The Man Who Downloaded 30,000 Private Photos: Inside Meta’s Employee Surveillance Scandal in the UK

A fired Meta employee in the UK allegedly downloaded 30,000 private photos from Facebook users' accounts using internal tools. The case, exposed through employment tribunal proceedings, raises urgent questions about insider threats, data protection enforcement, and the fragile trust underpinning social media.
The Man Who Downloaded 30,000 Private Photos: Inside Meta’s Employee Surveillance Scandal in the UK
Written by Emma Rogers

A Meta employee based in the United Kingdom allegedly exploited his privileged access to company systems to download more than 30,000 private photographs from Facebook users’ accounts. The accusation, now the subject of an employment tribunal in London, strikes at the heart of a question that has haunted the tech industry for years: Who watches the watchers?

The employee, identified in tribunal proceedings as Olatayo Olatoye, worked at Meta’s London office and reportedly used internal tools to access users’ private data without authorization. According to reporting by Engadget, Olatoye was dismissed from the company after an internal investigation uncovered the alleged misconduct. He is now challenging his firing through the UK employment tribunal system, claiming unfair dismissal — a legal avenue that has, paradoxically, brought the details of his alleged behavior into public view.

Thirty thousand photos. That’s not a slip of the mouse. It’s not a momentary lapse in judgment or a misunderstanding of company policy. If the allegations hold, it represents a sustained, deliberate campaign of unauthorized data access carried out by someone Meta trusted with the keys to its users’ most intimate digital spaces.

The case was first surfaced by The Telegraph, which reported details from the tribunal filings. According to those filings, Meta’s internal security team discovered the activity and launched an investigation that ultimately led to Olatoye’s termination. The company argued the dismissal was justified given the severity of the breach. Olatoye, for his part, has contested the characterization of his actions and the fairness of the process that led to his firing.

Meta declined to comment in detail on the case, citing the ongoing tribunal proceedings. But the company has previously emphasized that it maintains strict protocols governing employee access to user data and that violations are met with disciplinary action, including termination.

Here’s what makes this case particularly unsettling for the broader tech industry. Every major platform — Meta, Google, Apple, TikTok, X — employs thousands of people who, by the nature of their jobs, can access user data. Engineers debugging systems. Content moderators reviewing flagged material. Trust and safety teams investigating abuse reports. The architecture of these platforms requires some humans to have some access. The question is how much access, how well it’s monitored, and what happens when someone abuses it.

Meta has a system called “Oops” — an internal tool designed to flag when employees access data they shouldn’t be looking at. The company also uses automated monitoring to detect anomalous access patterns. But as this case suggests, no system is perfect. And the sheer scale of Meta’s operations — with more than 80,000 employees worldwide and nearly 3.3 billion monthly active users on Facebook alone — means the attack surface for insider threats is enormous.

This isn’t the first time Meta has faced allegations of employee data misuse. In 2018, Vice’s Motherboard reported that Facebook had fired multiple employees for using their data access privileges to stalk women. That reporting revealed a pattern: employees with elevated access would look up the profiles and personal information of people they knew, were romantically interested in, or were in disputes with. The company acknowledged the firings at the time but offered few specifics.

The 2018 incidents prompted Meta to tighten its internal access controls. The company implemented more granular logging of data access events, restricted the number of employees who could view certain types of user information, and increased the frequency of audits. Yet here we are, years later, with an allegation that dwarfs those earlier cases in scale.

The UK tribunal system offers Olatoye certain protections that wouldn’t necessarily apply in the United States. Under UK employment law, employees who have worked for a company for at least two years have the right to challenge their dismissal if they believe it was procedurally unfair or disproportionate. The tribunal will examine not just whether Olatoye accessed the data, but whether Meta followed a fair process in investigating and dismissing him. This is a critical distinction. Even if the underlying conduct is proven, a tribunal can still find the dismissal unfair if the employer cut corners in its internal procedures.

For Meta, the stakes extend well beyond the outcome of a single employment dispute. The company operates under the jurisdiction of the UK’s Information Commissioner’s Office, which enforces the UK General Data Protection Regulation. Under UK GDPR, organizations that fail to protect personal data can face fines of up to £17.5 million or 4% of annual global turnover — whichever is higher. For Meta, 4% of global revenue would translate to billions of dollars.

The ICO has not publicly commented on whether it is investigating the matter. But the regulator has historically taken a keen interest in cases involving unauthorized access to personal data by insiders. In 2020, the ICO fined a former employee of a telecommunications company for illegally accessing customer records. The precedent is clear: the regulator views insider data abuse as a serious enforcement matter.

So what did Olatoye allegedly do with the 30,000 photos? The tribunal filings don’t provide a complete picture. It’s unclear whether the images were shared with third parties, stored on personal devices, or used for any specific purpose beyond collection. This ambiguity matters — both for the legal proceedings and for the affected users, who may never know their private photographs were accessed by someone inside the company they entrusted with their data.

And that’s the deepest problem here. Not the legal outcome. Not the fine print of UK employment law. The problem is trust.

Facebook’s entire business model rests on the premise that users will voluntarily share personal information — photos, messages, location data, relationship status, political views — in exchange for a free social networking service. That exchange only works if users believe their data is reasonably secure. Every insider abuse case chips away at that belief. Every headline about an employee downloading thousands of private photos makes the next user think twice before uploading a family picture or sending a private message.

The timing of this revelation is particularly awkward for Meta. The company is in the midst of a massive push into artificial intelligence, a project that requires vast amounts of data and, by extension, vast amounts of user trust. Meta’s AI training practices have already drawn scrutiny from European regulators, with several data protection authorities questioning whether the company has a lawful basis to use personal data for AI model training. An insider data breach — even one involving a single rogue employee — feeds the narrative that Meta cannot be trusted to safeguard the information it collects.

Other tech companies are watching this case closely. Google, Amazon, and Apple all face similar insider threat challenges and have invested heavily in monitoring systems designed to detect unauthorized data access. Microsoft, which recently dealt with its own security controversies following the Storm-0558 breach attributed to Chinese hackers, has made insider threat mitigation a stated priority. But the fundamental tension remains: the people who build and maintain these systems must, at some level, have access to the data flowing through them.

The cybersecurity industry has a term for this: the insider threat problem. It’s considered one of the hardest challenges in information security because it involves people who have legitimate access credentials and intimate knowledge of internal systems. Traditional perimeter defenses — firewalls, intrusion detection systems, encryption — are designed to keep outsiders out. They do nothing to stop an authorized employee from misusing their access.

Modern approaches to the problem include zero-trust architecture, which requires continuous verification of every user and device regardless of their position within the organization. There’s also behavioral analytics, which uses machine learning to establish baseline patterns of employee activity and flag deviations. But these tools are probabilistic, not deterministic. They can reduce risk. They can’t eliminate it.

The Olatoye case also raises questions about Meta’s hiring and vetting processes. What level of background screening do employees undergo before being granted access to user data? Are there ongoing checks, or is access granted once and rarely revisited? Meta has not publicly detailed its vetting procedures, and the company is unlikely to do so given the security implications. But the question lingers.

For the 30,000 users whose photos were allegedly accessed, the situation is grim. Under UK GDPR, they have the right to be informed of a data breach that poses a high risk to their rights and freedoms. Whether Meta has notified the affected individuals is unknown. The company’s public silence on the matter, while understandable given the tribunal proceedings, leaves a vacuum that speculation naturally fills.

Privacy advocates have seized on the case as evidence that self-regulation by tech companies is insufficient. Jim Killock, executive director of the Open Rights Group, has previously argued that platforms need independent oversight mechanisms to monitor how employee access to user data is managed. “You can’t just trust these companies to police themselves,” he told The Guardian in earlier commentary on tech industry data practices.

The tribunal proceedings are expected to continue in the coming months. Whatever the outcome, the case has already accomplished something significant: it has forced a public reckoning with the uncomfortable reality that the people inside the world’s largest social media company can, under certain circumstances, see everything their users thought was private.

That’s a fact no amount of corporate messaging can fully address. And it’s one that every Facebook user — all 3.3 billion of them — should sit with for a moment.

Subscribe for Updates

CybersecurityUpdate Newsletter

The CybersecurityUpdate Email Newsletter is your essential source for the latest in cybersecurity news, threat intelligence, and risk management strategies. Perfect for IT security professionals and business leaders focused on protecting their organizations.

By signing up for our newsletter you agree to receive content related to ientry.com / webpronews.com and our affiliate partners. For additional information refer to our terms of service.

Notice an error?

Help us improve our content by reporting any issues you find.

Get the WebProNews newsletter delivered to your inbox

Get the free daily newsletter read by decision makers

Subscribe
Advertise with Us

Ready to get started?

Get our media kit

Advertise with Us