Space Industry and Business News
CYBER WARS
Ex-WhatsApp executive sues Meta over alleged security failures
Ex-WhatsApp executive sues Meta over alleged security failures
by AFP Staff Writers
San Francisco, United States (AFP) Sept 8, 2025

A former top security executive at WhatsApp filed a federal lawsuit Monday alleging that parent company Meta systematically violated cybersecurity regulations and retaliated against him for reporting the failures.

Attaullah Baig, who served as head of security for WhatsApp from 2021 to 2025, claims that approximately 1,500 engineers had unrestricted access to user data without proper oversight, potentially violating a 2020 US government order that imposed a $5 billion penalty on the company.

The lawsuit, filed in federal court in San Francisco, alleges that Meta failed to implement basic cybersecurity measures, including adequate data handling and breach detection capabilities.

According to the 115-page complaint, Baig discovered through internal security testing that WhatsApp engineers could "move or steal user data" -- including contact information, IP addresses, and profile photos -- "without detection or audit trail."

The filing claims Baig repeatedly raised concerns with senior executives, including WhatsApp head Will Cathcart and Meta CEO Mark Zuckerberg.

Baig alleges he faced escalating retaliation after his initial reports in 2021, including negative performance reviews, verbal warnings, and ultimately termination in February 2025 for alleged "poor performance."

The lawsuit also claims Meta blocked implementation of security features intended to address account takeovers affecting an estimated 100,000 WhatsApp users daily, choosing instead to prioritize user growth.

Meta strongly disputed the allegations.

"Sadly, this is a familiar playbook in which a former employee is dismissed for poor performance and then goes public with distorted claims that misrepresent the ongoing hard work of our team," Carl Woog, vice president of communications at WhatsApp, told AFP in a statement.

"Security is an adversarial space, and we pride ourselves on building on our strong record of protecting people's privacy," Woog added.

The company said Baig left due to poor performance, with multiple senior engineers independently validating that his work was below expectations.

Meta also noted that the Department of Labor's Occupational Safety and Health Administration dismissed Baig's initial complaint, finding that Meta had not retaliated against him.

The company further insisted that Baig's self-description as head of security was an exaggeration of his role at WhatsApp, and that he was a lower-level engineer.

Prior to joining Meta, Baig worked in cybersecurity roles at PayPal, Capital One, and other major financial institutions.

The case adds to ongoing scrutiny of Meta's data protection practices across its platforms -- Facebook, Instagram, and WhatsApp -- which serve billions of users globally.

Meta agreed to the 2020 government settlement following the Cambridge Analytica scandal, which involved improper harvesting of data from 50 million Facebook users. The consent order remains in effect until 2040.

In his whistleblower complaint, Baig is requesting reinstatement, back pay, and compensatory damages, along with potential regulatory enforcement action against the company.

In a separate case targeting Meta first reported by the Washington Post on Monday, current and former employees allege the company suppressed research on child safety risks in its virtual reality products.

Meta denies these claims, stating it prioritizes youth safety and complies with privacy laws.

Related Links
Cyberwar - Internet Security News - Systems and Policy Issues

Subscribe Free To Our Daily Newsletters
Tweet

RELATED CONTENT
The following news reports may link to other Space Media Network websites.
CYBER WARS
Far-right German MP denies knowing ex-aide allegedly spied for China
Dresden, Germany (AFP) Sept 3, 2025
Far-right German politician Maximilian Krah denied in court Wednesday having any knowledge of an aide's alleged espionage for China. Giving evidence at the Higher Regional Court in Dresden, Alternative for Germany (AfD) lawmaker Krah said he first learned from media that a former staffer from his previous role as a member of the European Parliament, Jian Guo, was suspected of spying. "At no time was I warned by any public authority, whether from the Federal Republic (of Germany) or the EU, of an ... read more

CYBER WARS
Loft Federal wins NASA task order for fault tolerant RISC V flight computer

SwRI advances laser driven testing for ballistic resistance

Europe bets on supercomputer to catch up in AI race

Engineering fantasy into reality

CYBER WARS
Gilat wins $7 million US defense contract for transportable SATCOM systems

York delivers full 21 satellite payload for Space Development Agency Tranche 1 launch

Globalstar strengthens defense reach with resilient satellite and 5G solutions

Space Force taps five firms to develop secure global tactical satcom solutions

CYBER WARS
CYBER WARS
USGS introduces first fully integrated national geologic map

Galileo daughter mission named Celeste to strengthen navigation resilience

Real time navigation breakthrough with new algorithm OiSAM FGO

Iranians struggle with GPS disruption after Israel war

CYBER WARS
Ground vibration test validates structural models for UpLift research aircraft

Norway experiments with electric plane in real-life test

Polish F-16 jet crashes killing pilot ahead of air show: govt

German defence minister ups pressure on France over jet project

CYBER WARS
Graphene reveals light tuned quantum states pointing to new electronics

US limits TSMC chipmaking tool shipments to China

Rice research team on quest to engineer computing systems from living cells

Autonomous robot lab accelerates search for advanced quantum dots

CYBER WARS
Global study maps regions most threatened by ocean plastic pollution

Pixxel expands Firefly fleet advancing global hyperspectral satellite imaging

Metop SGA1 begins delivering atmospheric data weeks after launch

Spire wins NOAA pair of satellite weather data contracts totaling 13.7 million

CYBER WARS
Wildfires producing 'witches' brew' of air pollution: UN

No-sort plastic recycling is near

South Australia bans plastic fish-shaped soy sauce containers

Smog then floods: Pakistani families 'can't catch a break'

Subscribe Free To Our Daily Newsletters




The content herein, unless otherwise known to be public domain, are Copyright 1995-2024 - Space Media Network. All websites are published in Australia and are solely subject to Australian law and governed by Fair Use principals for news reporting and research purposes. AFP, UPI and IANS news wire stories are copyright Agence France-Presse, United Press International and Indo-Asia News Service. ESA news reports are copyright European Space Agency. All NASA sourced material is public domain. Additional copyrights may apply in whole or part to other bona fide parties. All articles labeled "by Staff Writers" include reports supplied to Space Media Network by industry news wires, PR agencies, corporate press officers and the like. Such articles are individually curated and edited by Space Media Network staff on the basis of the report's information value to our industry and professional readership. Advertising does not imply endorsement, agreement or approval of any opinions, statements or information provided by Space Media Network on any Web page published or hosted by Space Media Network. General Data Protection Regulation (GDPR) Statement Our advertisers use various cookies and the like to deliver the best ad banner available at one time. All network advertising suppliers have GDPR policies (Legitimate Interest) that conform with EU regulations for data collection. By using our websites you consent to cookie based advertising. If you do not agree with this then you must stop using the websites from May 25, 2018. Privacy Statement. Additional information can be found here at About Us.