Earlier quoted context omitted.
That is not the only thing you can get fined for under GDPR.
I’m fairly knowledgeable in the GDPR and I’m legitimately curious what you think the fine basis would be related to this breach.
1) https://news.ycombinator.com/item?id=18203002
This comment suggests that they discovered the vulnerability and spent two days working out how to fix it, whilst leaving the site live for exploitation.
2) Did they report the breach in a timely manner. That is not clear to me yet
3) Until a detailed analysis is done we don't know if there was anything negligent about this.
4) If in other investigations into Facebook it is found that Facebook were storing data they had no right to, and it transpired that they had lost some in this attack, they would be culpable because they shouldn't have had the data to lose.
So nothing specific, but lots of maybees