Some 40 workers in Facebook’s Dublin Headquarters have been hit by a security breach that saw their personal details inadvertently exposed to suspected terrorists.

Gardaí have been offering security assistance and advice to the Irish employees judged to be at highest risk, The Irish Times understands. The Office of the Data Protection Commissioner has said it is also aware of the breach.

At least one of the employees has approached the Personal Injuries Assessment Board seeking compensation from Facebook for the distress caused. It is understood more are considering taking legal action in the High Court.

The security lapse affected a total of more than 1,000 content moderators across 22 departments at Facebook who used the company’s moderation software to review and remove inappropriate content from the platform, including sexual material, hate speech and terrorist propaganda.

A bug in the software, discovered late last year, resulted in the personal profiles of content moderators automatically appearing as notifications in the activity log of the Facebook groups whose administrators were removed from the platform for breaching the terms of service. The personal details of Facebook moderators were then viewable to the remaining admins of the group, according to a report in The Guardian.

Dublin counter-terror unit

Of the 1,000 affected workers, around 40 worked in a counter-terrorism unit based at Facebook’s European headquarters in Dublin, Ireland. Six of those were assessed to be “high priority” victims of the mistake after Facebook concluded their personal profiles were likely viewed by potential terrorists.

The Guardian spoke to one of the six, who did not wish to be named out of concern for his and his family’s safety. The Iraqi-born Irish citizen, who is in his early 20s, fled Ireland and went into hiding after discovering that seven individuals associated with a suspected terrorist group he banned from Facebook - an Egypt-based group that backed Hamas and, he said, had members who were Islamic State sympathizers - had viewed his personal profile.

The moderator said he was hired because he spoke Arabic. He was paid €13 per hour, according to The Guardian.

Facebook confirmed the security breach in a statement and said it had made technical changes to “better detect and prevent these types of issues from occurring”.

“We care deeply about keeping everyone who works for Facebook safe,” a spokesman said. “As soon as we learned about the issue, we fixed it and began a thorough investigation to learn as much as possible about what happened.”

The moderator who went into hiding was among hundreds of “community operations analysts” contracted by global outsourcing company Cpl Recruitment. Community operations analysts are typically low-paid contractors tasked with policing Facebook for content that breaches its community standards.

Overwhelmed with fear that he could face retaliation, the moderator, who first came to Ireland as an asylum seeker when he was a child, quit his job and moved to eastern Europe for five months.

Beheading threat

The punishment from Isis for working in counter-terrorism is beheading.

“It was getting too dangerous to stay in Dublin,” he said, explaining that his family had already experienced the horrifying impact of terrorism: his father had been kidnapped and beaten and his uncle executed in Iraq. “The only reason we’re in Ireland was to escape terrorism and threats,” he said.

The moderator said that others within the high-risk six had their personal profiles viewed by accounts with ties to Isis, Hezbollah and the Kurdistan Workers Party. Facebook complies with the US state department’s designation of terrorist groups.

“When you come from a war zone and you have people like that knowing your family name you know that people get butchered for that,” he said. “The punishment from Isis for working in counter-terrorism is beheading. All they’d need to do is tell someone who is radical here.”

Facebook moderators like him first suspected there was a problem when they started receiving friend requests from people affiliated with the terrorist organizations they were scrutinising.

An urgent investigation by Facebook’s security team established that personal profiles belonging to content moderators had been exposed. As soon as the leak was identified in November 2016, Facebook convened a “task force of data scientists, community operations and security investigators”, according to internal emails seen by the Guardian, and warned all the employees and contracted staff it believed were affected. The company also set-up an email address, nameleak@fb.com, to field queries from those affected.

Facebook then discovered that the personal Facebook profiles of its moderators had been automatically appearing in the activity logs of the groups they were shutting down.

Craig D’Souza, Facebook’s head of global investigations, liaised directly with some of the affected contractors, talking to the six individuals considered to be at the highest risk over video conference, email and Facebook Messenger.

In one exchange, before the Facebook investigation was complete, Mr D’Souza sought to reassure the moderators that there was “a good chance” any suspected terrorists notified about their identity would fail to connect the dots.

“Keep in mind that when the person sees your name on the list, it was in their activity log, which contains a lot of information,” Mr D’Souza wrote, “there is a good chance that they associate you with another admin of the group or a hacker ...”

“I understand Craig,” replied the moderator who ended up fleeing Ireland, “but this is taking chances. I’m not waiting for a pipe bomb to be mailed to my address until Facebook does something about it.”

Software bug

The bug in the software was not fixed for another two weeks, on November 16th, 2016. By that point the glitch had been active for a month. However, the bug was also retroactively exposing the personal profiles of moderators who had censored accounts as far back as August 2016.

Facebook offered to install a home alarm monitoring system and provide transport to and from work to those in the high risk group. The company also offered counselling through Facebook’s employee assistance program, over and above counselling offered by the contractor, Cpl.

The moderator who fled Ireland was unsatisfied with the security assurances received from Facebook. In an email to Mr D’Souza, he wrote that the high-risk six had spent weeks “in a state of panic and emergency” and that Facebook needed to do more to “address our pressing concerns for our safety and our families”.

Exile

He told The Guardian that the five months he spent in eastern Europe felt like “exile”. He kept a low profile, relying on savings to support himself. He spent his time keeping fit and liaising with his lawyer and gardaí in Dublin, who checked up on his family while he was away. He returned to Ireland last month after running out of money, although he still lives in fear.

“I don’t have a job, I have anxiety and I’m on antidepressants,” he said. “I can’t walk anywhere without looking back.”

This month he filed a legal claim against Facebook and Cpl . He is seeking compensation for the psychological damage caused by the leak. Cpl did not respond to a request to comment. The statement provided by Facebook said its investigation sought to determine “exactly which names were possibly viewed and by whom, as well as an assessment of the risk to the affected person”.

The social media giant played down the threat posed to the affected moderators, but said that it contacted each of them individually “to offer support, answer their questions, and take meaningful steps to ensure their safety”.

“Our investigation found that only a small fraction of the names were likely viewed, and we never had evidence of any threat to the people impacted or their families as a result of this matter,” the spokesman said.