MilikMilik

Meta AI Bug Let Hackers Hijack 20,000+ Instagram Accounts

Meta AI Bug Let Hackers Hijack 20,000+ Instagram Accounts
Interest|Mobile Apps

What Happened: A New Route for Instagram Account Takeovers

The Meta AI Instagram account hack refers to a security incident where attackers abused an AI-powered account recovery chatbot bug, allowing them to trigger password reset emails to their own addresses, bypass standard protections, and take over thousands of Instagram accounts that did not have two-factor authentication enabled. Meta confirmed through a government data breach notice that hackers used a flaw in its AI-assisted account recovery tool, called High Touch Support (HTS), to compromise 20,225 Instagram accounts. The account takeover vulnerability first appeared on April 17 and was eventually spotted in late May, after password reset exploit techniques spread on Telegram and social platforms. In affected cases, contact information, direct messages, and linked services may have been exposed. Many victims only realised their Instagram account was hacked when they were suddenly locked out or saw unfamiliar posts appearing under their names.

Meta AI Bug Let Hackers Hijack 20,000+ Instagram Accounts

How Hackers Exploited Meta’s AI Chatbot Bug

Meta designed its HTS chatbot to help locked-out users regain access by sending a password reset link to the email on file. However, a bug in a separate code path meant the system failed to check that the email provided to the bot matched the one associated with the account. According to Meta’s filing to Maine’s attorney general, “the system did not properly verify that the email address provided by the individual requesting a password reset matched the email address associated with that user’s Instagram account.” Attackers learned they could start recovery from an IP address in the same region as the victim, then ask the bot to send the reset link to any email they controlled. Once the link arrived, they reset the password and took over accounts without two-factor authentication, sometimes posting political propaganda and spam.

Meta AI Bug Let Hackers Hijack 20,000+ Instagram Accounts

Who Was Affected and What Meta Did Next

Meta’s notice says 20,225 Instagram accounts were affected through the Meta AI security bug, with hackers gaining access between April 17 and May 31. Reports highlighted that some high-profile accounts were hit, including the inactive Obama-era White House handle, beauty retailer Sephora, a senior Space Force official, and brands like SimpliSafe. For victims, the risk went beyond defaced posts: attackers could view phone numbers, email addresses, dates of birth, direct messages, and connected accounts. In response, Meta disabled the AI-assisted support tool, removed the vulnerable code path from production, and invalidated password reset links created via the exploit. The company says it has secured impacted profiles, restored users’ access where possible, and plans to re-enable the tool only after fixing the authentication check and reviewing similar account recovery flows across its platforms for related weaknesses.

Protect Yourself: Steps to Take If Your Instagram Account Is Hacked

If your Instagram account was hacked or you see unfamiliar logins, treat it as an emergency. First, try to log in and immediately change your password to something long, unique, and not reused on any other service. Next, enable two-factor authentication through the Instagram security settings—preferably using an authenticator app instead of SMS, which offers stronger protection against password reset exploits. Review your login activity and devices, and log out of any sessions you do not recognise. Check connected email accounts for password reset messages you did not request, and secure them too. Look through recent posts, DMs, and linked services for suspicious activity. If you cannot regain access, use Instagram’s official support and recovery flows, but avoid third-party “recovery” services that may be scams. Continue monitoring for new login alerts or changes to your email, phone number, or security settings.

AI Support Tools and the Future of Security on Social Platforms

This incident shows that even when AI is used for support, it can introduce new attack paths if basic checks fail. The Meta AI security bug did not come from the chatbot’s language model itself, but from the surrounding code that handled password reset rules, which allowed a powerful account recovery system to be turned into a weapon. As platforms add more AI-assisted help desks and automation, any flaw can quickly scale into a mass problem—evident in how this password reset exploit spread on Telegram, leading to thousands of hijacked accounts. For users, that means features that look convenient can also become points of failure. Strong personal security habits such as two-factor authentication, unique passwords, and frequent review of account activity remain essential, even as platforms promise smarter, faster AI-driven support for account recovery and security.

Milik earns a commission when you shop through our links, at no extra cost to you. This article was generated with AI from published sources and product data.

You May Also Like

Comments
Say something...
No comments yet. Be the first to share your thoughts!