Former WhatsApp security manager Attaullah Baig sued Meta Platforms and several executives on September 8, 2025, alleging excessive employee access to user data, weak monitoring and retaliation after he raised security concerns. Meta denies retaliating and says he was dismissed for poor performance. On March 23, 2026, a federal judge dismissed Baig’s sole Sarbanes-Oxley retaliation claim without prejudice—but did not decide whether the alleged WhatsApp security weaknesses existed or whether Meta can read end-to-end-encrypted messages.
What the lawsuit is—and is not
Baig’s case, Baig v. Meta, was filed in the U.S. District Court for the Northern District of California, San Francisco Division (case 25-cv-07604-LB). The complaint presents Baig’s account of internal security and privacy problems and claims that Meta retaliated against him. Those allegations have not been established as facts by a trial or regulatory finding.
The court’s March 23, 2026 order addressed only whether Baig adequately pleaded a retaliation claim under Section 806 of the Sarbanes-Oxley Act (SOX), 18 U.S.C. § 1514A. Judge Laurel Beeler granted Meta’s motion to dismiss without prejudice. The available record does not establish whether Baig later amended the complaint or appealed, so the live docket should be checked before treating the case as finally ended.
Read the March 23, 2026 court order and check the case docket.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
Who is Attaullah Baig?
Baig describes himself in the complaint as a former WhatsApp “Head of Security” or security manager. Meta disputed that characterization, saying his formal position was software engineering manager and that more senior security professionals were above him. Any description of his earlier cybersecurity work should therefore be attributed to the complaint or contemporaneous reporting, rather than presented as independently verified employment history.
What Baig alleged about WhatsApp’s security controls
According to the complaint, a red-team exercise showed that roughly 1,500 WhatsApp engineers could access user data without adequate business justification. Baig alleged that employees could move or copy sensitive information without reliable detection or audit trails. The complaint also alleged that WhatsApp lacked a complete inventory of the user data it collected, where it was stored and who could access it.
- Monitoring: Baig alleged WhatsApp lacked a security operations center or equivalent capability to monitor internal access continuously.
- Logging: He alleged insufficient logging and tracking of employee access to data.
- Account security: He claimed approximately 100,000 WhatsApp accounts were taken over each day. That figure is an allegation, not a court finding or independently established incident count.
- Staffing: He alleged WhatsApp had about 10 security-focused engineers, while similarly sized companies had substantially larger teams. The comparison comes from his account.
- Compliance concerns: He argued the alleged practices could implicate California privacy law, the EU General Data Protection Regulation, Meta’s 2020 Federal Trade Commission privacy order and securities-related obligations. The court did not make those findings.
The complaint is about access controls, data governance and account security. Saying employees allegedly had access to “user data” does not establish that they routinely read the plaintext contents of end-to-end-encrypted chats.
Read the complaint filed September 8, 2025.
Baig’s reported warning timeline
- September 2021: Baig joined Meta/WhatsApp and says he discovered the alleged problems.
- 2021–2022: He says he raised concerns with supervisors and executives repeatedly.
- August–September 2022: He allegedly briefed Meta and WhatsApp executives about security staffing, data-access risks and possible regulatory consequences.
- January 2, 2024: He allegedly wrote to CEO Mark Zuckerberg and General Counsel Jennifer Newstead, claiming central security reports had been falsified or used to conceal shortcomings.
- January 2024: He allegedly raised concerns about compliance with Irish data-protection obligations.
- November 2024: He allegedly filed a Tip, Complaint or Referral with the Securities and Exchange Commission.
- 2024–2025: He says he continued raising privacy and security concerns.
- April 11, 2025: CyberScoop reported that Meta terminated him, citing poor performance; the broader account also links the termination to a performance-based layoff process.
The precise employment sequence should be read against the complaint and termination documents. Temporal proximity and references to his complaints formed the basis of his retaliation theory, but they do not by themselves prove causation.
Recommended Free Tools
What retaliation did Baig allege?
Baig alleged that his supervisor criticized his performance after he raised concerns, his rating was reduced to “Needs Support,” and negative reviews referred to his security complaints. He also alleged that a supervisor called one security document extremely poor, warned that executives could fire him for writing it and threatened consequences involving compensation or discretionary equity. Meta later cited poor performance, an inability to collaborate or inclusion in performance-based layoffs as the reasons for ending his employment.
Meta’s response and the agency outcome
Meta denied that Baig was fired for whistleblowing. The company said he was dismissed for poor performance, disputed his description of his title and authority, and said his claims distorted or misrepresented its continuing security work. Meta also emphasized its commitment to privacy and security.
Rank #3
CyberScoop reported that the Occupational Safety and Health Administration and the Department of Labor rejected Baig’s retaliation complaint. OSHA said he had not made a prima facie showing and that the alleged protected activity likely was not objectively reasonable. That agency outcome supports Meta’s position, but it is not a judicial ruling on whether WhatsApp’s security controls were adequate.
See CyberScoop’s report and Meta’s response.
Why the federal court dismissed the claim
SOX protects specific types of reporting
Section 806 of SOX protects employees of publicly traded companies from retaliation for reporting specified misconduct. Protected reports generally must concern securities fraud, mail or wire fraud, bank fraud, violations of Securities and Exchange Commission rules or federal law relating to shareholder fraud.
Reporting a serious privacy or cybersecurity problem is not automatically a SOX-protected report. The employee must plausibly connect the reported conduct to one of those statutory categories.
Rank #4
What Judge Beeler found missing
The March 23 order said Baig had not pleaded enough facts showing which SEC rules he reported, how the alleged conduct approximated securities or wire fraud, or how the alleged cybersecurity problems related to internal-accounting controls. The court also rejected using the OSHA complaint to add facts missing from the federal pleading and questioned whether the individual defendants could be held liable under the asserted theory.
“Without prejudice” means the dismissal was not necessarily a permanent bar to an amended complaint, subject to later docket activity and applicable deadlines.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What the ruling says about WhatsApp encryption
The lawsuit does not show that Meta can routinely read WhatsApp messages. End-to-end encryption concerns whether a service provider can access plaintext message content in transit. Baig’s allegations concern a wider set of systems and information, including:
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Best Value
- message content in particular systems or workflows;
- metadata and account-registration information;
- address books and contact data;
- backups and device-stored content;
- reports, moderation material and user-submitted messages;
- cloud or operational data available to authorized employees; and
- access-control, logging and audit records.
Some data can exist in plaintext outside the encrypted messaging channel, and access to that data can still create significant privacy risk. But the complaint and dismissal order do not establish that Meta defeated WhatsApp’s end-to-end encryption or routinely accessed encrypted chat plaintext.
What the case actually establishes
| Question | What the record shows |
|---|---|
| Did Baig allege serious privacy and security weaknesses? | Yes. The complaint alleges broad internal access, inadequate monitoring and logging, account takeovers and understaffing. |
| Did Meta admit those allegations? | No. Meta disputed Baig’s account, title and reason for termination. |
| Did OSHA or the Department of Labor sustain his retaliation complaint? | CyberScoop reported that they did not. |
| Did the federal court find WhatsApp’s systems secure? | No. It dismissed the SOX retaliation pleading as legally insufficient. |
| Did the court find Meta could read encrypted WhatsApp messages? | No. The order made no such finding. |
| Is the litigation conclusively over? | Not established by the available record; later amendment or appeal activity must be checked on the docket. |
What to watch next
The important procedural questions are whether Baig filed an amended complaint, sought reconsideration or appealed after March 23, 2026. Any such filing could change the case’s status, but it would not by itself prove the underlying technical allegations. A dismissal for insufficient pleading is different from a trial verdict, a regulatory finding, a breach notification or a settlement admitting liability.
Bottom line
Baig raised substantial allegations about WhatsApp’s internal access controls, data governance and account security and said Meta retaliated against him. Meta denied those claims and attributed his termination to performance. The federal court dismissed his SOX retaliation claim without prejudice because the complaint did not sufficiently tie his reports to conduct covered by the statute. Nothing in that ruling establishes that the alleged WhatsApp weaknesses were true—or that Meta can routinely read end-to-end-encrypted messages.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




