WhatsApp Security Boss Lawsuit: Meta Culture Compared to Cult
- A lawsuit alleges significant data governance failures at WhatsApp, stemming from concerns raised by a former head of security.
- According too the lawsuit, Baig began escalating his concerns to increasingly senior leaders within Meta following his initial discovery of the problems.
- Baig's concerns, detailed in a "detailed letter" sent last year to Meta CEO Mark Zuckerberg and General Counsel Jennifer Newstead, outlined multiple shortcomings.
WhatsApp Data Governance Failures alleged in Whistleblower Lawsuit
Table of Contents
Background of the Allegations
A lawsuit alleges significant data governance failures at WhatsApp, stemming from concerns raised by a former head of security. The complaint states that these issues represent the “first concrete step toward addressing WhatsApp’s fundamental data governance Failures.” The whistleblower, whose name is not explicitly mentioned in the provided text but is identified as Mr.Baig, claims a deeply ingrained culture at Meta (WhatsApp’s parent company) stifles internal questioning of established practices, particularly those approved by senior leadership.
According too the lawsuit, Baig began escalating his concerns to increasingly senior leaders within Meta following his initial discovery of the problems.
Specific Data Security Shortcomings
Baig’s concerns, detailed in a “detailed letter” sent last year to Meta CEO Mark Zuckerberg and General Counsel Jennifer Newstead, outlined multiple shortcomings. These included improper access granted to engineers regarding WhatsApp user data, a failure to properly inventory user data as required by privacy laws in California, the European Union, and a 2019 Federal Trade Commission (FTC) settlement, and a lack of systems to monitor user data access. The complaint also alleges an inability to detect data breaches-a capability standard at other companies.
Furthermore, the letter reportedly alleged that Meta leaders were retaliating against Baig and that the central Meta security team had “falsified security reports to cover up decisions not to remediate data exfiltration risks.”
scale of Account Compromises and Data Scraping
The lawsuit, filed under the whistleblower protection provision of the Sarbanes-Oxley Act of 2002, claims that approximately 100,000 whatsapp user accounts were hacked daily in 2022. This number allegedly increased to as many as 400,000 accounts being locked due to takeovers each day by last year.
Baig also reportedly informed superiors about widespread data scraping on the platform. He stated that WhatsApp lacked standard protections found on other messaging apps like Signal and Apple messages. As a result, he estimated that around 400 million user profiles-including pictures and names-were improperly copied each day, frequently used for account impersonation scams.
Legal Context and Ongoing Implications
The allegations center on potential violations of the FTC settlement and Security and Exchange Commission rules regarding the reporting of security vulnerabilities. The lawsuit seeks protection under the Sarbanes-Oxley Act,designed to protect whistleblowers who report corporate wrongdoing. As of September 9, 2024, the status of the lawsuit and any response from Meta are pending further developments.
Related reading
- Capcom to Evolve RE Engine Into AI-Generation Tool via Project REX
- Intergenerational Bond Celebrated: La petite et le vieux in Granby
- Why the Social Security COLA Is Announced in October (daybreakwire.com)
- Trump’s top national security officials held a secret meeting at Camp David on Iran and Yemen (time.news)
