What Happened: A New Route for Instagram Account Takeovers
The Meta AI Instagram account hack refers to a security incident where attackers abused an AI-powered account recovery chatbot bug, allowing them to trigger password reset emails to their own addresses, bypass standard protections, and take over thousands of Instagram accounts that did not have two-factor authentication enabled. Meta confirmed through a government data breach notice that hackers used a flaw in its AI-assisted account recovery tool, called High Touch Support (HTS), to compromise 20,225 Instagram accounts. The account takeover vulnerability first appeared on April 17 and was eventually spotted in late May, after password reset exploit techniques spread on Telegram and social platforms. In affected cases, contact information, direct messages, and linked services may have been exposed. Many victims only realised their Instagram account was hacked when they were suddenly locked out or saw unfamiliar posts appearing under their names.

How Hackers Exploited Meta’s AI Chatbot Bug
Meta designed its HTS chatbot to help locked-out users regain access by sending a password reset link to the email on file. However, a bug in a separate code path meant the system failed to check that the email provided to the bot matched the one associated with the account. According to Meta’s filing to Maine’s attorney general, “the system did not properly verify that the email address provided by the individual requesting a password reset matched the email address associated with that user’s Instagram account.” Attackers learned they could start recovery from an IP address in the same region as the victim, then ask the bot to send the reset link to any email they controlled. Once the link arrived, they reset the password and took over accounts without two-factor authentication, sometimes posting political propaganda and spam.

Who Was Affected and What Meta Did Next
Meta’s notice says 20,225 Instagram accounts were affected through the Meta AI security bug, with hackers gaining access between April 17 and May 31. Reports highlighted that some high-profile accounts were hit, including the inactive Obama-era White House handle, beauty retailer Sephora, a senior Space Force official, and brands like SimpliSafe. For victims, the risk went beyond defaced posts: attackers could view phone numbers, email addresses, dates of birth, direct messages, and connected accounts. In response, Meta disabled the AI-assisted support tool, removed the vulnerable code path from production, and invalidated password reset links created via the exploit. The company says it has secured impacted profiles, restored users’ access where possible, and plans to re-enable the tool only after fixing the authentication check and reviewing similar account recovery flows across its platforms for related weaknesses.
Protect Yourself: Steps to Take If Your Instagram Account Is Hacked
If your Instagram account was hacked or you see unfamiliar logins, treat it as an emergency. First, try to log in and immediately change your password to something long, unique, and not reused on any other service. Next, enable two-factor authentication through the Instagram security settings—preferably using an authenticator app instead of SMS, which offers stronger protection against password reset exploits. Review your login activity and devices, and log out of any sessions you do not recognise. Check connected email accounts for password reset messages you did not request, and secure them too. Look through recent posts, DMs, and linked services for suspicious activity. If you cannot regain access, use Instagram’s official support and recovery flows, but avoid third-party “recovery” services that may be scams. Continue monitoring for new login alerts or changes to your email, phone number, or security settings.
AI Support Tools and the Future of Security on Social Platforms
This incident shows that even when AI is used for support, it can introduce new attack paths if basic checks fail. The Meta AI security bug did not come from the chatbot’s language model itself, but from the surrounding code that handled password reset rules, which allowed a powerful account recovery system to be turned into a weapon. As platforms add more AI-assisted help desks and automation, any flaw can quickly scale into a mass problem—evident in how this password reset exploit spread on Telegram, leading to thousands of hijacked accounts. For users, that means features that look convenient can also become points of failure. Strong personal security habits such as two-factor authentication, unique passwords, and frequent review of account activity remain essential, even as platforms promise smarter, faster AI-driven support for account recovery and security.






