MilikMilik

Meta’s AI Support Bot Flaw Enabled 20,000+ Instagram Account Takeovers

Meta’s AI Support Bot Flaw Enabled 20,000+ Instagram Account Takeovers
Interest|Mobile Apps

What Happened: An AI Shortcut to Instagram Account Takeover

The Meta AI security bug was a flaw in Instagram’s AI-powered account recovery chatbot that allowed attackers to redirect password reset emails to their own inboxes, making large-scale account hijacking far easier than normal manual attacks. This account recovery chatbot vulnerability centered on Meta’s High Touch Support (HTS) system, an AI-assisted tool meant to help users locked out of their profiles regain access. Instead of improving safety, a bug in a separate code path meant HTS did not properly check whether the email address requesting a reset matched the one registered to the Instagram account. Attackers learned they could trigger password reset links to email addresses they controlled and then reset passwords for victims without two-factor authentication, leading to a wave of Instagram account takeover cases across thousands of profiles.

Meta’s AI Support Bot Flaw Enabled 20,000+ Instagram Account Takeovers

How Hackers Exploited the AI Support Bot

The exploit relied on abusing the design of Meta’s AI support bot rather than guessing passwords. To start an Instagram account takeover, attackers initiated the AI-assisted recovery flow from an IP address in the same region as the victim, which helped them avoid location-based flags. They then requested a password reset but supplied an attacker-controlled email instead of the legitimate one. Because the HTS bug skipped proper email verification, the system sent the reset link to that unassociated address. Once the link arrived, the attacker reset the password and took over the account if two-factor authentication (2FA) was not enabled. Meta says it disabled the AI-assisted support tool and invalidated the reset links created through this method, but only after the technique spread through Telegram and social media.

Meta’s AI Support Bot Flaw Enabled 20,000+ Instagram Account Takeovers

Scope of the Breach and Data at Risk

According to a data breach notice filed with a state attorney general, hackers abused the Meta AI security bug to compromise 20,225 Instagram accounts, starting on 17 April and continuing until the issue was discovered on 31 May. Some affected profiles were high-profile or verified accounts, including the inactive Instagram handle for a former White House, beauty retailer Sephora, and a senior Space Force official. Once attackers took control, they could access a wide range of personal data. Meta said contact information, direct messages and communications, and connected accounts or linked services (such as associated email IDs) were all potentially exposed. In many cases, this kind of breach is more damaging than a simple password leak, because private conversations, recovery channels, and cross-linked platforms can be abused for further fraud and impersonation.

Immediate Steps to Protect Your Instagram Account

Even though Meta has patched the account recovery chatbot vulnerability, you should harden your Instagram security now. Start by changing your password to a unique, strong passphrase that you do not reuse on other services. Next, enable two-factor authentication in Instagram’s security settings, using an authenticator app if possible; this extra step blocks most password-based hijacks, including similar AI-related flaws in the future. Review your active logins and device list, and log out any sessions you do not recognize. Check connected apps and linked services and revoke access for anything you no longer use or trust. Finally, watch for password reset emails you did not request and treat them as warning signs of attempted Instagram account takeover. If you notice suspicious activity, report it through Instagram’s in-app support immediately.

Ongoing Monitoring and Safer Use of AI Support Tools

The Meta AI security bug shows that automated support systems can introduce new attack paths even when traditional checks seem strong. Going forward, be cautious whenever an AI chatbot handles sensitive actions like password resets or account recovery. Avoid sharing security codes or full email addresses in public or semi-public chats, and always confirm that any reset link arrives at your real, long-standing inbox rather than a new or unfamiliar address. Regularly review your security and privacy settings, including who can log in, what devices are authorized, and which email and phone number are set for recovery. Treat any unexpected logouts, language changes, or new posts you did not create as red flags. Strong passwords, 2FA, and regular account reviews remain the best way to protect your Instagram account against future automation-related flaws.

Milik earns a commission when you shop through our links, at no extra cost to you. This article was generated with AI from published sources and product data.

You May Also Like

Comments
Say something...
No comments yet. Be the first to share your thoughts!