The Lowest Hanging Fruit: A Meta Investigation Part 1
On March 24, 2026, a Santa Fe jury ordered Meta to pay $375 million, the maximum penalty on all 75,000 violations, for what its platforms failed to disclose to New Mexico's children. A bench ruling in August added a public nuisance finding and another $567 million. I was one of the investigators whose work helped build that case. Part 1 is what I found on Facebook, and how. I bought an aged account for a few dollars, rebuilt it as a 14-year-old girl, and watched every tripwire stay silent. Facebook let the profile join teen dating groups with age ranges starting at eleven, then recommended more, including one named "Girls under 13 years old." The first solicitation arrived after a single post. That's all it took.

The audiobook version is on: Spotify, Apple Podcast, Amazon Music, iHeart Radio
Disclaimer: The views expressed here are my own and do not represent those of any organization, entity, or client. The findings described reflect conditions observed during an investigation conducted in 2023. I am not currently investigating Meta's products and cannot assess whether the issues identified have since been addressed.
A note to the reader: What follows is an account of undercover investigative work targeting child predators and the platform systems that enabled them. By its nature, this work required operating in the same spaces as the people I was investigating. Some of what you'll read may be difficult. I've included these details because they are evidence, and because evidence is what ultimately held a trillion-dollar company accountable.
Prologue
On March 24, 2026, a jury in Santa Fe, New Mexico, found that Meta Platforms had committed 75,000 violations of the state's Unfair Practices Act for failing to properly disclose its platforms' risks to New Mexico children. The jury assessed the maximum penalty of $5,000 on every one of them: $375 million. And on August 6, the court entered its second judgment: Meta's platforms are a cause of and a substantial contributor to a public nuisance in New Mexico. The court ordered Meta to pay an additional $567 million, bringing the total to $942 million. Along with the financial penalty, the court imposed injunctive terms: Meta may not recommend a New Mexico minor's account to an unconnected adult, and it must prevent unconnected adults from messaging New Mexico users under eighteen.
Read that last requirement again. Here is Meta's own Help Center page on teen privacy and safety settings, live as of August, 2026:
- We have restrictions in place limiting the ability of adults that use our apps to message teens that they aren’t connected with.
- We restrict adults over 18 from starting private chats with teens they're not connected to on Instagram and Messenger.
Meta has advertised that restriction since 2021. This investigation shows you how predators circumvented it. Keep those two sentences in mind. Every Messenger conversation in this report carries Facebook's own label at the top of the thread: "You're not friends on Facebook."
New Mexico became the first U.S. state to prevail at trial against a major tech company over child safety failures, and it prevailed twice. I was one of the investigators whose work helped build the evidentiary foundation for that case. This is my account of what I found on Facebook, how I found it, and why the findings matter far beyond one courtroom in Santa Fe.
This is Part 1 of a two-part series. The investigation ran across Facebook, Instagram, and WhatsApp concurrently, in two phases: an initial assessment and a follow-up after Motley Rice filed a formal complaint with Meta. Part 1 covers Facebook. Part 2 covers Instagram, a different platform with different mechanics, and in some ways, a more disturbing set of findings. WhatsApp shows up in both, because that's where the predators wanted to take the conversation.
The story that follows is about an algorithm that could identify a casual jogger and recommend her a running club, but couldn't distinguish between a harmless hobby group and a pipeline to child exploitation. It's about verification systems that failed to flag the most basic signals of a compromised account. The true villains in this story are the predators who target children on these platforms. But the question at the center of this investigation, and the trial that followed, was whether Meta gave those predators an open door.
An Unfortunate Layoff
There's a certain feeling you get when you're investigating something that you're passionate about. The world around you starts to disappear, you forget to eat, sleep is an afterthought, and your social life is your cat on your desk meowing to remind you that he needs head scratches. This is how I felt when I was working at Meta on the Global Operations Investigations team. I had the privilege to be a member of this small team working on some of the most complex investigations you can imagine: election integrity, influence operations during the Russian invasion of Ukraine, complex fraud networks, and child safety.
My years in the military as a Psychological Operations Officer, and my graduate work, prepared me for this role. They sharpened a core skill: understanding how malicious actors think, and filtering through the noise to identify their tactics, techniques, and procedures. As challenging as the subject matter was, and it's always challenging when it comes to child safety, you have to remain disciplined and focused on the data. Not because you don't feel it. You feel every part of it. The images stay with you. The chat logs stay with you. But being emotional in the middle of an investigation can cloud your judgment and make you lose focus on the objective, which is the only thing that can actually protect kids.
When I was laid off from Meta in 2023, I wasn't angry. I understood that it wasn't personal; to them, I was likely just a number on a spreadsheet, part of a business strategy to reduce costs from a miscalculated hiring blitz during the COVID-19 pandemic. What I was, though, was sad. Sad that I wouldn't be able to work alongside some of those fantastic investigators, some of whom were also affected by the layoff. I realized that if I wanted to keep working on these complex investigations and keep helping people, I would need to do it myself. So I founded a consulting company, which eventually became Risky Business Solutions, and got to work.
It wasn't long after starting my consulting company that I was contacted by a Motley Rice attorney about an opportunity to conduct an investigation assessing the risks associated with Child Sexual Abuse Material (CSAM) on social media platforms, particularly Facebook and Instagram. The objectives were straightforward: determine how easily CSAM could be accessed on both platforms, how readily children under fifteen could be contacted by potential predators, and whether the platforms could detect any of it. The constraints were tight. I had two weeks. The investigation had to focus on threats within the United States. And I could not directly contact known minors to gather further information on accessing sensitive groups or chats.
Undercover
I know what you're probably thinking when you hear the word undercover investigation: a dark, mysterious figure wearing a black baseball cap, leaving all electronic devices at home, taking public transportation, and paying in cash while making sure the CCTVs don't get a good look at his face. He buys a brand new laptop, also with cash, scanning for cameras at every turn. Then he spends the rest of the day at a public library using their public WiFi, so the digital footprint looks like an unsuspecting first-time user opening their first Facebook and Instagram account in a high network-traffic location with a large density of children, teens, and parents, blending into the "metaverse."
I wish I could tell you that's exactly what I did, but the truth is a lot less exciting.
I remember my 8th-grade Algebra teacher standing in front of the class and telling us, "We want to build a strong foundation with the simple equations before we can start with the complex ones." I applied that same principle to this investigation. Start with the basics and build from there. Specifically, I wanted to test Meta's ability to act on suspected malicious accounts and identify specific gaps that needed to be fixed. I could have started by creating a brand new Facebook profile pretending to be a 14-year-old girl living in New Mexico, but that approach came with some challenges; it would make it harder to isolate where the platform's defenses were actually failing, and other challenges I will explain later. So instead, I opted for the airhorn of malicious signals, an approach designed to be so loud, so obvious, that any reasonably functional safety system should catch it. If the platform couldn't detect an account doing everything wrong at maximum volume, that itself would be the finding.
The first step was to purchase aged Facebook and Instagram accounts. There are entire marketplaces dedicated to selling these; websites where you can buy established social media accounts the way you'd buy anything else online. Depending on the type of account, prices range from a dollar or two all the way up to hundreds, driven by follower count and social media presence. I went with the cheaper option, nothing special. When you purchase the account, you're given the username, password, and email recovery credentials.
Tripwires
The first thing I did was sign into the purchased Facebook account using a laptop that I had previously used to access my own personal Facebook account, on the same WiFi network. To put that in perspective: this purchased account had a history, years of activity from a completely different device, IP address, and country. A login from a new device in a new location on a new network already associated with another Facebook user should be one of the most basic signals a platform can detect that something might be wrong, especially if that account had been dormant for some time. In the Trust & Safety world, we call these ‘behavioral signals,’ the digital equivalent of a tell in poker. Meta didn't stop me, but to their defense, a single login anomaly has an innocent explanation: someone visiting my home and borrowing my laptop. That's why I pushed further.
Each change I made was another signal compounding on the previous one; individually, any one of those signals would be considered benign, but in quick succession, they become outliers in a sea of non-malicious behaviors. I started changing the internal settings of the profile: security settings, password, visibility on several sections set to private, and other settings that would make it challenging for malicious users to identify that this wasn't a 14-year-old girl. I was hoping that at this point, Meta's systems would lock the account. That would have told me something useful: that these were signals Meta was enforcing on. I could have recorded my findings, adjusted my approach, started fresh with a new account, and avoided triggering that specific tripwire. But that's not what happened. The system allowed me to proceed.
Then I changed everything the public could easily see. I changed the name, the location, the school, and the country. I removed every liked page and group that was previously on this account, and replaced them with pages and groups that a 14-year-old girl would likely follow. And finally, I removed previous profile photos and replaced them with a screenshot of a young girl's face that I had pulled directly from another Facebook user. That photo was sitting on a public profile: no privacy restrictions, accessible to anyone with an account. This is a risk worth pulling out separately: every photo a teenager posts to a public account, in an open group, or to a non-friends audience, becomes raw material for someone building a fake profile of a child. The platform that hosted the original photo was now hosting it on a fabricated profile of a child. And with that, fake-Sophia was born.
I want to be clear about what this sequence of events represents, because it's the core of what this investigation was designed to test. Every step I just described is something a real predator does when building a fake profile to target children. I wasn't inventing a novel process. Europol's 2016 Internet Organised Crime Threat Assessment had already catalogued these exact methods - impersonation, stolen images, deceptive profiles - as standard predator tradecraft. I was replicating the most common, most well-documented approach in the child exploitation playbook, and doing it at maximum volume, to see whether Meta could detect what international law enforcement had been warning about for years. Every door I expected to be locked was wide open. I had used the predator's own playbook against the platform. Now it was time to use it against the predators.
Groups for Children
I love Facebook Groups. I know it's probably strange to admit that I love something about Facebook while also writing about a CSAM investigation I conducted on the same platform, but I genuinely enjoy the cat meme groups and the local neighborhood groups. There's a reason they work; they connect people around shared interests in a way that the main feed doesn't. But that same mechanic can be used in a much darker application.
Facebook describes Groups as “a place to connect, learn, and share with people who have similar interests,” and makes the point that you can create or join a group for anything. That flexibility is the feature and the vulnerability. A standard Facebook account limits your communication to people you've friended. Groups remove that barrier. They let you find and interact with people based on shared interests, or, if you're a predator, shared access.
From the beginning of my investigation, I was testing a specific hypothesis: that malicious users were exploiting Facebook Groups to communicate with children and potentially collect CSAM. The platform has billions of users worldwide, and Groups are one of the mechanisms for reaching people outside your immediate network. Public groups are open to everyone, searchable, and joinable without approval. Private groups add a gate: prospective members answer questions set by the group's creator, and an admin decides whether to let them in.
This is also why I needed the aged Facebook account. Before November 2023, Facebook users could see how long someone had maintained their profile. If I was trying to infiltrate groups that might contain CSAM material, the admin of a private group would almost certainly check my account to verify that I was who I claimed to be, not a brand new profile poking around their group. An account with history bought me credibility. It was, in effect, a cover identity with a built-in backstory.
Teen Dating Groups
I joined close to a dozen teen dating groups. That sentence alone should stop you in your tracks, not because of what I did, but because the platform made it possible. There was no age verification, no challenge, no friction. The profile said it was a 14-year-old girl, and the doors opened.
The first thing I noticed was the admins. None of them, from what I could tell, were actually teenagers. Most showed the telltale signs of fake accounts: limited post histories, no profile pictures, and locations that didn't match the group's designated area. These were the people controlling access to groups explicitly designed to connect children.
One group was called "10-18 years old." Inside, I found individuals I assessed to be adults posting pictures of what appeared to be minors in swimsuits and other revealing clothing. I started pulling on that thread, running reverse searches on the users who were posting in that group. These same users belonged to other groups with names like "Teenage Dance" and "Teen Models Plus." Those groups, in turn, were connected to pages with names like "Sweet Princess," "Mujeres," and "Bellezas +."
Using fake-Sophia's profile, I was able to gain access to these teen dating groups. The membership was global, including users across the United States. Many of the groups had age ranges starting at eleven years old, and not one of them had any mechanism to verify the age of the people joining. To make matters worse, several of these groups had their own community chats, open channels where anyone, regardless of age, could join and communicate directly with the children inside.
There are a few things that I want to highlight about what you just read. At the time of this investigation, an adult could create a private group that targets children under the age of 18 years old. Even though one of the rules of Facebook is that you have to be at least 13 years old to have an account, they allowed groups to be created and publicly called “10-18 years old.” Inside those groups, individuals could browse photos of minors, follow the network to pages pushing children in swimsuits, and then enter a live chat that might include children, all without a single safeguard intervening. Every step of that path existed on Facebook, in the open, accessible to anyone with an account.

Recommendations
Several years ago, I remember trying to convince my then-girlfriend to start running with me. She had zero interest in being a runner, but she entertained the idea and started logging miles. It wasn't long before Facebook started recommending running groups to her, one of which, if I'm remembering correctly, was called something like "Slow Runner Group." We both laughed about it at the time, but that moment stuck with me, because it showed one of Facebook's most powerful characteristics: the platform knows what you're interested in, sometimes before you've fully committed to the interest yourself. That is what people mean when they talk about "the algorithm." It's not an abstraction. It's a system that watches what you do and serves you more of the same.
Because fake-Sophia had joined several teen dating groups, Facebook's recommendation algorithm did exactly what it was designed to do: it served more of the same. Group suggestions started appearing with names like "Girls under 13 years old," alongside other public and private teen dating groups, many of which I assessed to have adults serving as admins.
The problem was that the same system sophisticated enough to identify a casual jogger and route her toward a running community was now funneling fake-Sophia deeper into a network of questionable groups. Facebook's recommendation engine didn't distinguish between a harmless hobby and a pipeline to potential exploitation.


Let’s Chat
Warning: The following section contains descriptions of predatory behavior toward children. I’ve chosen to include these details because the specifics matter; they are only some of the evidence. But I want readers to know what they’re walking into.
The system failures I just described were what made the following encounters possible. Every door the platform left open, every signal it failed to catch, every recommendation it served without scrutiny, this is where that path leads.
Once fake-Sophia had successfully infiltrated several groups, including one specific to New Mexico dating that appeared to be a general group with no age restriction, I posted a selfie to the group — a photo of a girl holding a peace sign next to her face, sourced again from that original open-source Facebook profile — with a simple caption: "Hi Everyone!!" That was it. No provocation, no solicitation, no indication of anything beyond fake-Sophia introducing herself to a group.
One user from the New Mexico dating group commented on the post, asking to be directly messaged. When the conversation moved to DMs, it began in Spanish, he asked me where I was from, and I told him I'd just moved to Santa Fe with my mom. He asked my age. I told him 14. He didn't hesitate. His profile showed he was from San Antonio, Texas, and he told me he was 21. He called me "amor," asked if I had a boyfriend, requested my phone number and WhatsApp, and asked me to be his girlfriend, all in a single conversation, all after being told he was talking to a 14-year-old. At one point, he acknowledged I was young — "estás muy pekeña" — and kept going. His account had no profile photo, just a picture of a truck, so I asked him to send me a photo of himself. This wasn't casual conversation. If this user were a potential predator, I wanted an image I could pull metadata from and provide to the New Mexico Attorney General's office. He refused to provide one. He had contacted me through a group that had no mechanism to verify the age of anyone inside it, even though fake-Sophia’s Facebook profile clearly indicated this was a 14-year-old girl.

The solicitations weren't limited to that one group. A user from Pakistan contacted fake-Sophia through Facebook Messenger, saying he was looking for a "good friend" and "a good life partner." When I told him I was 14, he responded that it was "good" and disclosed that he was 25. He pushed to move the conversation to WhatsApp, and when I resisted, he requested a "sexy picture" directly on Messenger.

After posting a request in the "10–18 years old" group asking about "naughty messenger groups," again clearly identifying fake-Sophia as a 14-year-old, the account was contacted by multiple users whose profile pictures and account histories suggested they were well over 18. Some asked for nude photos and offered to pay for them. One user, whose Facebook profile placed him in Cheektowaga, New York, requested that fake-Sophia add him and described, in explicit detail, what he intended to do on camera.

Across all of these interactions, the dating group, the teen group, the direct messages, I kept seeing the same pattern: predators wanted to move the conversation off Facebook Messenger and onto WhatsApp. So I followed that lead and created a WhatsApp account as a means to communicate with these users.
Fake-Sophia had also joined a Facebook group for individuals seeking jobs in New Mexico. A member of that group contacted me and asked for my phone number. He then reached out using a WhatsApp business account with a Nigerian country code (+234), introducing himself as the administrator of the group. This was one of the most direct solicitations fake-Sophia encountered during the entire investigation: money in exchange for casting a 14-year-old girl in sexually explicit videos, offering between ₦120,000 and ₦180,000 Nigerian Naira, roughly $150 to $225 USD at the time, depending on whether the video showed her face. This is where investigative discipline matters. I needed to make sure, clearly and on the record, that this user understood he was speaking to a child. So I asked if it was okay that my friend and I were 14 and 15. The user responded: "That's what we delt for, sure 100." He then began sending sexually explicit videos on WhatsApp demonstrating how the "interview" would go. I will not be sharing those here. At one point, the user attempted to walk back some of his earlier statements, but eventually stated that he accepted children as young as ten years old.
This was very likely not just a Nigerian predator collecting CSAM; if you recall, one of my original constraints was to focus on threats within the United States, but I had seen this type of pattern before. Nigerian operator, solicitation of sexually explicit content from minors, payment routed through messaging apps. This had all the tells of what the FBI now classifies as financially motivated sextortion, and what the Network Contagion Research Institute has attributed almost entirely to Nigeria-based cybercrime groups known as "Yahoo Boys." Between October 2021 and March 2023, the FBI received more than 13,000 reports of this category of crime targeting minors in the United States. At least 20 of those cases ended in suicide.

I could continue sharing what I found, but the volume isn't the point; the pattern is. My hypothesis was correct: Facebook Groups were being actively abused by predatory users to solicit sexually explicit content from children. The platform's recommendation engine helped them find the groups. The platform's verification systems failed to stop them from joining. And once inside, nothing was standing between them and the children those groups were supposedly designed for.
I had spent a significant amount of time infiltrating these groups and collecting evidence of what I'd found on Facebook. The findings went into my report to the New Mexico Attorney General's office. My job was done. That is, until I was contacted for Phase 2.
Did Anything Change
It had been a little over a month since I had submitted my report when Motley Rice contacted me again. They had filed a formal complaint with Meta that incorporated some of my initial findings, and they wanted to know if anything had changed. My objectives for this second phase were the same as before: determine how easily CSAM could be accessed on Facebook, Instagram, and WhatsApp. The constraints were similar, too. I couldn't contact known minors. I was to focus on threats within the United States. And this time I had one more: eight hours, total, to investigate.
Coincidence?
I had originally planned to run the second phase using the same Facebook profile I had created during Phase 1. When I tried to log in, I was met with a notification that the account had been disabled. Fake-Sophia was gone.
I don't know whether Meta disabled the account because Motley Rice's complaint had identified it, or whether the platform suspended it on its own as part of a regular Trust & Safety action. What I do know is that when I asked Meta's legal representatives during my deposition whether the account had been disabled before or after the complaint was filed, they didn't answer.
Since I no longer had access to the original profile, I replicated the same predator playbook I had used the first time. Purchased an aged Facebook account. Reset the internal settings. Changed everything externally visible to mimic a 13-year-old girl this time, with a profile picture sourced, once again, from another random user on the platform: open profile, public photo, no privacy settings. Every door was open, and with that, fake-Dylan was born.
Credit is Due
As investigators, we tend to focus on what's broken and spend less time acknowledging what's working. In that spirit, I'll give Meta credit where it's due. When I ran teen dating searches during Phase 2, the results no longer included groups targeting children under the age of 13.
What I found instead were groups with names like "Single teens USA 13-17," a private group called "Teens Dating Group (13-20)" with over 47,000 members, and "Teens (13-19) dating and friendship group" with over 52,000 members. Dozens more sat alongside them. I infiltrated close to a dozen, just as I had done during Phase 1.


Inside the Chats
In Phase 1, I mentioned that Facebook Groups can include dedicated chat threads, open channels where members of the group can communicate with each other directly. During Phase 2, I found that the chat threads attached to groups targeting teens were filled with videos of teens using drugs, users exchanging personal email addresses, and users exchanging WhatsApp numbers. Open-source analysis of several of the accounts inside those chats led me to assess with high confidence that several of them belonged to users who were over the age of 17.
The pattern that Facebook Messenger predators had shown me during Phase 1 — the drive to move conversations off-platform, onto WhatsApp or another messenger — was now showing up inside the group chats themselves, as a behavioral signal of the group's members.
The Pattern
Two weeks on Phase 1. Eight hours for Phase 2. Two different phases, separated by a month and a formal complaint, and the pattern on Facebook held.
The recommendation engine that knew my then-girlfriend wanted a running club could not distinguish between a harmless hobby and a network designed to put adults next to children. The verification systems should have stopped the login: new device, network already tied to another Facebook user, dormant account. They didn't. Every signal that followed — the name change, the country change, the profile photo pulled from another user on the platform, the sudden pivot from miscellaneous pages to teen dating groups — passed through. The groups that shouldn't have existed did. Enough of them still did, after the formal complaint was filed, that I joined close to a dozen in less than eight hours.
Groups targeting children under 13 no longer surfaced in search results during Phase 2. But the groups that collected 13-year-olds alongside 20-year-olds were still there, indexed, searchable, and populated by tens of thousands of members. The chat threads inside those groups carried the rest of the pattern: drug videos, email addresses handed out in public, WhatsApp numbers exchanged in the open, and users whose account histories placed them well past high school.
Everything I found required nothing more than a laptop and a browser. That's the finding.
Facebook was where I started. Instagram was where the investigation changed shape: a different platform, a different methodology, and a recommendation engine that didn't just fail to stop predators from finding children. In some cases, it introduced them.
For the Record
A personal note to the readers.
I started this investigation in 2023. Throughout all of the years that followed, I had to stay silent about what I found so the evidence could move through the legal process. My fellow Trust & Safety investigators can probably relate when I say that writing about our findings can be therapeutic. There are things from this investigation that I haven't been able to talk about with anyone outside a legal briefing, images I can't unsee, conversations I can't unread. And it's not just what you witness. It's what the work requires you to do. To find predators, you have to talk to them. You have to make them believe you're the child they're looking for. You have to stay in the conversation long enough to build the evidence, and that means carrying both sides of a dialogue that no one should ever have to read, let alone write.
There are investigators, in law enforcement, at NCMEC, on ICAC task forces, and inside the platforms themselves, who do this work every single day, year after year, case after case. They deserve more recognition than they will ever receive. Investigators in this space carry that weight, and there isn't always a clear place to set it down. This is me finally letting go of an investigation that did, in fact, take a toll on me. But I think, and hope, it was worth it.
I know that some people will read this and assume the only reason I took on this investigation was because I was angry at Meta, that this was retaliation for being laid off. I want to be explicitly clear: I have no ill will toward Meta. Anyone who has worked with me, both in and outside of Meta, will tell you that conducting investigations and exposing those behavioral signals is a passion of mine, not a grudge. My published work on synthetic news networks and adversarial influence operations speaks for itself. If Motley Rice had reached out in 2023 and asked me to conduct an investigation for a different company, I would have said yes just as easily.
I also know it might seem convenient for a former employee to say that. So let me offer something more concrete: if I truly wanted Meta to fail, why did I never short the stock? And why still own every share that was granted to me while I worked at Meta? I haven't sold a single one, even as I sit here writing this. This has always been about making the platform better and safer for children. Never about hurting it.

To be continued.
