MilikMilik

Instagram's AI Chatbot Flaw Let Hackers Hijack 20,000+ Accounts

Instagram's AI Chatbot Flaw Let Hackers Hijack 20,000+ Accounts
Interest|Mobile Apps

What Happened: A Password Reset Vulnerability in Meta’s AI Chatbot

Meta’s AI-assisted Instagram account-recovery chatbot vulnerability was a security flaw in its support system that allowed attackers to receive password reset links at their own email addresses, bypassing normal verification and letting them hijack accounts that did not have two-factor authentication enabled, potentially exposing contact details, direct messages, and linked services. Meta disclosed in a government data breach notice that 20,225 Instagram accounts were affected when hackers exploited a bug in its High Touch Support (HTS) tool for locked-out users. The bot was meant to send reset links only to the account owner’s registered email. Instead, a separate code path failed to check whether the email provided to the chatbot matched the email on the account. According to Meta’s report, this bug allowed “unauthorized third parties to receive a password reset link for accounts they did not own.”

Instagram's AI Chatbot Flaw Let Hackers Hijack 20,000+ Accounts

How Hackers Exploited the Account Recovery Chatbot

Attackers turned a convenience feature into an account recovery exploit. To trigger the password reset vulnerability, they opened Instagram’s AI-assisted recovery flow and convinced the chatbot to send a reset link to an email they controlled. The only regional safeguard—starting the process from an IP address in the same area as the victim—was weak and easy to work around for determined attackers. Because the system did not properly verify that the requested email matched the one on the Instagram profile, the reset link went straight to the attacker instead of the rightful owner. Once the hacker clicked the link and chose a new password, the account was theirs to control if two-factor authentication was disabled. This method spread quickly on Telegram and other social platforms, helping fuel a wave of “Instagram account hacked” reports as more people tried and shared the technique.

Who Was Affected and What Data Was at Risk

Meta says 20,225 users were affected by the Meta AI security flaw before the bug was found and fixed. Victims included both ordinary users and prominent accounts, such as the inactive Instagram handle for the Obama-era White House, beauty retailer Sephora, and a senior official in the US Space Force. For any hijacked account, criminals could access far more than profile pictures. Meta reported that attackers could potentially view personal contact information, email addresses, phone numbers, dates of birth, direct messages, and connected accounts or linked services. This goes beyond the nuisance of losing access to a profile and cuts into privacy and potential impersonation risks. The incident shows how tightly Instagram identities are woven into wider digital lives, where a single password reset exploit can open the door to private conversations, business communications, and other platforms tied to the same login.

Meta’s Response and What It Means for AI Support Tools

Once Meta confirmed the account recovery exploit, it disabled the AI-assisted support tool and removed the vulnerable code path from production. Password reset links generated through the abused method were invalidated, and impacted accounts were secured and restored where possible. Meta has said it will fix the authentication check before relaunching the chatbot and is reviewing similar recovery flows across its platforms. In a statement to regulators and the press, the company stressed that its internal backend checks failed, rather than the core AI decision-making. Still, this security incident underscores a broader risk: AI-powered support tools can introduce new attack surfaces when they connect directly to sensitive account actions like password resets. For users, the lesson is clear: any automated helper that can change security settings or send login links should be treated as a high-value target for hackers.

What You Should Do Now to Protect Your Instagram Account

If you worry your Instagram account was hacked or exposed in this breach, start with two-factor authentication (2FA). Enable 2FA in Instagram’s security settings using an authenticator app or SMS so attackers cannot take over your account with only a password reset link. Meta itself recommends that affected users “enable 2FA,” because accounts without it were the ones vulnerable to takeover. Next, review active sessions and login activity in your Instagram Security settings. Log out of devices or locations you do not recognize. Change your password to a unique, long passphrase that you do not reuse on other services. Then scan your account for unusual activity: new posts, DMs you did not send, changed email or phone number, or connected accounts you do not recognize. Finally, stay cautious with account recovery messages and chatbot interactions, and avoid sharing verification codes with anyone.

Milik earns a commission when you shop through our links, at no extra cost to you. This article was generated with AI from published sources and product data.

You May Also Like

Comments
Say something...
No comments yet. Be the first to share your thoughts!