Technologytechnology

2018 saw 5 major breaches, 1B+ records exposed

Details of the major 2018 data breaches at Facebook, Marriott, British Airways, Google+, Quora, Exactis, MyFitnessPal, and Aadhaar, plus the effect of GDPR and the fines that followed.
data-breach-2018

2018 was the year data privacy moved from a compliance footnote to a boardroom liability. Eight major incidents exposed the personal information of more than two billion people across social media, hospitality, finance, and government databases. The EU's General Data Protection Regulation (GDPR) came into force on May 25, 2018, and the breaches that followed became the first test cases for its penalty regime. By 2019, the UK Information Commissioner's Office (ICO) had levied record fines against British Airways and Marriott International, and the US Federal Trade Commission (FTC) had imposed a penalty on Facebook that reached $5 billion, the ceiling set by the 2019 settlement. The incidents are historically concluded, but their consequences reshaped corporate data governance permanently.

The breaches shared a pattern: attackers exploited trust in large databases, often through third-party applications, misconfigured servers, or compromised payment systems. The scale of each intrusion forced regulators and consumers to confront how much data companies held and how poorly they protected it.

Mark Zuckerberg testifies before Congress 2018
Anurag R Dubey, Wikimedia Commons, CC BY-SA 4.0

The Facebook, Cambridge Analytica scandal: 87 million profiles harvested through a quiz app

A quiz app with friend-network access

In March 2018, Facebook disclosed that the data of up to 87 million users had been improperly shared with the political consulting firm Cambridge Analytica. The mechanism was straightforward. A researcher created a personality quiz app called "thisisyourdigitallife" that was installed by roughly 270,000 users. At the time, Facebook's platform permissions allowed the app to collect not only the quiz-taker's data but also the data of their entire friend network. That practice harvested tens of millions of profiles without explicit consent.

Psychological profiles and disputed effectiveness

The data included likes, friend lists, and other public profile information. Cambridge Analytica used that data to build psychological profiles that it claimed could predict voter behavior, though the effectiveness of those models was later disputed. The scandal triggered investigations on both sides of the Atlantic.

The $5 billion FTC settlement

In July 2019, the FTC fined Facebook $5 billion, the largest penalty ever imposed on a technology company for privacy violations at that point. Facebook also agreed to restructure its privacy oversight, creating a board-level privacy committee and submitting to independent audits.

Marriott International and the Starwood reservation system: 500 million guests exposed

Four years of undetected access

On November 30, 2018, Marriott International disclosed that its Starwood guest reservation database had been breached. The attackers had accessed the system since 2014, meaning unauthorized access persisted for four years before detection. The breach affected up to 500 million guests. For a large subset of them, the compromised data included name, mailing address, phone number, email address, passport number, date of birth, and in some cases encrypted payment card numbers. Marriott said the encryption keys for those payment cards might also have been taken.

Inherited risk from an acquisition

Marriott had acquired Starwood Hotels in 2016 and was in the process of merging the two reservation systems when the breach was discovered. The intrusion demonstrated the risk of inheriting legacy IT infrastructure during an acquisition.

A fine that fell from £99 million to £14.4 million

In July 2019, the ICO announced its intention to fine Marriott a headline figure of £99 million under GDPR for failing to secure the personal data of European guests. That penalty was later reduced to £14.4 million after Marriott argued that the breach occurred before GDPR took effect and that the company had taken corrective steps. The consumer version of the settlement involved a class-action payout of $52 million to US cardholders. For the most current penalty figures, consult the ICO's public register.

British Airways and the Magecart attack: 380,000 payment cards skimmed

JavaScript injected into the booking flow

In September 2018, British Airways disclosed a breach that compromised 380,000 card transactions. The attack was attributed to the Magecart group, a criminal network that specializes in injecting skimming code into online payment pages. The intruders inserted malicious JavaScript into the British Airways website and mobile app. When a customer entered their payment details on the booking page, the script copied the data and sent it to a server controlled by the intruders.

A vulnerability in third-party libraries

Magecart attacks were not new, but the British Airways intrusion was the largest and most visible example at the time. The criminals exploited a vulnerability in the third-party JavaScript libraries that the airline used to render its booking forms. The breach compromised cardholder names, billing addresses, email addresses, and the three-digit CVV codes printed on the back of cards.

From a record £183 million notice to a £20 million penalty

The ICO issued a notice of intent to fine British Airways £183 million under GDPR, which would have been the largest GDPR penalty to date. After a lengthy appeal, the final sum was reduced to £20 million in 2020. The ICO publishes its final enforcement notices; readers should check that register for the binding figure. The breach also led to a class-action lawsuit in the UK and the US that was settled for undisclosed terms.

Marriott International headquarters Bethesda
User:Moreau1, Wikimedia Commons, CC0

Google+ exposed 500,000 profiles and was shut down

A bug that stayed quiet

In October 2018, Google announced that a bug in its Google+ social network had revealed the private profile data of up to 500,000 users. The bug allowed third-party developers to access profile fields that users had set to private, including name, email address, occupation, and age. Google said it discovered the bug in March 2018 but chose not to disclose it immediately because it found no evidence that the data had been misused and because it feared regulatory attention.

Silence until The Wall Street Journal reported

The decision to withhold disclosure became public when The Wall Street Journal reported on the lapse. Google then announced that it would accelerate the shutdown of the consumer version of Google+, which was already planned due to low usage. The consumer platform was fully shut down in April 2019. Google also introduced stricter data access policies for its remaining APIs.

The real story: a calculus of risk

The episode was notable not for the number of users affected, which was relatively small compared to other 2018 breaches, but for what it revealed about Google's internal calculus: the company weighed reputational risk against legal disclosure obligations and chose silence until it was forced to speak.

Quora, Exactis, MyFitnessPal, and Aadhaar: breaches across every sector

Quora: private actions laid bare

In December 2018, Quora disclosed a breach affecting approximately 100 million users. The intruders accessed account information including names, email addresses, encrypted passwords, and data from linked social networks. More concerning was that the breach also compromised private actions such as upvotes, downvotes, and direct messages. Quora said it had detected the intrusion and forced a password reset for all affected accounts.

Exactis: 340 million profiles on an open server

In June 2018, Exactis, a marketing and data aggregation firm, left a database containing nearly 340 million individual records on a publicly accessible server. The database included detailed personal profiles with phone numbers, email addresses, home addresses, and information about each individual's interests, family structure, and purchasing habits. The exposure did not involve financial data or passwords, but the depth of the profiles made it valuable for social engineering attacks.

MyFitnessPal and Aadhaar: fitness apps to national ID

Under Armour disclosed in March 2018 that its MyFitnessPal app had been breached, affecting 150 million user accounts. The intruders accessed usernames, email addresses, and hashed passwords. In India, the Aadhaar database, which contains the biometric and demographic data of over 1.1 billion citizens, was reported to have suffered unauthorized access. The Unique Identification Authority of India disputed some of the claims, but the episode raised fundamental questions about the security of large-scale national identity systems.

GDPR enforcement and the lasting shift in data governance

The 72-hour clock and the 4 percent ceiling

The EU's General Data Protection Regulation came into force on May 25, 2018. Its key requirement for breach notification was immediate: companies had 72 hours to notify the relevant supervisory authority after becoming aware of a breach. That timeline forced organizations to build incident response capabilities that most did not have. The British Airways and Marriott fines, though later reduced, established that regulators were willing to use the maximum penalty provisions of GDPR, which allow fines of up to 4 percent of global annual turnover.

New laws spread beyond Europe

The 2018 breaches accelerated the adoption of stricter data privacy laws around the world. California passed the California Consumer Privacy Act (CCPA) in 2018, which took effect in 2020. Brazil enacted the Lei Geral de Proteção de Dados (LGPD) in 2018. India began work on its Personal Data Protection Bill.

The end of collect-everything

Corporate data governance practices changed fundamentally. Companies began mapping their data flows, limiting the retention of personal information, and auditing third-party access to their systems. The era of collecting everything and asking questions later ended in 2018, not because companies became more ethical, but because the cost of getting caught became too high.

Key facts about the 2018 data breaches

  • Largest fine imposed: $5 billion (FTC against Facebook, 2019)
  • Largest GDPR fine announced: £183 million (ICO against British Airways, later reduced to £20 million)
  • Largest number of people affected by a single breach: 500 million (Marriott Starwood)
  • Largest number of records exposed in a single incident: 1.1 billion (Aadhaar)
  • Date GDPR came into force: May 25, 2018
  • GDPR breach notification deadline: 72 hours after discovery
  • Date Google+ consumer platform shut down: April 2019

About the author

, Editor

Kenneth Ma is the editor of LeadMonitor.ai, covering the companies, deals and policy decisions shaping business and technology markets.

View all 427 articles by Kenneth Ma  ·  Our editorial policy

Recent Stories

How to make money selling Canva templates

How to highlight text in Canva

How to print from Canva without quality loss

How to check if Canva is down right now

How to group and ungroup elements in Canva

How to stretch an image in Canva

How to make a QR code in Canva

Convert Canva to PowerPoint and Google Slides