Vulnerabilities · 98 days ago
The broken assumption is that account recovery is safer than login. Here, the reset channel itself handed out access when the destination email was not tied to the account, so changing the password could become the attacker's way in if 2FA was off.
Meta says it found the flaw in its AI-assisted High Touch Support tool on May 31 and counted 20,225 potentially affected Instagram accounts. The abuse hit many high-profile accounts and could expose profile data, messages, posts, and account history; Meta disabled the tool and is reviewing similar recovery flows.
The wider risk is in any support-driven recovery system that trusts a new destination without verifying it against the existing account. Passwords can be fine and the account can still fall if the recovery path becomes the credential.
4 sources covering this story
Hackers used Meta's AI support system to hijack over 20,000 Instagram accounts - Help Net Security
Meta revealed that a flaw in Instagram's AI-assisted account recovery system led to 20,225 account takeovers.
Meta AI Bug Exposes Over 20,000 Instagram Accounts
Meta confirms an AI tool vulnerability led to unauthorized access to Instagram accounts after a failure in email verification during password reset
Meta Says 20,000 Instagram Accounts Hacked via AI Tool Abuse
The social media giant has informed authorities about the impact of the recent attack involving an account recovery support tool.
Over 20,000 Instagram accounts stolen in Meta AI support hack
Meta has revealed that 20,225 Instagram users had their accounts hijacked in a recent incident where attackers used Meta's AI-powered support system to reset passwords.
Part of the PlainSec briefing for 2026-06-08