MilikMilik

Meta AI Bug Exposed Thousands of Instagram Accounts to Takeovers

Meta AI Bug Exposed Thousands of Instagram Accounts to Takeovers
Interest|Mobile Apps

What the Meta AI Security Vulnerability Was and Who It Affected

Meta’s AI security vulnerability was a flaw in Instagram’s AI-assisted account recovery tool that allowed attackers to reset passwords and take over accounts without passing normal email verification checks, exposing personal data and enabling unauthorized access to thousands of profiles. Meta uses an AI-powered support chatbot called High Touch Support to help people who are locked out regain access to their Instagram accounts. Instead of relying on passwords or security questions alone, the system sends password reset links via email. Because of a bug in a related code path, the tool failed to confirm that the email supplied during recovery matched the email registered to the Instagram account. This account takeover vulnerability meant attackers could trigger password reset links to addresses they controlled, turning a helpful AI “support” feature into an unexpected backdoor for an Instagram account hacked scenario at scale.

Meta AI Bug Exposed Thousands of Instagram Accounts to Takeovers

How Hackers Used Meta’s AI Support Bot to Hijack Instagram Accounts

Attackers learned they could talk to Meta’s AI chatbot and persuade it to send password reset links for accounts they did not own. Instead of blocking mismatched information, the flawed workflow accepted a new email and proceeded. Meta explained that “the system did not properly verify that the email address provided by the individual requesting a password reset matched the email address associated with that user’s Instagram account.” In practice, hackers requested help through High Touch Support, supplied a different email address, and received working reset links. Once they changed the password, they could log in to any affected account that did not have Instagram two-factor authentication enabled. Reports indicate the technique worked especially well when combined with VPNs to mask suspicious access patterns, allowing intruders to quietly test large numbers of profiles until they found accounts without extra security enabled.

How Many Instagram Accounts Were Exposed and What Data Was at Risk

Meta’s disclosures and independent reporting point to a significant but uneven impact. In a notice to regulators, the company described 20,225 affected Instagram accounts, while internal documents seen by The New York Times suggest around 34,000 accounts were touched by the Meta AI security vulnerability, with roughly 20,000 of those accounts likely compromised. According to Android Authority, affected users faced unauthorized password changes, altered usernames, and temporary loss of control over their profiles. Once attackers gained access, anything inside the account could be exposed, including email addresses, phone numbers, birth dates, profile details, posts, direct messages, and activity history. Some hijacked accounts, including high-profile and organizational profiles, were used to publish inflammatory or political content before Meta intervened. Meta says it is not aware of exactly which personal information was viewed in each case, but it has notified impacted users.

Meta AI Bug Exposed Thousands of Instagram Accounts to Takeovers

What Meta Fixed—and Why AI Account Systems Need Extra Care

Meta has now patched the account takeover vulnerability and paused the specific recovery tool that caused the problem. The company says the flaw was in the verification logic around the AI assistant, not in the AI model itself. In other words, the chatbot followed the rules it was given, but those rules did not enforce strong enough checks on who should receive a password reset link. Meta has restored access to affected Instagram accounts and says it has tightened email validation and recovery flows. However, this incident highlights a wider risk: as companies hand more security-critical tasks to AI-driven support, a single bug can be repeated thousands of times in minutes. Automated tools that can reset passwords or change recovery emails should be treated as high-risk systems, with strong validation, monitoring, and limits on what an AI agent can change without human review.

Practical Steps: How to Protect Your Instagram Account Now

Even though Meta has fixed this specific bug, you should treat your profile as at risk until you confirm it is safe. Start by enabling Instagram two-factor authentication in the app’s Security settings; accounts with 2FA were far harder for attackers to fully control during this incident. Next, review your login activity for unknown devices or locations, and log out of any sessions you do not recognize. Check your account email and phone number, making sure they have not been changed, and update your password to a unique one that you do not reuse elsewhere. If you suspect your Instagram account was hacked, use the official in-app recovery flow rather than links sent by email or direct message. Finally, be cautious about relying on any “support” links you find through search or social media; always confirm you are dealing with Meta’s official channels.

Milik earns a commission when you shop through our links, at no extra cost to you. This article was generated with AI from published sources and product data.

You May Also Like

Comments
Say something...
No comments yet. Be the first to share your thoughts!