Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert & block trade
Convert crypto with one click and zero fees
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
Ex-WhatsApp security chief files suit over privacy failures at Meta

Ex-WhatsApp security chief files suit over privacy failures at Meta

CryptopolitanCryptopolitan2025/09/09 04:00
By:By Nellius Irene

Share link:In this post: A former WhatsApp security chief is suing Meta, claiming he was punished after reporting privacy risks. He says 1,500 engineers had open access to user data and that WhatsApp lacked basic security measures. Meta denies the claims and says he was fired for poor performance, not retaliation.

A former Meta employee has filed a lawsuit accusing the company of allowing “systemic cybersecurity failures” at WhatsApp that put user privacy at risk.

The complaint, filed Monday in U.S. District Court for the Northern District of California, comes from Attaullah Baig, WhatsApp’s former head of security. Baig alleges Meta retaliated against him after he raised concerns, including those directly to CEO Mark Zuckerberg, about serious flaws in the messaging app.

Ex-WhatsApp security chief claims Meta ignored privacy risks

The lawsuit, filed in U.S. District Court for the Northern District of California, alleges that after joining WhatsApp in 2021, Baig uncovered security flaws that breached federal securities laws and Meta’s obligations under a 2020 Federal Trade Commission (FTC) privacy settlement .

The case emerges against the backdrop of Meta’s broader legal battles, including its recent request for a U.S. federal judge to dismiss the FTC’s antitrust suit. That case accuses Meta of unlawfully consolidating power in the social media market by acquiring Instagram and WhatsApp.

In its defence, Meta argues the FTC has failed to provide sufficient evidence that the deals were anticompetitive or harmful to consumers. The company contends that Instagram and WhatsApp have thrived under its ownership, benefiting from significant investments, improved security, and enhanced features. As earlier reported by Cryptopolitan , Meta also rejects the FTC’s narrow market definition, pointing out that platforms like TikTok, YouTube, and Reddit compete directly for users’ attention.

See also Nvidia chips still wanted by Chinese AI firms despite Beijing pressure

In the current case, Baig claimed that in a security test with Meta’s central team, he found that about 1,500 WhatsApp engineers had unrestricted access to sensitive user data and could move or steal it without detection or audit logs. Meta disputed Baig’s allegations in a statement and sought to downplay his position and responsibilities.

“Sadly this is a familiar playbook in which a former employee is dismissed for poor performance and then goes public with distorted claims that misrepresent the ongoing hard work of our team,” the spokesperson wrote. “Security is an adversarial space, and we pride ourselves in building on our strong record of protecting people’s privacy.”

Whistleblower group Psst.org represents Baig alongside the law firm Schonbrun, Seplow, Harris, Hoffman & Zeldes.  While the lawsuit does not allege that user data was directly compromised, it claims Baig repeatedly warned his superiors that WhatsApp’s cybersecurity shortcomings created serious regulatory compliance risks.

The issues cited are the platform’s lack of a 24-hour security operations center appropriate for its size, inadequate systems to track employee access to user data, and the absence of a comprehensive inventory of data-storing systems, making proper protection and regulatory disclosure impossible.

Baig’s attorneys argue in the lawsuit that his superiors repeatedly criticized his work and that he began receiving “negative performance feedback” just three days after his initial cybersecurity disclosure.

See also Tesla proposes $1 trillion pay to Musk expanding his voting power

Late last year, Baig informed the SEC of the alleged “cybersecurity deficiencies and failure to inform investors about material cybersecurity risks,” the suit says. A month later, Baig sent Zuckerberg the second of two letters, informing the CEO that he “had filed the SEC complaint” and was “requesting immediate action to address both the underlying compliance failures and the unlawful retaliation.”

Meta denies allegations, calling the lawsuit a “distorted” attack on its record

In January, according to the lawsuit, Baig filed a complaint with the Occupational Safety and Health Administration, noting “the systemic retaliation” he alleged he received after the security disclosures.

The next month, the complaint says Meta dismissed Baig, citing “poor performance”. This occurred during the company’s February layoffs, which affected 5% of its workforce.

The lawsuit argues that the timing and circumstances of Baig’s termination show a clear link to his protected activity. It came soon after his external regulatory filings, capping over two years of alleged systemic retaliation over his cybersecurity disclosures and pushing for compliance with federal law and regulatory orders.

Baig’s attorneys said he filed a notice on Monday to move his SEC-related claims to federal court and had already exhausted all administrative remedies before pursuing the case.

KEY Difference Wire helps crypto brands break through and dominate headlines fast

1

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

From "flood irrigation" to a differentiated landscape, will the altcoin season repeat the glory of 2021?

The altcoin season of 2021 erupted under a unique macro environment and market structure, but now, the market environment has changed significantly.

Chaincatcher2025/09/09 12:26
From "flood irrigation" to a differentiated landscape, will the altcoin season repeat the glory of 2021?

a16z In-Depth Analysis: How Do Decentralized Platforms Make Profits? Pricing and Charging Strategies for Blockchain Startups

a16z points out that a well-designed fee structure is not at odds with decentralization—in fact, it is key to creating a functional decentralized market.

Chaincatcher2025/09/09 12:25
a16z In-Depth Analysis: How Do Decentralized Platforms Make Profits? Pricing and Charging Strategies for Blockchain Startups