Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The largest breach-related amounts are not all the same kind of payment. Equifax’s 2019 U.S. settlement was a package of at least $575 million, potentially rising to $700 million; Meta’s 2024 €251 million penalty is a regulatory fine; and Marriott’s $52 million figure was a separate settlement with U.S. states. Comparing them requires looking at what each amount covers and whether it is final, proposed, or under appeal.

Largest reported data breach penalties and settlements

The cases below are notable, documented examples—not a definitive global ranking. There is no comparable official global list in the cited materials, and a settlement package cannot be ranked fairly against a regulatory fine without accounting for its components.

Amount What it represents Jurisdiction and authority Breach and affected population Status
$575 million, potentially up to $700 million Global settlement package, including consumer relief and other terms; not a single fine United States; FTC, CFPB, states and territories Equifax’s 2017 breach; approximately 147 million people Settlement announced in 2019
€251 million Administrative fines in four components Ireland/EU; Irish Data Protection Commission Facebook token breach in September 2018; approximately 29 million accounts globally, including approximately 3 million in the EU/EEA Decision dated 12 December 2024; listed as pending appeal when the regulator’s register was checked
$52 million Penalty settlement with 49 states and the District of Columbia United States; state authorities, announced by the FTC Marriott/Starwood data-security allegations involving multiple breaches Settlement announced in 2024
£14 million Agreed penalty United Kingdom; Information Commissioner’s Office Capita’s 2023 breach Final amount; Capita admitted liability and agreed not to appeal in 2025
£11,164,400 Penalty after a 30% settlement discount; pre-discount amount was £15,949,200 United Kingdom; Financial Conduct Authority Equifax Ltd and the 2017 breach FCA notice issued in 2023

What the largest amounts actually include

Equifax: a broad U.S. settlement, not a $700 million fine

For its 2017 breach affecting approximately 147 million people, Equifax agreed in 2019 to a global settlement with the FTC, CFPB, and states and territories. The FTC described the package as at least $575 million and potentially as much as $700 million. The CFPB specified that up to $425 million was for consumer relief. These are parts of the same package: do not add the consumer-relief figure to the headline total as if it were a separate penalty. FTC settlement announcement; CFPB announcement.

Meta/Facebook: €251 million, with an appeal caveat

On 12 December 2024, Ireland’s Data Protection Commission announced administrative fines totaling €251 million over the September 2018 Facebook token breach. The total comprised four fines: €8 million, €3 million, €130 million, and €110 million. The DPC said approximately 29 million accounts were affected worldwide, including approximately 3 million in the EU/EEA. Its fine register listed the penalty as pending appeal when checked, so the amount should not be presented as procedurally settled. DPC decision announcement.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Marriott: separate state penalties and an FTC order

The $52 million Marriott figure announced by the FTC in 2024 refers to a settlement with 49 states and the District of Columbia concerning data-security allegations involving multiple breaches. The FTC also announced its own separate order. That order requires security-program measures and includes data-minimization, deletion-request, and loyalty-account remedies; it is not part of the $52 million state penalty figure. FTC announcement.

Capita: a final £14 million agreed penalty

The ICO said in 2025 that Capita agreed to a final £14 million penalty connected to its 2023 breach. Capita admitted liability and agreed not to appeal, making this distinct from an initial notice of intent. ICO announcement.

Equifax UK: a separate penalty against a UK entity

The FCA’s 2023 notice records an £11,164,400 penalty against Equifax Ltd related to the 2017 breach, after a 30% settlement discount. The pre-discount figure was £15,949,200. This UK company penalty is separate from the U.S. Equifax settlement package; it is not another component of that package. FCA notice.

Why the $5 billion Facebook penalty is not on this breach list

The FTC’s 2019 $5 billion civil penalty against Facebook is often mentioned in discussions of technology-company penalties, but the cited DOJ and FTC materials describe it as a privacy case and enforcement of a prior privacy order—not as a fine for a data breach. It is therefore not comparable to the breach-specific cases above. FTC announcement; DOJ announcement.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to compare breach enforcement figures

Before treating one headline amount as “bigger” than another, check what the figure measures. A fine imposed by a regulator, a civil penalty, compensation for affected consumers, and a negotiated settlement package can all be reported in currency but represent different obligations.

  • Identify the payment type: Is the amount a regulatory fine, a civil penalty, consumer relief, or a package combining several kinds of relief?
  • Check the authority and jurisdiction: Separate national or state actions, and distinguish penalties against different corporate entities.
  • Read the procedural status: A proposed amount, final agreed penalty, or decision pending appeal should not be described as the same kind of outcome.
  • Keep non-monetary remedies separate: Orders can require security, data-minimization, deletion, or account-related changes without those remedies being included in a monetary figure.
  • Use the case’s own scope: An incident may involve multiple breaches or regions; affected people or accounts are not interchangeable measures.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.