1) Prompting users to give Facebook their email passwords.[0]
2) Using that email access to "inadvertently" upload the information of their email contacts.[1]
3) Storing said passwords and others in plaintext. [2]
It's pretty impressive that a company could do something so brazenly malevolent and be confident that they will escape with no more than a fine.
[0] https://www.thedailybeast.com/beyond-sketchy-facebook-demand...
[1] https://www.theguardian.com/technology/2019/apr/18/facebook-...
[2] https://krebsonsecurity.com/2019/03/facebook-stored-hundreds...