BotBeat
...
← Back

> ▌

MetaMeta
POLICY & REGULATIONMeta2026-06-06

Meta Confirms 20,000+ Instagram Accounts Hijacked Through AI Chatbot Vulnerability

Key Takeaways

  • ▸At least 20,225 Instagram users were affected by the breach, which lasted from approximately April 17 until its discovery this week
  • ▸Hackers exploited an email verification flaw in Meta's AI-assisted password reset system that allowed them to trick the chatbot into sending verification codes to attacker-controlled email addresses
  • ▸The exploit gave attackers full account access, including personal information, contact details, posts, direct messages, and account activity for accounts without two-factor authentication
Source:
Hacker Newshttps://this.weekinsecurity.com/meta-confirms-thousands-of-instagram-accounts-were-hacked-by-abusing-its-ai-chatbot/↗

Summary

Meta disclosed a major security breach affecting at least 20,225 Instagram users whose accounts were hijacked through exploitation of a vulnerability in the company's AI-assisted account recovery chatbot. The breach occurred between mid-April and this week, when hackers repeatedly tricked the chatbot into resetting account passwords and sending verification codes to attacker-controlled email addresses. The vulnerability exploited a flaw in the system's email verification logic during password reset requests, allowing unauthorized access to account information, direct messages, posts, and account activity.

The compromised accounts lacked two-factor authentication protection, making them vulnerable to the exploit. Meta confirmed in a data breach notification filed with Maine's attorney general that the chatbot had a code path bug that failed to verify email addresses properly during password resets. When hackers provided an attacker-controlled email address, the system incorrectly sent password reset links to that email rather than rejecting the request or sending it to the account holder's registered address. Meta has since disabled the vulnerable chatbot, removed the problematic code path, and begun notifying affected users to reset their passwords and secure their accounts.

  • Meta has disabled the vulnerable chatbot and is reviewing other chatbots across its platforms to prevent similar security incidents
  • The breach highlights the security risks of deploying AI systems to handle sensitive account recovery and authentication functions
AI AgentsCybersecurityRegulation & PolicyAI Safety & AlignmentPrivacy & Data

More from Meta

MetaMeta
UPDATE

Meta Continues to Postpone Developer Access to New AI Model

2026-06-06
MetaMeta
UPDATE

Meta Deploys Tent Data Centers to Rapidly Scale AI Infrastructure Across US

2026-06-05
MetaMeta
POLICY & REGULATION

Meta's AI Support Agent Became an Unwitting Accomplice in Instagram Account Thefts

2026-06-05

Comments

Suggested

OpenAIOpenAI
UPDATE

OpenAI Rolls Out Lockdown Mode to Protect Against Prompt Injection Attacks

2026-06-06
Academic ResearchAcademic Research
RESEARCH

Tree-Like Self-Play Cuts Code Generation Vulnerabilities by 24.5%, Advances LLM Security

2026-06-06
TenureTenure
RESEARCH

AI Memory Proves Inefficient: Tenure Project Detects 95% Error Rate

2026-06-06
← Back to news
© 2026 BotBeat
AboutPrivacy PolicyTerms of ServiceContact Us