Meta halted its internal Model Capability Initiative (MCI) after a permissions misconfiguration exposed sensitive employee-monitoring data to the company’s broader workforce. The program, launched in April for U.S.-based employees, collected detailed telemetry including mouse movements, clicks, keystrokes, and occasional screenshots to train internal AI and machine-learning systems. Reuters-reported documents indicated the exposed data included private conversations, AI prompts and request transcripts, and other records gathered from internal systems.
Internal concerns had reportedly been raised earlier about both the intrusiveness of the monitoring and data-storage weaknesses, with a later security alert finding confidential information accessible in cleartext to Meta employees. The exposed material reportedly included named HR performance data and documents classified under DSS sensitivity levels 1 through 4. Meta said it has found no evidence of improper employee access or malicious exploitation, but it suspended the program while investigating and has not said when, or in what form, it may resume.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
In May 2026, Meta employees petitioned against the Model Capability Initiative, raising concerns about privacy protections and the scope of telemetry collection for AI training. The reference says workers questioned the lack of completed privacy reviews and the vagueness of proposed mitigations.
Reuters reported that data storage issues related to the MCI program had already been flagged in May. This preceded discovery that collected confidential data was broadly accessible internally.
An internal security alert determined that confidential MCI training data was accessible in cleartext to any Meta employee because of a permissions misconfiguration. Exposed data reportedly included AI prompts and transcripts, private employee conversations, HR performance data, and documents with DSS sensitivity labels 1 through 4.
Meta began deploying its Model Capability Initiative (MCI) to U.S.-based employees in April 2026 to collect telemetry such as mouse movements, clicks, keystrokes, and occasional screenshots for AI training.
On 2026-06-22, Meta halted the Model Capability Initiative while it investigated the internal exposure of sensitive employee monitoring data. Meta said it had no evidence that employees improperly accessed the data or that the issue involved external malicious exploitation.
Meta said it detected unauthorized internal access to MCI data on 2026-06-18 and fixed the issue within four hours. The company later acknowledged that the initial remediation was incomplete and that additional access restrictions were required.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
boingboing.net
Open sourcetomshardware.com
Open sourcepivot-to-ai.com
Open sourcecio.com
Open sourcescworld.com
Open sourcezdnet.fr
Open sourceghacks.net
Open sourcewired.com
Open sourcewired.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.