The largest breach-related amounts are not all the same kind of payment. Equifax’s 2019 U.S. settlement was a package of at least $575 million, potentially rising to $700 million; Meta’s 2024 €251 million penalty is a regulatory fine; and Marriott’s $52 million figure was a separate settlement with U.S. states. Comparing them requires looking at what each amount covers and whether it is final, proposed, or under appeal.
Largest reported data breach penalties and settlements
The cases below are notable, documented examples—not a definitive global ranking. There is no comparable official global list in the cited materials, and a settlement package cannot be ranked fairly against a regulatory fine without accounting for its components.
| Amount | What it represents | Jurisdiction and authority | Breach and affected population | Status |
|---|---|---|---|---|
| $575 million, potentially up to $700 million | Global settlement package, including consumer relief and other terms; not a single fine | United States; FTC, CFPB, states and territories | Equifax’s 2017 breach; approximately 147 million people | Settlement announced in 2019 |
| €251 million | Administrative fines in four components | Ireland/EU; Irish Data Protection Commission | Facebook token breach in September 2018; approximately 29 million accounts globally, including approximately 3 million in the EU/EEA | Decision dated 12 December 2024; listed as pending appeal when the regulator’s register was checked |
| $52 million | Penalty settlement with 49 states and the District of Columbia | United States; state authorities, announced by the FTC | Marriott/Starwood data-security allegations involving multiple breaches | Settlement announced in 2024 |
| £14 million | Agreed penalty | United Kingdom; Information Commissioner’s Office | Capita’s 2023 breach | Final amount; Capita admitted liability and agreed not to appeal in 2025 |
| £11,164,400 | Penalty after a 30% settlement discount; pre-discount amount was £15,949,200 | United Kingdom; Financial Conduct Authority | Equifax Ltd and the 2017 breach | FCA notice issued in 2023 |
What the largest amounts actually include
Equifax: a broad U.S. settlement, not a $700 million fine
For its 2017 breach affecting approximately 147 million people, Equifax agreed in 2019 to a global settlement with the FTC, CFPB, and states and territories. The FTC described the package as at least $575 million and potentially as much as $700 million. The CFPB specified that up to $425 million was for consumer relief. These are parts of the same package: do not add the consumer-relief figure to the headline total as if it were a separate penalty. FTC settlement announcement; CFPB announcement.
Meta/Facebook: €251 million, with an appeal caveat
On 12 December 2024, Ireland’s Data Protection Commission announced administrative fines totaling €251 million over the September 2018 Facebook token breach. The total comprised four fines: €8 million, €3 million, €130 million, and €110 million. The DPC said approximately 29 million accounts were affected worldwide, including approximately 3 million in the EU/EEA. Its fine register listed the penalty as pending appeal when checked, so the amount should not be presented as procedurally settled. DPC decision announcement.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
Marriott: separate state penalties and an FTC order
The $52 million Marriott figure announced by the FTC in 2024 refers to a settlement with 49 states and the District of Columbia concerning data-security allegations involving multiple breaches. The FTC also announced its own separate order. That order requires security-program measures and includes data-minimization, deletion-request, and loyalty-account remedies; it is not part of the $52 million state penalty figure. FTC announcement.
Capita: a final £14 million agreed penalty
The ICO said in 2025 that Capita agreed to a final £14 million penalty connected to its 2023 breach. Capita admitted liability and agreed not to appeal, making this distinct from an initial notice of intent. ICO announcement.
Equifax UK: a separate penalty against a UK entity
The FCA’s 2023 notice records an £11,164,400 penalty against Equifax Ltd related to the 2017 breach, after a 30% settlement discount. The pre-discount figure was £15,949,200. This UK company penalty is separate from the U.S. Equifax settlement package; it is not another component of that package. FCA notice.
Why the $5 billion Facebook penalty is not on this breach list
The FTC’s 2019 $5 billion civil penalty against Facebook is often mentioned in discussions of technology-company penalties, but the cited DOJ and FTC materials describe it as a privacy case and enforcement of a prior privacy order—not as a fine for a data breach. It is therefore not comparable to the breach-specific cases above. FTC announcement; DOJ announcement.
How to compare breach enforcement figures
Before treating one headline amount as “bigger” than another, check what the figure measures. A fine imposed by a regulator, a civil penalty, compensation for affected consumers, and a negotiated settlement package can all be reported in currency but represent different obligations.
Quick Recap
Best Value
- Identify the payment type: Is the amount a regulatory fine, a civil penalty, consumer relief, or a package combining several kinds of relief?
- Check the authority and jurisdiction: Separate national or state actions, and distinguish penalties against different corporate entities.
- Read the procedural status: A proposed amount, final agreed penalty, or decision pending appeal should not be described as the same kind of outcome.
- Keep non-monetary remedies separate: Orders can require security, data-minimization, deletion, or account-related changes without those remedies being included in a monetary figure.
- Use the case’s own scope: An incident may involve multiple breaches or regions; affected people or accounts are not interchangeable measures.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

