The leak was discovered before external parties accessed it, and Meta stated no improper access occurred . But the severity rating (SEV 2) prompted an immediate pause
.
Backlash was immediate and sustained from the program's April launch:
The program captured data from designated work apps and websites, but Reuters reported that Meta acknowledged it could also capture communications involving non-US employees . EU privacy regulators began examining whether MCI violated GDPR requirements around consent, data minimization, and employee monitoring
.
The data leak itself — unencrypted databases containing private conversations and performance records — was the culminating event that forced the suspension . It turned months of internal privacy complaints into a concrete data breach that Meta could not ignore.
MCI was suspended not because of the employee backlash alone, but because a security configuration failure exposed the program's deeply sensitive data trove to the entire company. The incident turned months of internal privacy complaints into a concrete data breach, forcing Meta to halt the initiative while it investigates.