CPO Magazine - News, Insights and Resources for Data Protection, Privacy and Cyber Security Leaders
CPO Magazine - News, Insights and Resources for Data Protection, Privacy and Cyber Security Leaders
  • Home
  • News
  • Insights
  • Resources
Meta logo on a device screen showing account hijacking using account recovery tool
Cyber SecurityNews
·3 min read

Document Leak Reveals Meta Employees Took Bribes To Use Account Recovery Tool for Expedited Service, Account Hijacking

Scott Ikeda·December 2, 2022

The Wall Street Journal is reporting that a leak of internal Meta documents reveals at least a year of internal abuse of an account recovery tool by various parties, who accepted bribes of up to several thousand dollars to recover locked accounts and in some cases even played an accomplice role in account hijacking.

The rogue employees and contractors abused an internal feature called “Oops,” which is primarily intended for in-house account recovery for employees and business partners. Increasingly widespread access to the tool translated into a big jump in abuse, as use of it more than doubled between 2017 and 2020.

Speedy service, account hijacking were available for a price at Facebook and Instagram

Anyone who has ever lost access to a Facebook account knows that the account recovery process is onerous at best, and in some cases impossible. Meta has never had anything more than a skeleton crew manning the customer service desks, relying on highly imperfect automated tools and algorithms to field the vast majority of requests for assistance with locked-out or stolen accounts. In desperation to reach an actual human, some have turned to purchasing Oculus VR headsets (which cost hundreds of dollars) simply because that branch of the company has a dedicated customer service line for hardware owners.

While most people struggle mightily with Facebook or Instagram account recovery, a select set of insiders and high-profile public figures get special access to swiftly resolve their issues. Meta’s internal “Online Operations” (Oops) tool is for them, providing a private email channel available to certain qualified individuals when they have account issues. This channel has reportedly existed for years, but did not run into serious trouble until recently when the amount of internal employees given access to it spiked.

One of the sources of spikes in Oops abuse appears to be contractor Allied Universal, which provides physical security to Meta facilities. Guards stationed on site at these facilities were apparently granted access to Oops despite being third-party contractors, and the leaked documents indicate some amount quickly made a side hustle out of this access. The documents reveal that some of these parties took bribes (or “fees”) of up to $7,000 to either expedite the account recovery of an outside party that would not normally have access to Oops, or to simply help out with someone’s account hijacking scheme.

The documents are part of an internal investigation into the issue ordered by Meta executives. After the brisk trade in Oops access was discovered, there was reportedly a wave of firings of both Meta employees and contractors that had been profiting from the system. It’s unclear when Oops was first made available, but the documents show that use of it steadily increased from 22,000 requests in 2017 to over 50,000 in 2020.

Account recovery tool restricted in the wake of internal investigation

The Oops system allowed Facebook employees (and select contractors) to email a private address with the email address of an account that they would like restored. So long as the request came from an approved source, the rules governing this appeared to be quite loose, allowing the employees to request expedited account recovery service on behalf of family, friends and business associates. Employees were only asked to list whether the request was on behalf of a personal contact, a Meta business partner, a celebrity or a member of Mark Zuckerberg’s personal team.

At least one of these internal sources was feeding a third-party account recovery service that charged people thousands of dollars for this special access. One of the cases listed by WSJ is that of an Instagram model who paid $7,000 to one of these services, whose owner confirmed that they had an “inside contact” at Meta who facilitated account recovery.

The report also indicates that some of the fired contractors were loathe to give up this lucrative side gig after being removed from the premises, reaching out to Facebook employees to assist in Instagram account hijacking schemes. One of these, who was named in the internal documents and interviewed, has been threatened with charges under the Computer Fraud and Abuse Act. The man claims that security contractors are briefed on the Oops service as part of employment but not told about any restrictions on its use. Meta says that it conducts standard training on the use of Oops as part of its onboarding process, to include phishing training.

In total about 24 Meta employees and contractors were fired over bribe-taking or account hijacking issues. Meta has told the media that it has taken “appropriate action” to secure the system. Account hijacking has become an increasing problem recently, as criminals find creative new means of monetizing social media accounts that were previously seen as having too little value to expend any real energy in attacking.

 

Tags
Account HijackingAccount RecoveryMeta
Scott Ikeda
Senior Correspondent at CPO Magazine
Scott Ikeda is a technology futurist and writer for more than 15 years. He travels extensively throughout Asia and writes about the impact of technology on the communities he visits. Over the last 5 years, Scott has grown increasingly focused on the future landscape of big data, surveillance, cybersecurity and the right to privacy.
Related
Finger tapping icon on mobile phone screen showing EDPB guidance for data protection regulators on Meta's consent or pay model
Data ProtectionNews

EDPB Issues Guidance to Data Protection Regulators on Meta’s ‘Consent or Pay’ Model: “Real Choice” Must Be Offered

May 6, 2024
Meta logo on device screen showing GDPR complaint on withdraw consent
Data ProtectionNews

New GDPR Complaint Filed Against Meta by noyb; Company Accused of Ignoring Right to Withdraw Consent With “Privacy Fee”

January 18, 2024
Meta logo on mobile phone showing GDPR complaint on ad-free service
Data ProtectionNews

noyb Challenging Meta’s Ad-Free Option in New GDPR Complaint

December 12, 2023
Meta logo is shown on a device screen showing EU ban over behavioral advertising
Data ProtectionNews

Meta Behavioral Advertising Restrictions That Began in Norway Expand to EU Ban

November 6, 2023
Meta logo on device screen showing EU ban for Meta tracking ads
Data ProtectionNews

Norwegian DPA Seeks to Expand Fine on Meta for Tracking Ads, Raises Possibility of an EU Ban

October 2, 2023
Meta logo on device screen showing switch to user consent for targeted ads
Data ProtectionNews

Blizzard of EU Regulation Triggers Changes at Meta, Company Will Now Obtain User Consent Before Serving Targeted Ads

August 16, 2023
Woman's hand touching screen on tablet showing Meta fine in Australia for personal data usage
Data ProtectionNews

Meta Fined $20 Million in Australia Over Personal Data Usage

August 3, 2023
Facebook logo on smartphone screen showing Meta Norway fine for targeted advertising
Data ProtectionNews

Meta Facing Severe Targeted Advertising Restrictions, Potential $100,000 Per Day Fine in Norway

July 27, 2023
- Advertisement -
- Advertisement -

Latest

Hacker working showing third-party data breach

Oxford Confirms Third-Party Data Breach Impacting CareerConnect Platform Exposed Personal Information

People icons showing Chinese espionage through LinkedIn recruitment

Five Eyes: Chinese Espionage Uses LinkedIn Recruitment to Target Security and Intelligence Officers

World map and data showing Mythos AI in cyber operations

Inside Source Claims Anthropic Has Sent Mythos AI Engineers to NSA for Cyber Operations Training

Virtual screen with brain showing national security concerns with AI models

New US National Security Order Calls for Pre-Release Access and Assessment of AI Models

- Advertisement -
- Advertisement -
- Advertisement -
- Advertisement -

Learn More

About
Contact
Our Advertising
Privacy Policy
Cookie Policy
Terms of Use

CPO Magazine

News, insights and resources for data protection, privacy and cyber security professionals.

Learn More

About
Contact
Our Advertising
Privacy Policy
Cookie Policy
Terms of Use

Categories

Data Privacy
Data Protection
Cyber Security
Tech
Digital
Insights
News
Resources
Press Releases

© 2025 Rezonen Pte. Ltd.
CPO Magazine - News, Insights and Resources for Data Privacy, Protection and Cybersecurity Leaders
  • Home
  • News
  • Insights
  • Resources
    Start typing to see results or hit ESC to close
    Data Breach U.S. Cyber Attack Regulations Ransomware Attack
    See all results