A US judge dismisses a lawsuit against Meta by Attaullah Baig, a former head of cybersecurity at WhatsApp and who alleged Meta ignored critical security flaws
A judge ruled WhatsApp's former head of cybersecurity did not bring sufficient facts to the case when claiming violations by Meta and retaliation after the disclosure.
Context & Ripple Effects
The dismissal separates internal allegations about WhatsApp’s security practices from Meta’s longer-running effort to pursue outside spyware vendors. In that separate track, the Supreme Court allowed WhatsApp’s case against NSO Group to proceed over exploitation of a WhatsApp bug, and a court later ordered disclosure of Pegasus and other spyware code.
It also follows a ruling barring NSO from targeting WhatsApp users, although the court sharply reduced the damages award. The Baig case instead turns on whether a former security leader supplied enough factual support for claims that Meta ignored flaws and retaliated after disclosure.
First-order effects
- Meta and WhatsApp avoid having Baig’s claims proceed on the facts pleaded; the reported security and retaliation allegations are not tested further in this case at this stage.
- Baig’s lawsuit does not create an immediate court-ordered disclosure or operational obligation for Meta, unlike the discovery imposed in WhatsApp’s spyware litigation against NSO.
Second-order effects
- The outcome leaves employees and security researchers seeking to challenge platform practices with a high bar to substantiate technical-risk and retaliation claims in court.
- Meta’s security narrative remains shaped more immediately by its affirmative litigation against external attackers, including the injunction against NSO targeting WhatsApp users, than by this internal challenge.
Third-order effects
- The contrasting cases show that platform-security accountability can depend heavily on the legal vehicle: litigation over identifiable external exploitation can yield discovery and injunctions, while internal governance claims may fail without sufficiently specific factual pleadings.
- If this pattern persists, courts will remain an uneven mechanism for surfacing product-security governance: effective at constraining named attackers, but less reliable for independently testing alleged internal security decisions.
The trend: Platform security disputes are increasingly being resolved through procedural legal thresholds that determine which technical risks reach discovery and public scrutiny.