
Meta has put its employee tracking software programme on indefinite hold after sensitive information collected from the software was made available for access to anyone within the firm. According to reports from Wired, the programme was launched to monitor keystrokes, clicks, and mouse movements from Meta's US-based employees to train the company's artificial intelligence systems. A Meta spokesperson confirmed the incident and stated the company was looking into it, emphasizing that while there was no indication at this time that any data was improperly accessed by Meta employees, the company was pausing the programme while investigating. The latest data reveals that nearly two months after Meta told its US workforce that tracking software would start logging their every click and keystroke, the company has hit pause on the indefinite hold.
Meta Vice President Stephane Kasriel confirmed that the security issue was initially discovered on Thursday, June 18, with engineers deploying a security patch within four hours. However, as reported by Reuters, the fix failed to lock down access to the sensitive data. According to Wired, the company is currently investigating the potential internal data breach to determine whether it was accessed by others on Meta's staff. A Meta engineer issued an internal security notice on Monday, June 22, warning that databases containing the tracked employee information remained exposed to all workers at the company. The programme faced immediate resistance from employees, with workers protesting the internal tracking over privacy and personal liberty concerns, circulating petitions that eventually forced Meta to offer limited opt-out options. In May, Reuters reported that the program was gathering more data than originally disclosed and keeping it in an unencrypted format, prompting privacy concerns among employees.
The exposed data included full prompts and transcriptions, private conversations, people and performance data, and DSS sensitivity ratings on a scale of one to four. According to Wired, the security notice noted that employee data across 45,000 hive tables had been breached, with the tables consisting of employee activity like full prompts and transcriptions, private conversations, people and performance data. According to screenshots reviewed by Business Insider, information collected through the programme was inadvertently made available to employees across the company, with the exposed material reportedly including private staff conversations, performance-related information and transcriptions generated through the initiative. The incident has sharpened privacy concerns and added to unease over the company's AI-driven changes. As reported by Reuters, the exposure was not a breach by an outside attacker but a permissions problem - the kind of internal misconfiguration that turns a surveillance dataset into an open filing cabinet.
Screenshots of internal discussions obtained by Business Insider show employees responding with alarm to the data exposure. According to the report, one Meta employee wrote on Monday in an internal group, "I am incensed. I don't see any evidence of malicious access, but the fact that this data wasn't locked down as originally promised is super frustrating." Another employee raised broader concerns about the scope of data captured, noting that many employees have accessed personal tax and medical information through work computers and were told this data would be protected. The latest incident has reignited concerns over workplace surveillance, data governance and Meta's ability to secure AI systems amid a series of recent security setbacks. The leak comes despite Meta claiming at the time of deployment that employee data will not be used for any other purpose and that the tool has 'safeguards in place to protect sensitive content'.
Chief Technology Officer Andrew Bosworth admitted the program's implementation fell short of privacy standards, marking a significant admission from senior leadership. According to Wired, Bosworth stated in an internal memo that the tracking programme had misconfigured access control lists and the firm needs to find every data access point and analyse it. A Meta spokesperson told Wired that "We have carefully designed this program with privacy safeguards and while we have no indication at this time that any data was improperly accessed by Meta employees, we're pausing it while we investigate." The company maintains there is currently no evidence that employee data from the MCI programme was improperly used, but the incident has renewed debate over how organisations collect and manage information to train increasingly sophisticated AI models. Sources from the firm stated that the incident has been marked 'closed', which indicates that the matter has likely been considered concluded by the IT company. This marks the latest in a series of AI-related cybersecurity incidents for the company, following similar responses in March after an agentic AI took unprompted action and earlier this month when hackers exploited its AI customer service chatbot to hijack Instagram accounts.