Meta fires employees for allegedly hacking into users' accounts

Internal documents allege that employees were paid thousands of dollars to hijack accounts

Add bookmark
Meta fires employees for allegedly hacking into user’s accounts

Meta has allegedly fired and/or discipled more than 12 employees for hacking into users’ Facebook and Instagram accounts on the behalf of hackers.

According to the Wall Street Journal (WSJ), which broke the story on November 17, some of the hacking cases involved bribery, with employees being paid thousands of dollars to hack into the accounts.  

According to an internal investigation into the account hijacking, those fired by Meta included contractors employed at the company’s facilities as security guards. They were able to hack into unsuspecting victim’s accounts after being allowed access to Online Operations, known as ‘OOps’, a tool used to help users log back into their accounts after being locked out or forgetting their login details. 

Access to OOps is usually heavily regulated, with the vast majority of users being unable to access it and having to use Meta’s other avenues for account recovery. However, this has led to a rise in a so-called "cottage industry of intermediaries" who charge users thousands of dollars to reset their accounts.

To be able to take advantage of OOps, outsiders must "really have to have someone on the inside who will actually do it", according to Nick McCandless, owner of content creation platform McCandless Group.  

An internal document accessed by the WSJ showed that this alternative to the usual account recovery procedure which the majority of users have to go through in the event they cannot access their account, processed 50,720 tasks in 2020, a 77 percent increase in use from 2017.

In the document viewed by the WSJ, a former employee fired in February of this year was allegedly accused of working with hackers and being paid thousands of dollars in Bitcoin to reset multiple Facebook accounts for them. The employee accused has denied any wrongdoing.

Another individual claimed that they were tricked into filling out OOps forms and allowing third parties access to a number of Instagram accounts. The third parties then fraudulently took over the accounts.

Andy Stone, a spokesperson for Meta, said to the Wall Street Journal that “individuals selling fraudulent services are always targeting online platforms, including ours”, and that they are “adapting their tactics in response to the detection methods that are commonly used across the industry”. He added that Meta will “keep taking appropriate action against those involved in these kinds of schemes”.

Stone also noted that buying or selling accounts, or access to account recovery services, is a violation of Meta’s terms of service. 
Meta is currently investigating former employees who allegedly stayed in contact with their former coworkers to retain access to OOps and hack into accounts. 


Upcoming Events

16th Automotive Cybersecurity Summit 2026

March 18 - 19, 2026

Sheraton Ann Arbor Hotel, Ann Arbor, Michigan

16th Automotive Cybersecurity Summit 2026

Digital Identity Week

1st - 2nd September 2026

Sydney, Australia

Digital Identity Week

Latest Webinars

From Dependencies to Defences: Navigating Software Supply Chain Security

2025-09-24

11:00 AM - 12:00 PM SGT

Learn how to defend your software supply chain from dependency threats and build resilient security...

Unpacking global regulatory frameworks to enhance third-party operational resilience

2024-11-14

11:00 AM - 12:00 PM EST

Join this webinar to explore the resilience-focused requirements of DORA, NIS2 and other global regu...

Preventing financial and reputational risk with process intelligence

2024-05-23

11:00 AM - 12:00 PM EDT

Learn how to manage risk stemming from poorly controlled processes in a collaborative way

Recommended

info@cshub.com/r/n

We hope you enjoy All Access from CS Hub!!<\/p>\r\n<p>Best Regards,<\/p>\r\n<p><a href=https://www.cshub.com/"https:////www.cshub.com///" target=\"_blank\">CS Hub Team<\/a><\/p>\r\n<p>P.S. Be sure to check out our other upcoming <a href=https://www.cshub.com/"https:////www.cshub.com//events?filter_format=ONLINE\%22 target=\"_blank\">All Access events here<\/a>.<\/p>\r\n<p>--------------------------------<\/p>\r\nConnect with us on Social Media: <a href=https://www.cshub.com/"https:////www.linkedin.com//groups//12067996///" target=\"_blank\">LinkedIn<\/a> | <a href=https://www.cshub.com/"https:////twitter.com//CSHubUSA/" target=\"_blank\">Twitter<\/a><\/p>\r\n<p>--------------------------------<\/p>\r\n<p>FAQS<\/p>\r\n<p><b>Can I invite my colleagues?<\/b><br>Yes of course! Please send them this link so they can register for free! [WebUrl]<\/p>\r\n\r\n<p><b>How do I access the sessions?<\/b><br>\r\nAll Access is run on Zoom Events. You should receive an email shortly from Zoom Events with your unique All Access link to the event lobby. Please hold on to that email ahead of the event. We\u2019ll also send you a reminder 24 hours before we go live!<\/p>\r\n\r\n<p><b>Will the agenda be updated?<\/b><br>\r\nYes, the agenda will be continuously updated on the website with the latest sessions & speakers. As we get closer to the event, also look out for our weekly updates which will also include the latest updates information and link to access the event.<\/p>\r\n<p><b>Can I access the sessions On Demand?<\/b><br>\r\nEvery session will be available after the event via the event lobby. We\u2019ll also send you a reminder about the On Demand sessions which will be sent to you after the event is over.<\/p>\r\n<p>--------------------------------<\/p>\r\n<p>RELATED RESOURCES TO READ BEFORE YOUR EVENT<\/p>\r\n<ul>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//executive-decisions//reports//cs-hub-mid-year-market-report-2022?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CS Hub Mid-Year Market Report 2022<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//ciso-strategies-for-proactive-threat-prevention?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CISO strategies for proactive threat prevention<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//how-to-strengthen-email-security-and-protection-against-advanced-ransomware-attacks?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">How to strengthen email security and protection against advanced ransomware attacks<\/a><\/li>\r\n<\/ul>","event_registration_srs_confirmation_email":null,"assets_from_cdn":true},"bant_disabled":1,"sponsorship_disclaimer":null,"sponsorship_disclaimer_text":null,"sponsorship_disclaimer_checkbox_disabled":0,"ext_treat_id":null,"recording_url":null,"file_attachment":null,"ingo_enabled":0,"ingo_activator_id":null,"ingo_autofiller_id":null,"ingo_amplifier_id":null,"ingo_authorizer_id":null,"restricted_content":0,"featured_events_embedded":[],"featured_content_embedded":[{"id":"62f131794ed39e399d7bd243","name":"Twitter confirms data from 5.4 million accounts has been stolen","description":"Twitter has confirmed that a suspected data breach in July led to account data being stolen","file":null,"url":"\/attacks\/news\/twitter-confirms-data-from-54-million-accounts-has-been-stolen"},{"id":"6078615bd1d92e70163d1404","name":"IOTW: Facebook Data Leak Impacts 533 Million Users","description":null,"file":null,"url":"\/attacks\/articles\/iotw-facebook-data-leak-impacts-533-million-users"},{"id":"62e167ad83eb71240631551d","name":"5.4 million Twitter accounts reportedly on sale in hacking forum","description":"The social media site is currently investigating the authenticity of claims that 5.4 million accounts have been breached and are for sale on hacking forums","file":null,"url":"\/attacks\/news\/54-million-twitter-accounts-reportedly-on-sale-in-hacking-forum"},{"id":"5c1ab4ace389914a66796ecb","name":"Incident Of The Week: Facebook Exposes Photos Of 6.8 Million Users In Second Data Breach Since September","description":"Social Media Giant Gave Tech Giants Access To More People\u2019s Data Than It Had Disclosed","file":null,"url":"\/attacks\/news\/incident-of-the-week-facebook-exposes-photos-of-68-million-users-in-second-data-breach-since-september"},{"id":"5f1b3027d1d92e3b24658fb2","name":"Incident Of The Week: The Infamous Twitter Attack And What Enterprises Can Learn From It","description":"5 Lessons Learned From The Breach","file":null,"url":"\/attacks\/articles\/incident-of-the-week-the-infamous-twitter-attack-and-what-enterprises-can-learn-from-it"}],"featured_content_portal_embedded":null}" >