TheJakartaPost

Please Update your browser

Your browser is out of date, and may not be compatible with our website. A list of the most popular web browsers can be found below.
Just click on the icons to get to the download page.

Jakarta Post

Ex-WhatsApp executive sues Meta over alleged security failures

Attaullah Baig, who served as head of security for WhatsApp from 2021 to 2025, claims that approximately 1,500 engineers had unrestricted access to user data without proper oversight, potentially violating a 2020 US government order that imposed a $5 billion penalty on the company.

News Desk (AFP)
Washington
Tue, September 9, 2025 Published on Sep. 9, 2025 Published on 2025-09-09T12:05:16+07:00

Change text size

Gift Premium Articles
to Anyone

Share the best of The Jakarta Post with friends, family, or colleagues. As a subscriber, you can gift 3 to 5 articles each month that anyone can read—no subscription needed!
Facebook, Whatsapp and Instagram logos are displayed through broken glass in this illustration taken October 4, 2021. Facebook, Whatsapp and Instagram logos are displayed through broken glass in this illustration taken October 4, 2021. (Reuters/Dado Ruvic/Illustration)

A

former top security executive at WhatsApp filed a federal lawsuit Monday alleging that parent company Meta systematically violated cybersecurity regulations and retaliated against him for reporting the failures.

Attaullah Baig, who served as head of security for WhatsApp from 2021 to 2025, claims that approximately 1,500 engineers had unrestricted access to user data without proper oversight, potentially violating a 2020 US government order that imposed a $5 billion penalty on the company.

The lawsuit, filed in federal court in San Francisco, alleges that Meta failed to implement basic cybersecurity measures, including adequate data handling and breach detection capabilities.

.

From The Weekender

Turning Jakarta’s overlooked sidewalks into common ground

In a city built for cars, sidewalks often feel like an afterthought. But revitalized stretches in Jakarta are proving that these in-between spaces have the power to shape not just how we move, but how we connect and belong.

Read on The Weekender

According to the 115-page complaint, Baig discovered through internal security testing that WhatsApp engineers could "move or steal user data" -- including contact information, IP addresses, and profile photos -- "without detection or audit trail."

The filing claims Baig repeatedly raised concerns with senior executives, including WhatsApp head Will Cathcart and Meta CEO Mark Zuckerberg.

Baig alleges he faced escalating retaliation after his initial reports in 2021, including negative performance reviews, verbal warnings, and ultimately termination in February 2025 for alleged "poor performance."

The lawsuit also claims Meta blocked implementation of security features intended to address account takeovers affecting an estimated 100,000 WhatsApp users daily, choosing instead to prioritize user growth.

Meta strongly disputed the allegations.

"Sadly, this is a familiar playbook in which a former employee is dismissed for poor performance and then goes public with distorted claims that misrepresent the ongoing hard work of our team," Carl Woog, vice president of communications at WhatsApp, told AFP in a statement.

"Security is an adversarial space, and we pride ourselves on building on our strong record of protecting people's privacy," Woog added.

The company said Baig left due to poor performance, with multiple senior engineers independently validating that his work was below expectations.

Meta also noted that the Department of Labor's Occupational Safety and Health Administration dismissed Baig's initial complaint, finding that Meta had not retaliated against him.

The company further insisted that Baig's self-description as head of security was an exaggeration of his role at WhatsApp, and that he was a lower-level engineer.

Prior to joining Meta, Baig worked in cybersecurity roles at PayPal, Capital One, and other major financial institutions. 

The case adds to ongoing scrutiny of Meta's data protection practices across its platforms -- Facebook, Instagram, and WhatsApp -- which serve billions of users globally.

Meta agreed to the 2020 government settlement following the Cambridge Analytica scandal, which involved improper harvesting of data from 50 million Facebook users. The consent order remains in effect until 2040.

In his whistleblower complaint, Baig is requesting reinstatement, back pay, and compensatory damages, along with potential regulatory enforcement action against the company.

In a separate case targeting Meta first reported by the Washington Post on Monday, current and former employees allege the company suppressed research on child safety risks in its virtual reality products.

Meta denies these claims, stating it prioritizes youth safety and complies with privacy laws.

 

Your Opinion Matters

Share your experiences, suggestions, and any issues you've encountered on The Jakarta Post. We're here to listen.

Enter at least 30 characters
0 / 30

Thank You

Thank you for sharing your thoughts. We appreciate your feedback.

Share options

Quickly share this news with your network—keep everyone informed with just a single click!

Change text size options

Customize your reading experience by adjusting the text size to small, medium, or large—find what’s most comfortable for you.

Gift Premium Articles
to Anyone

Share the best of The Jakarta Post with friends, family, or colleagues. As a subscriber, you can gift 3 to 5 articles each month that anyone can read—no subscription needed!

Continue in the app

Get the best experience—faster access, exclusive features, and a seamless way to stay updated.