Latest Articles

Conservative
Legal News

Receive information on new articles posted, important topics and tips.
Join Now
We won't send you spam. Unsubscribe at any time.

Meta engineer under criminal investigation for allegedly downloading 30,000 private user images

Ben Marquis,
 April 7, 2026

A software engineer at Meta is the subject of an active criminal investigation after the company discovered he had allegedly downloaded roughly 30,000 private images from Facebook and Instagram users, the Daily Mail reported. The case has been referred to the Department of Justice, raising fresh questions about who has access to the billions of personal photos users trust to Big Tech platforms.

The engineer, identified as Davis Varghese, allegedly exploited his internal access at Meta to view and download private images belonging to female users. The company fired Varghese after an internal investigation and referred the matter to federal law enforcement.

What Meta's internal probe allegedly found

Meta's investigation determined that Varghese used internal company tools to access user accounts without authorization, the Daily Mail reported. The images he allegedly downloaded were private photos that users had not made publicly available on their profiles.

The alleged conduct reportedly involved approximately 30,000 images. The scope of that number alone distinguishes this case from a single rogue search. If the allegations are substantiated, it would represent a sustained pattern of unauthorized access carried out by someone the company entrusted with privileged system credentials.

Meta confirmed to the Daily Mail that Varghese was terminated. A company spokesperson said Meta referred the matter to the DOJ after concluding its own review. The company stated that it takes employee misuse of internal tools seriously and cooperates with law enforcement when warranted.

The DOJ referral and what comes next

No criminal charges have been publicly filed against Varghese as of the Daily Mail's reporting. The matter remains under investigation following Meta's referral to the Department of Justice. Federal prosecutors will need to determine whether the alleged conduct violates federal computer fraud or privacy statutes, and whether the evidence supports formal charges.

The Computer Fraud and Abuse Act, the primary federal statute governing unauthorized computer access, carries penalties that can range from misdemeanor-level offenses to multi-year felony sentences depending on the nature and scale of the intrusion. Prosecutors examining this referral will likely weigh whether Varghese's internal credentials gave him authorized access to the tools themselves, or whether using those tools to view private user data for personal purposes exceeded his authorization, a legal distinction that has generated significant case law in federal courts.

The referral to DOJ follows a pattern of federal authorities increasingly scrutinizing tech-sector insiders who abuse platform access. A recent guilty plea in a Supreme Court hacking case illustrated how seriously federal prosecutors treat unauthorized intrusions into protected systems, even when the perpetrator is not a traditional outside hacker.

A trust problem bigger than one engineer

The allegations land at a moment when Meta already faces intense legal and public scrutiny over how it handles user data and platform safety. The company's core business model depends on billions of users uploading personal content, including private photos shared only with selected friends or stored in personal albums, with the expectation that only intended recipients can see them.

An insider threat of this nature strikes at the foundation of that trust. If a single engineer can allegedly harvest tens of thousands of private images using internal tools, users and regulators will demand answers about what safeguards exist to detect and prevent such access in real time, not merely after the fact.

Meta has faced legal consequences for platform-related harms before. A Los Angeles jury recently found Google and Meta liable in a lawsuit over social media design, underscoring the growing willingness of courts and juries to hold tech giants accountable for how their platforms affect users.

The company has not publicly detailed what internal monitoring systems flagged the alleged conduct, how long the activity persisted before detection, or whether any of the affected users have been notified. Those are questions that federal investigators and, potentially, congressional oversight committees will press.

What investigators must determine

Authorities have not publicly confirmed whether Varghese distributed the images to anyone else, stored them on external devices, or used them for any secondary purpose. Investigators will need to determine the full scope of accounts accessed, the time period of the alleged activity, and whether any other Meta employees were involved or aware.

Prosecutors will also need to establish Varghese's intent. Under federal computer fraud statutes, the difference between authorized and unauthorized access often turns on whether the individual exceeded the scope of permissions granted by the employer. Meta's internal policies governing employee access to user data will be central to that analysis.

The case also raises the question of whether Meta's internal detection systems caught the alleged behavior promptly or whether it continued for an extended period before the company intervened. The Daily Mail's reporting did not specify the timeline between when the alleged downloads began and when Meta's internal investigation commenced.

Criminal referrals to the DOJ do not guarantee prosecution, but they signal that the referring entity, in this case one of the largest technology companies in the world, concluded the conduct was serious enough to warrant federal law enforcement attention. Readers who follow how major criminal referrals to the Justice Department develop know that the gap between referral and formal charges can be significant, and outcomes are never guaranteed.

The broader insider-threat landscape

Silicon Valley's largest companies employ tens of thousands of engineers, many of whom hold access credentials that could theoretically allow them to view user data. The industry has long maintained that internal access controls, audit logs, and monitoring tools prevent misuse. Cases like the one alleged against Varghese test that assurance directly.

Tech companies have faced insider-threat incidents before, though most are resolved internally and never reach public attention. The decision to refer this matter to federal prosecutors suggests Meta viewed the alleged conduct as crossing a line that internal discipline alone could not address.

For conservative lawmakers who have pushed for greater accountability from Big Tech, including on questions of platform power and user rights, this case provides concrete evidence that the insider-access problem is not theoretical. It is a live vulnerability in systems that hold the most intimate data of hundreds of millions of Americans.

What Meta has said, and what it has not

Meta's public statements on the matter have been limited. The company confirmed the termination and the DOJ referral but has not addressed broader questions about how many users were affected, whether those users have been contacted, or what systemic changes, if any, it has implemented in response.

The company has not disclosed whether its internal audit systems detected the alleged activity through automated monitoring or whether a tip or complaint triggered the investigation. That distinction matters. Automated detection would suggest existing safeguards worked, even if belatedly. A tip-driven investigation would suggest the safeguards failed and human intervention was required to catch the problem.

Varghese has not publicly commented on the allegations. No attorney representing him has been identified in public reporting. He has not been charged with a crime, and the investigation remains ongoing.

When a company the size of Meta fires an engineer and picks up the phone to call federal prosecutors, the underlying facts are usually serious enough to survive scrutiny. Whether the DOJ agrees, and whether charges follow, will determine if this case becomes a landmark insider-threat prosecution or quietly fades from public view. Either outcome will say something about how seriously the system treats the privacy promises Big Tech makes to every user who uploads a photo.

About Ben Marquis

Latest Articles

Conservative
Legal News

Receive information on new articles posted, important topics and tips.
Join Now
We won't send you spam. Unsubscribe at any time.

Get a FREE Membership to CLN:

Subscribe to the Conservative Legal News email newsletter for free, and find out exactly what is happening when it happens.

    Sponsored