A former Meta engineer based in London, who knew Facebook's security systems better than most, has been arrested after stealing over 30,000 private photos belonging to users. He was well aware of how to bypass the company's internal security measures.
The engineer had written a program himself that could extract private photos that ordinary users couldn't access, and used it to steal the images. Meta discovered this in early 2025 and immediately fired the employee, then reported the case to the FBI and the British police force. The suspect was arrested in November 2025 and is scheduled for further interrogation at the police station in May 2026.
In fact, Meta has been frequently facing reputational damage and fines due to information security vulnerabilities. Between 2022 and 2024 alone, millions of users' data were exposed, and the company was hit with fines exceeding €356 million in Europe. Moreover, there have been court rulings requiring them to pay hundreds of millions of dollars in compensation over allegations that their social network designs are unsafe for young people.
This incident serves as a reminder that for major tech companies, "the enemy within" is more to be feared than "the enemy without." While they have built multiple layers of defenses to block hackers from outside, it is quite difficult to prevent abuse when the employee holding the keys inside the fortress misuses their access. Since the stolen photos have already reached the outside world, Meta's apologies will be hard for the victims to accept.
Ref: thenextweb

