Cyber Incident Victim: Meta Platforms, Inc.
Timeline
Summary
Meta Platforms, Inc. paused an AI training initiative that collected employee keystrokes and mouse movements after researchers inadvertently transferred the data to an internal location where it was not authorized. The discovery prompted a temporary halt while the company investigated the exposure, addressed workforce concerns about privacy and morale, and reviewed the program's data variety and opt‑out mechanisms.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 0 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
In April 2026 Meta launched the Model Capability Initiative, a program that installed tracking software on the majority of its US employees to record keystrokes and mouse movements for AI model training. The company mandated participation, telling employees they could not opt out of the data collection. The initiative drew significant backlash from the workforce. Andrew Bosworth, Meta's chief technology officer, later described employee morale as 'probably one of the worst it's ever been' in the company's two-decade history. The goal of the initiative was to collect diverse user interaction data to train Meta's AI models.

In June 2026 Bosworth disclosed in an interview with The Atlantic's Nicholas Thompson that the keystroke data had been inadvertently moved by a researcher to an internal location where it was not supposed to reside. He emphasized that only a small number of individuals had access to the data and that there was no evidence of a breach or foul play. The misplaced data, which was in a transformed state, had 'landed someplace that it shouldn't have landed internally,' according to Bosworth. Following the discovery, Meta began 'locking the whole thing down' while it investigated how the data ended up in the unauthorized location. Simultaneously, screenshots shared with Business Insider showed that a leak had made sensitive employee data accessible to the entire company, prompting the pause of the initiative in June.
A Meta spokesperson told Business Insider that the program had been designed with privacy safeguards and that, absent any indication of improper employee access, the pause was intended to allow a thorough investigation. Bosworth added that the initiative had been producing large amounts of repetitive data, noting that variance is more valuable than high volume of similar examples for AI training. He said that after a few weeks the company expanded opt‑out options for employees who did not wish to participate, describing the pause as an 'infinite pause' that workers could invoke at any time. Meta representatives declined to provide further comment on the matter when approached by Business Insider.