A former Meta engineer based in London is being investigated by the Metropolitan Police after reportedly acquiring around 30,000 personal Facebook images from the social network. The suspect, a man in his 30s, is said to have created a programme capable of circumventing the company’s security measures to retrieve users’ private photos without authorisation. He was arrested in November 2025 on charges relating to unauthorised access computer material and has since been released on bail, with his next police interview due in May. Meta uncovered the breach over a year ago, swiftly terminated the employee’s employment, and reported the matter to law enforcement. The company has since alerted impacted users and enhanced its protective systems.
The Alleged Breach and Identification
According to Meta, the security breach came to light over twelve months before the arrest, when the company’s systems detected unauthorised access to user photographs. The discovery led to immediate response from Meta’s leadership, who ended the engineer’s contract and escalated the matter to law enforcement authorities. The social media giant subsequently initiated an inquiry to ascertain the complete scope of the breach and identify which users had been affected by the unauthorised data downloads.
The investigation has since been taken up by the Metropolitan Police’s Cybercrime Unit, in response to a recommendation from the Federal Bureau of Investigation in the US. This international cooperation underscores the seriousness of the suspected crime and the international scope of cybercrime investigations. Meta has confirmed that it informed all affected Facebook users whose images were downloaded and has implemented strengthened security measures to avoid comparable events happening in future.
- Violation uncovered more than twelve months prior to the defendant’s arrest
- Alleged developer created system to bypass protective measures
- Metropolitan Police Digital Crime Division leading the inquiry
- FBI referral prompted international law enforcement collaboration
Police Response and Timeline
The Metropolitan Police’s response to the reported data breach was prompt after Meta’s referral and the ensuing engagement of American federal law enforcement. A man in his 30s, living in London, was arrested in November 2025 on suspicion of unauthorised access to computer material. The arrest represented a major milestone in what had been an active investigation from the time Meta first uncovered the breach over a year prior. The suspect’s arrest highlighted the seriousness with which law enforcement bodies treat claims regarding widespread unauthorised access to personal user information.
Following his apprehension, the suspect was let out on bail pending further enquiries. According to Press Association reports, he is obliged to present back to police in May, when investigators will evaluate developments in the case. The decision to release on bail rather than remand suggests authorities are pursuing their enquiries whilst granting the suspect conditional freedom. This approach is common in intricate cyber-related investigations where detectives need further time to collect information and establish the full extent of the claimed wrongdoing.
London Police Investigation
The Metropolitan Police’s Digital Crime Team has taken the lead in investigating the suspected data breach, bringing expert knowledge to bear on what is a highly intricate case. The unit’s participation reflects the increasingly sophisticated nature of contemporary cybercrime and the requirement of specialist personnel trained in cybersecurity and digital forensics. Their inquiry focuses on determining exactly how the individual in question circumvented Meta’s security systems and the techniques employed to download the images.
The inquiry has benefited from global partnership, with the FBI in the US submitting details to British officials. This transatlantic partnership demonstrates how cybercrime transcends international boundaries and requires joint investigative action. The FBI’s participation suggests the incident could have had repercussions outside the UK, likely affecting people in different regions and demanding collaborative investigation.
Meta’s Security Breaches and Earlier Occurrences
| Incident | Fine and Details |
|---|---|
| Facebook Data Breach (November 2022) | €265 million (£228 million) fine from Irish Data Protection Commission for publishing personal details of hundreds of millions of users online |
| Unencrypted Password Storage (September 2024) | €91 million (£75 million) fine from Irish Data Protection Commission for inadvertently storing user passwords on internal systems without encryption |
| Addictive Platform Design (March 2025) | $6 million (£4.5 million) damages awarded to user “Kaley” in California court case; both Meta and Google found to have intentionally built addictive platforms harming mental health |
| Unauthorised Photo Download (Current Investigation) | Approximately 30,000 private Facebook images allegedly accessed by former engineer; investigation ongoing by Metropolitan Police Cybercrime Unit |
This recent breach represents a concerning pattern of security breaches at Meta, one of the world’s largest technology companies. The incident illustrates how even advanced online systems with substantial resources can become targets of insider threats when employees exploit their privileged access to systems. The alleged circumvention of security protocols by the engineer underscores potential vulnerabilities in Meta’s security measures and access controls, prompting concerns about how thoroughly the company oversees staff conduct and protects sensitive user data from malicious actors within the organisation.
Wider Issues Surrounding Tech Company Responsibility
The inquiry into the ex-Meta engineer comes at a time of heightened scrutiny over how tech firms protect user information and defend their systems from insider risks. Meta’s ongoing security breaches have prompted regulators across various regions to examine whether the firm’s compliance measures are sufficiently robust. The cumulative effect of these occurrences—from the massive 2022 data breach to the present photo downloading controversy—suggests that despite substantial investment in security infrastructure, Meta may still struggle to stop motivated actors from taking advantage of security weaknesses. Commentators contend that the company’s responsive strategy, acting solely following breaches are uncovered, fails to meet the forward-thinking security approach necessary for companies managing billions of people’s private data.
Beyond Meta’s specific shortcomings, the case raises broader questions about responsibility in the technology sector. As social media platforms exercise unprecedented influence over users’ data privacy and psychological wellbeing, regulators and policymakers are raising concerns about whether current penalties and statutory consequences effectively discourage misconduct. The varying approaches taken by various bodies—the Irish Data Protection Commission, American courts, and now the Metropolitan Police—demonstrate the fragmented nature of tech regulation internationally. Some observers argue that stronger statutory requirements, required security reviews, and tighter controls of employee access to sensitive systems could avert subsequent breaches, whilst others contend that companies must encounter greater monetary penalties to warrant the investment in real security upgrades.
- Regulators worldwide are intensifying scrutiny of Meta’s data protection procedures and compliance standards
- Existing fines might be insufficient to discourage big tech organisations from neglecting data security safeguards
- Coordinated cross-border regulatory frameworks could strengthen defences against internal security risks and security breaches