Moneycontrol PRO
HomeTechnologyEx-Meta security head alleges major security flaws in WhatsApp, sues the company

Ex-Meta security head alleges major security flaws in WhatsApp, sues the company

The lawsuit, filed in the US District Court for the Northern District of California, comes from Attaullah Baig, WhatsApp’s former head of security. Baig claims that upon joining in 2021, he uncovered flaws that violated US securities laws and a 2020 Federal Trade Commission privacy settlement.

September 09, 2025 / 07:54 IST
WhatsApp

Meta is facing a fresh legal battle after a former WhatsApp executive alleged that the messaging app suffers from “systemic cybersecurity failures” that could compromise user privacy.

The lawsuit, filed in the US District Court for the Northern District of California, comes from Attaullah Baig, WhatsApp’s former head of security. Baig claims that upon joining in 2021, he uncovered flaws that violated US securities laws and a 2020 Federal Trade Commission privacy settlement. Among his allegations: roughly 1,500 WhatsApp engineers had unrestricted access to sensitive user data without audit trails, leaving room for potential misuse or theft.

Baig alleges that after raising these issues with top executives — including CEO Mark Zuckerberg — he faced retaliation. Within days of his first disclosure, he says he began receiving negative performance reviews. By late 2023, he had filed complaints with the SEC and OSHA, accusing Meta of both compliance failures and retaliation. Meta terminated Baig in February 2024, citing “poor performance” during a wave of layoffs affecting 5% of staff.

What does Meta have to say?

In its response, Meta strongly denied the claims, calling Baig’s role minor and his allegations “distorted.” A spokesperson said: “Security is an adversarial space, and we pride ourselves in building on our strong record of protecting people’s privacy.”

Baig, now represented by whistleblower group Psst.org and the law firm Schonbrun, Seplow, Harris, Hoffman and Zeldes, insists his termination was directly linked to his disclosures. The suit doesn’t allege that any user data was stolen but highlights lapses such as the lack of a 24-hour security operations center and poor monitoring of data access.

The case adds to ongoing scrutiny over Meta’s handling of privacy and compliance as regulators worldwide tighten oversight of tech giants.

 

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

MC Tech Desk Read the latest and trending tech news—stay updated on AI, gadgets, cybersecurity, software updates, smartphones, blockchain, space tech, and the future of innovation.
first published: Sep 9, 2025 07:53 am

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347