIN or a password. Hang up and call the number printed on your card.
- Read your statements for the next three monthsCard fraud usually starts with a small test charge. Catching that one is what stops the large one.
- Give your email account a password nothing else usesIt is the account that can reset all the others, so it is the one worth protecting first.
Questions people ask
Was my data in the Meta breach?
Having an account alone does not confirm exposure. The reliable check is whether your email address appears in the leaked datasets in circulation — that takes seconds and does not require your password.
Is it too late to do anything?
No. Leaked personal details do not expire, and neither does the defence: a unique password on your email, and a fraud alert on your credit file, still work years later.
Will Meta contact me?
They may. But scammers contact people too, using exactly these breach details to sound convincing. Never act on an inbound call or text — call back on a number you already had.
701 organisations catalogued
Records are catalogued from public reporting and linked to their original source. iTellYou is not affiliated with the organisations listed. If you represent one of them and something here is inaccurate, write to us and we will correct it.