MilikMilik

Meta’s AI Support Bot Bug Exposed Instagram Accounts

Meta’s AI Support Bot Bug Exposed Instagram Accounts
Interest|Mobile Apps

What the Meta AI vulnerability was and who it affected

The Meta AI vulnerability was a verification bug in Instagram’s AI-powered support workflow that allowed attackers to change recovery emails and trigger password resets for accounts they did not own, enabling large-scale Instagram account compromise and exposing personal data for tens of thousands of users across multiple incidents. In practical terms, Meta’s AI-assisted “High Touch Support” bot mishandled a basic security check: it sent password reset links to email addresses that were not linked to the target accounts. One report notes that 20,225 Instagram accounts were impacted in one incident, while another cites a broader flaw touching about 34,000 users, with more than 20,000 accounts allegedly compromised. Victims ranged from regular users to businesses and public figures, some of whom saw their profiles hijacked for unauthorized posts before Meta stepped in.

How the account takeover bug worked

The core account takeover bug sat inside Meta’s AI-assisted recovery flow, not inside the AI model’s “thinking”. When users appealed a locked or hacked account, the High Touch Support chatbot could be manipulated into changing the recovery email address without proper verification. Once attackers set a new email, they requested a password reset link, which the system then sent to that attacker-controlled inbox. They did not need the original password, security questions, or prior access. Some hackers reportedly paired this method with VPNs to hide suspicious login locations and avoid fraud detection. One article compares it to a restaurant handing your food order to anyone who asks. Because the same workflow ran automatically at scale, the same mistake repeated thousands of times before engineers disabled the feature and began a review.

Scale of the Instagram security breach and exposed data

Across the reported incidents, over 54,000 Instagram accounts were touched by the Meta AI vulnerability, with more than 20,000 accounts apparently suffering full compromise. According to Android Authority summarizing a New York Times report, “around 34,000 Instagram users” were affected in one wave, with personal information such as email addresses, phone numbers, and birth dates exposed for roughly 20,000 of them. Additional users saw their usernames changed or temporarily lost access. Meta’s own disclosures indicate that access through the compromised workflow could have revealed direct messages, contact details, posts, and linked services. Some high-profile, business, and government-linked accounts were misused to publish unauthorized content before being restored. Even though Meta says it has no evidence of large-scale data exfiltration, the exposure shows how an Instagram security breach can unfold without traditional phishing or malware.

Meta’s reaction and continued AI expansion

Once Meta confirmed the Meta AI vulnerability, it shut down the affected High Touch Support system, reset passwords on impacted accounts, and forced users through extra security checkpoints. Meta has told regulators that it plans to fix the verification bug before relaunching the tool and is reviewing similar recovery flows across its platforms. At the same time, internal documentation described by reporters shows Meta paused only the specific Instagram password recovery experiment tied to the breach. Broader AI-powered support and customer service projects are moving ahead. The company attributes the incident to weaknesses in surrounding verification systems rather than the AI model itself. This distinction matters: the bot followed allowed actions, but the guardrails around those actions were too weak. The episode highlights how AI support tools magnify any security mistake embedded in their workflows.

How to secure your Instagram account right now

For users, the main defense against this sort of Instagram account compromise is to strengthen login security and watch for unusual activity. First, turn on two-factor authentication (2FA) in Instagram’s security settings; reports note that accounts with 2FA enabled were far more resistant because attackers still needed a second factor to get in. Use an authenticator app rather than SMS where possible. Next, review your account activity: check login history, recent devices, and any connected apps you do not recognize, and revoke access where needed. Regularly confirm that your recovery email and phone number are accurate and under your control so you can regain access if something goes wrong. Finally, treat any unexpected password-reset emails or “support” DMs as suspicious, and always perform account recovery through official in-app or website flows, not links sent by strangers.

Milik earns a commission when you shop through our links, at no extra cost to you. This article was generated with AI from published sources and product data.

You May Also Like

Comments
Say something...
No comments yet. Be the first to share your thoughts!