Ex-WhatsApp security chief sues Meta, alleges unauthorized engineer access to billions of users' data
By
mdhb
Hand-rolled, kettle-boiled, baked to perfection. Worth every minute at the bakery.
Summary
A former top cybersecurity executive at WhatsApp, Attaullah Baig, has filed a lawsuit alleging that parent company Meta systematically disregarded internal security flaws, exposed billions of users to data breaches, and violated cybersecurity regulations. Baig, who served as head of security from 2021 to 2025, claims approximately 1,500 engineers had unrestricted access to user data without proper oversight, potentially violating a US government consent order that imposed a $5bn penalty on Meta. He alleges he was fired in retaliation for reporting these failures to CEO Mark Zuckerberg.
Key quotes
· 3 pulledA former top cybersecurity executive at WhatsApp filed a lawsuit on Monday alleging that parent company Meta disregarded internal flaws in the app's digital defenses and exposed billions of its users.
He says the company systematically violated cybersecurity regulations and retaliated against him for reporting the failures.
Attaullah Baig, who served as the head of security for WhatsApp from 2021 to 2025, claims that approximately 1,500 engineers had unrestricted access to user data without proper oversight
You might also wanna read
Google Engineer Charged With Insider Trading Using Confidential Data for $1.2M in Prediction Market Profits
A Google software engineer, Michele Spagnuolo (known online as "AlphaRaccoon"), has been charged by U.S. authorities for allegedly using con
cybersecuritynews.com·3d ago23andMe Data Breach Class Action Settlement Reached for 6.4 Million Affected Customers
A class action settlement has been reached with 23andMe (now Chrome) regarding a 2023 data breach that affected approximately 6.4 million U.
Edmunds Data Breach: 178,000 Records Exposed by ShinyHunters Hacking Group
In January 2026, the automotive research and car-shopping platform Edmunds was breached by the ShinyHunters hacking group. The compromised d
Google Ads to require passkeys for sensitive account actions starting July 15, 2026
Google Ads will mandate passkeys for sensitive account actions starting July 15, 2026, replacing traditional passwords with biometric or dev
Airbnb Host Sues Bot Company Over Alleged Unauthorized Robot Testing in Rental Property
San Francisco Airbnb host Sean Donovan has filed a lawsuit against Bot Company (Bot.co) alleging the startup used his rental property to con
DORA regulation creates compliance challenges for London law firms beyond GDPR requirements
The article discusses how the Digital Operational Resilience Act (DORA), which took full effect in January 2025, is impacting London law fir
