Facebook Faces Billions In Penalties After Jury Verdict
September 29, 2026Read also: TikTok agrees to pay a £12.7M fine over children’s data; Labcorp fined $2.3M after a data breach; and more.

New Mexico jury finds Facebook made misleading privacy claims
A jury in New Mexico, the US, has found Facebook liable for misleading users about its privacy protections and data-sharing practices. The jury found more than 43.8 million violations of the state’s consumer protection law. Each willful violation could carry a fine of up to $5,000, but the final penalty will be decided at a later date.
According to the New Mexico Department of Justice, the state is seeking the maximum penalty. Authorities also want Meta, Facebook’s parent company, to correct past statements and review how it handles user data.
The case stems from the Cambridge Analytica scandal, in which data from about 87 million Facebook profiles was collected through a third-party app and used for targeted advertising.
The jury found that Facebook made misleading statements about how users controlled their data, whether their information was shared with advertisers, and how the company handled third-party apps. It also found deceptive statements about misinformation, hate speech and the enforcement of Facebook’s content rules.
The final amount Facebook may have to pay has not yet been decided. With more than 43 million violations, the potential penalty could reach billions of dollars.
Labcorp fined $2.3M after a data breach impacted 10.2 million customers
One of the largest clinical lab providers Labcorp (Laboratory Corporation of America) has agreed to improve its data security practices and pay a $2.3 million fine following a 2019 data breach that affected 10.2 million customers.
Authorities said that the US-based company should have done more to oversee the security practices of the American Medical Collection Agency (AMCA), a debt collector that worked with Labcorp. The AMCA breach affected 27.5 million people nationwide.
Under the settlement, Labcorp must create a plan for responding to security problems involving vendors and limit the amount of customer data it shares with them. The company must also expand its vendor risk management program and require cybersecurity standards in vendor contracts.
Vendors will have to provide regular audits showing that they are following the new security rules. Labcorp must also hire an independent expert to assess its information security practices.
The company is also required to separate data that debt collectors may otherwise combine across multiple clients, reducing the amount of information available in a single system.
TikTok accepts a £12.7 million UK fine over children’s data
TikTok has agreed to pay a £12.7 million (about €14.77 million) fine in the UK after withdrawing its appeal against a penalty issued by the Information Commissioner’s Office (ICO) in 2023.
The ICO fined TikTok over concerns about how it handled children’s data. The regulator estimated that around 1.75 million UK children under 13 used TikTok in 2020, despite the platform’s rules banning children under that age from creating accounts.
The ICO said TikTok did not have strong enough age checks to stop underage children from joining. The watchdog also found that users were not given enough information about how their data was being used and that TikTok failed to get parental consent when it should have.
TikTok has also withdrawn its appeal against a separate ICO request for information about how the platform uses the data of 13- to 17-year-olds in its recommendation systems. The investigation began in February 2025.
The decision comes after a legal ruling in August in which the Upper Tribunal rejected TikTok’s argument that its use of personal data was protected for artistic purposes. Following the ruling, TikTok dropped both appeals and accepted the £12.7 million fine.
Tabcorp fined $350,000 over MFA failure
Australia’s largest gambling and wagering company Tabcorp has been fined A$350,000 (about €216,000) for failing to fully implement mandatory multi-factor authentication (MFA) controls to protect customer wagering accounts.
The Victorian Gambling and Casino Control Commission (VGCCC) found that Tabcorp failed to comply with four wagering and betting technical standards between 30 January and 23 June 2025.
During the period, some customer accounts were breached, resulting in the theft of money. The VGCCC said the lack of full MFA implementation left Tabcorp’s wagering and betting system vulnerable.
Tabcorp told the VGCCC that full MFA implementation was completed in June 2025, including an upgrade to a version of the TAB app with MFA. Affected customers have since been reimbursed.
Snap faces €250,000 fines over My AI ad data
A German court has ordered Snap Group Limited, the company behind Snapchat in Germany, to stop using data from its My AI chatbot for advertising without a legal basis.
The Regional Court of Cologne issued the ruling on September 17, 2026, after a lawsuit by Germany's Federation of German Consumer Organisations (vzbv). The court also banned Snapchat from using pre-ticked boxes to obtain advertising consent.
The ruling forbids Snapchat to automatically select alcohol and gambling as advertising topics for users under 18. If Snap breaks any of the three orders, the company could face a fine of up to €250,000 for each violation. The court also allowed for up to six months of coercive detention against members of the company's board as an alternative.
Snap was additionally ordered to repay €242.99 in warning costs, plus interest, and to cover the legal costs of the case.
What’s next:
- Request a free product demo or pricing
- Register for our webinars and product trainings
- Read our Cybercrime Investigations weekly blog
- Follow us on LinkedIn, X, Telegram and WhatsApp
- Subscribe to our Newsletter
- Join our Partner Program