The staff member is said to have developed a programme which allowed him to circumvent Meta’s internal security controls to access and download users images.
The Metropolitan Police Cybercrime unit has launched an investigation into the incident which is being termed a mass invasion of Facebook users’ privacy. Speaking about the case, Meta confirmed they were made aware of the situation over a year ago and the employee was dismissed. Upon learning about the alleged breach, Meta notified the police themselves and is cooperating with their investigations.
A Meta spokesperson commented: “Protecting user data is our top priority.
“After discovering improper access by an employee over a year ago, we immediately terminated the individual, notified users, referred the matter to law enforcement and enhanced our security measures”.
A spokesperson for the Information Commissioner’s Office (ICO) said: “We are aware of this incident.
“The ICO regularly engages with social media platforms, including Meta, regarding approaches to data protection to ensure that users rights and freedoms are being upheld.
“Social media users should be able to trust that their personal information is handled responsibly”.
Social media companies are under increasing pressure as governments enforce new legislation to clean up digital platforms. New age controls, identity verification and the banning of certain explicit content are amongst updates social media companies have enforced, or are likely to have to enforce in the near future.
Meta is amongst the digital channels that have recently been found liable in a childhood social media addiction trial, a case which will have widespread implications on how social media platforms operate moving forward.
Recommended reading
- Takes Aim at TikTok’s “Addictive” Design
- Jurors Yet to Decide on Addictive-by-design Social Media Lawsuit
- Meta Liable for $375M In New Mexico Child Exploitation Lawsuit
Whilst most recent updates have focused on external user behaviour or industry-wide practice, this case is a pertinent reminder of the need for strong internal security controls to safeguard against internal threats too.





