MilikMilik

Instagram's AI Chatbot Flaw Exposed 20,000 Accounts to Password Reset Attacks

Instagram's AI Chatbot Flaw Exposed 20,000 Accounts to Password Reset Attacks
Interest|Mobile Apps

What Happened: Defining Instagram’s AI Account Recovery Vulnerability

Instagram’s recent account recovery vulnerability was a security flaw in an AI-assisted support chatbot that allowed attackers to reroute password reset emails for other people’s accounts to attacker-controlled email addresses, enabling account hijacking when two-factor authentication was not enabled. Meta confirmed that this Meta AI security flaw affected 20,225 Instagram users and was exploited through the platform’s AI-assisted account recovery system. The bug became widely known after a hijacking technique spread on Telegram and social media, prompting reports of Instagram account hacked incidents from everyday users and high-profile targets. Meta later disclosed the issue to regulators and described it as a failure in backend checks rather than a fault in the AI agent itself. The incident highlights an account recovery vulnerability at the intersection of automation, identity verification, and sensitive account access.

How Attackers Exploited the Password Reset Attack Path

The attack centered on Instagram’s AI-assisted High Touch Support tool for locked-out users. Normally, the chatbot should send a password reset link only to the email address already tied to an account. Instead, due to a bug in a separate code path, the system failed to check whether the entered email matched the one on file. Attackers could ask the bot to send a reset link to any email they controlled, as long as the request came from an IP address in the same region as the victim’s account. Once the reset email arrived, they opened the link, changed the password, and took over the account if two-factor authentication (2FA) was not enabled. Meta wrote that “the system did not properly verify that the email address provided… matched the email address associated with that user’s Instagram account.”

Instagram's AI Chatbot Flaw Exposed 20,000 Accounts to Password Reset Attacks

Impact: Who Was Affected and What Data Was at Risk

According to Meta’s filing, the password reset attack impacted 20,225 Instagram users, with unauthorized third parties able to gain access in some cases. PCMag reports that the flaw enabled pro-Iranian hackers to temporarily seize notable accounts, including Barack Obama’s former White House Instagram, Sephora, and the Chief Master Sergeant for the US Space Force. Once inside, attackers could view and possibly misuse personal data such as email addresses, phone numbers, dates of birth, direct messages, posts, and account activity history. Meta stated, “We are unaware of what, if any, personal information was accessed,” but the risk remains significant given the sensitivity of direct messages and profile data. For many victims, the first visible sign that their Instagram account was hacked would have been a sudden lockout, changed contact details, or unfamiliar posts appearing on their profile.

Meta’s Response and What It Means for AI Support Systems

Meta says it identified active exploitation of the account recovery vulnerability at the end of May and responded the same day. The company disabled the AI-assisted support tool, removing the vulnerable code path from production, and invalidated all password reset links generated through the flawed process so unused links could no longer be abused. Meta also forced potentially affected users through a security checkpoint, asking them to reset passwords and verify recent logins. In its notice, Meta wrote it will fix the authentication check so email addresses are properly matched before any reset is allowed and is reviewing similar flows across its platforms. This incident shows how AI-powered support systems that handle sensitive tasks like account recovery must still rely on strict, well-tested identity checks to avoid exposing users to mass account hijacking.

Practical Security Steps: How to Protect Your Instagram Account Now

If you worry your Instagram account was hacked or exposed in this password reset attack, start by changing your password to something long and unique and avoid reusing it on other services. Enable two-factor authentication immediately using an authentication app or SMS; Meta notes that attackers could only sign in if 2FA was disabled. Check your account’s email and phone number in settings to confirm they match your own, and review recent logins and connected devices for anything unfamiliar. Remove suspicious sessions and revoke access for unknown apps. Watch for new login alerts, unexpected password reset emails, or changes to your profile. Finally, be cautious of messages or emails claiming to be from Meta support; always access account recovery and security settings directly through the Instagram app or official website rather than through links sent by others.

Milik earns a commission when you shop through our links, at no extra cost to you. This article was generated with AI from published sources and product data.

You May Also Like

Comments
Say something...
No comments yet. Be the first to share your thoughts!