HomeSecurityMeta: Former engineer under investigation for stealing 30,000 photos of Facebook users

Meta: Former engineer under investigation for stealing 30,000 photos of Facebook users

A former Meta engineer in London is under criminal investigation after allegations he developed a program to extract around 30,000 private photos from Facebook.

Meta engineer steals 30,000 Facebook users' photos

Meta's internal security systems are designed to prevent unauthorized access to user data by engineers and employees. According to the Metropolitan Police and the Press Association, they failed to do so in this case. A former Meta engineer living in London was arrested in November 2025 on suspicion of unauthorized access to computer hardware (under the Computer Misuse Act).

He has since been released on bail and must report to police again in May 2026.

The case came to light this week. The Metropolitan Police's Cyber ​​Crime Unit is dealing with it, following a referral from the FBI.

See also: Meta suspends cooperation with Mercor after breach

How did the former Meta engineer act and steal the photos?

The engineer allegedly wrote a program that could extract private images from Facebook accounts, bypassing the security checks that Meta uses to flag suspicious insider access. The result, researchers say, was the extraction of about 30,000 photos belonging to users who had not made those images public. Meta told the BBC that the breach was discovered more than a year ago. The company said it immediately fired the employee and referred the matter to law enforcement.

The mechanisms by which the program evaded detection have not been made public by either Meta or the Metropolitan Police. What is clear is that there was a period of several months between the discovery of the breach and the arrest, consistent with a cross-border investigation involving the FBI, before the referral reached British law enforcement.

Meta said it has since notified Facebook users whose images were downloaded and has upgraded its security systems to address the vulnerability.

Meta: Former engineer under investigation for stealing 30,000 photos of Facebook users

Meta: Privacy concerns are increasing

The investigation adds to a list of privacy and security that have dogged Meta for years, and which regulators have found serious enough to warrant significant fines.

See also: Meta's child safety judgment in the hands of two jurors

In November 2022, the Irish Data Protection Commission, which serves as Meta's lead regulator for GDPR in the European Union, fined the company €265 million following an investigation into the extraction of data on 533 million Facebook users. The data, which included names, phone numbers, and email addresses, appeared on an online hacking forum in April 2021.

The DPC found that Meta had failed to implement data protection “by design and by default” as required by Articles 25(1) and 25(2) of the GDPR.

Two years later, in September 2024, the same regulator imposed a €91 million fine after finding that Meta had inadvertently stored the passwords of around 600 million Facebook and Instagram in plain text on its internal systems. The passwords were never exposed to external parties, but the failure to secure them internally violated multiple provisions of the GDPR, including the key requirement to implement appropriate technical security measures.

Internal threats

The ex-engineer's image extraction brings to light the issue of insider threat, one of the most difficult challenges for large technology companies. The research, conducted in London, highlights a particularly complex type of risk: the employee who already has authorized access to the systems. Unlike external attacks, where attackers try to breach systems from the outside and can be countered by measures such as firewalls, access restrictions and suspicious activity detection tools, insider threats are harder to detect. This is because the person committing the abuse already knows how the systems work and can bypass control mechanisms more easily.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Meta: Removes end-to-end encryption from Instagram DMs

Meta: Former engineer under investigation for stealing 30,000 photos of Facebook users

Meta claimed to have identified the breach and acted promptly, dismissing the employee and referring the matter to the relevant authorities. This suggests that internal controls were ultimately in place and were able to detect the suspicious activity, albeit in hindsight. However, significant questions remain. It is not clear how long the data extraction system was operating before it was detected, nor how around 30,000 photos were leaked without prompt alerts being triggered. These points are expected to be examined in detail by the Metropolitan Police, while possible charges will be decided by the Crown Prosecution Service after the proceedings are concluded.

For the affected Facebook users, Meta’s update is hardly reassuring. The leaked images were private, meaning content they had chosen not to make public. It’s not known whether they were strictly personal or just private photos, but the main problem remains: this material is now off the platform. Furthermore, the fact that the alleged breach came from someone within the company adds to the sense of insecurity, as this is an organization that users had trusted with the protection of their data.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS