Trending

    Meta's AI Chatbot Exploited to Hijack Over 20000 Instagram Accounts

    Section editor: ·Moderate5 articles covering this·4 news sources·Updated 2 months ago·World
    Share:
    Illustration of Meta's AI chatbot security breach impacting Instagram accounts.

    Here's what it means for you.

    The recent exploitation of Meta's AI chatbot to hijack over 20,000 Instagram accounts raises significant concerns about the security of AI systems in high-stakes environments. This incident underscores the urgent need for robust safeguards in AI applications, particularly those involved in user authentication and account recovery. As scrutiny on AI security practices intensifies, companies may face increased regulatory pressure to enhance their security protocols.

    What happened

    Attackers exploited Meta's AI support agent to hijack Instagram accounts by initiating unauthorized password resets. By simply requesting email changes, they gained control over accounts, affecting a total of 20,225 users. The breach primarily targeted accounts lacking two-factor authentication, revealing a critical vulnerability in the system.

    Meta has since disabled the flawed recovery process and is actively reviewing other chatbots for similar security issues. This incident occurred between April 17 and early June 2026, culminating in a significant breach that included high-profile accounts, such as a dormant Obama White House handle.

    The Context

    The vulnerability in Meta's AI chatbot allowed attackers to bypass traditional security measures without relying on phishing or stolen credentials. This incident highlights the importance of two-factor authentication, as only accounts without this safeguard were compromised. The integration of AI into sensitive authentication processes raises questions about the adequacy of existing security measures.

    As AI systems become more prevalent in identity verification, the implications of this breach extend beyond individual users to the broader tech industry. Stakeholders must consider the potential for increased regulatory scrutiny and the need for improved security protocols to protect user data.

    Takeaway

    The Meta incident serves as a cautionary tale about the risks associated with integrating AI into security processes. Developers must prioritize robust safeguards to prevent similar exploits in the future. As the industry grapples with the fallout from this breach, we can expect heightened scrutiny on AI systems in high-stakes environments.

    Potential regulatory changes regarding AI security practices may emerge as a direct response to this incident. The focus will likely shift towards ensuring that AI applications are equipped with stringent security measures to protect user accounts and sensitive information.

    5 Articles
    DEV Community

    Meta's AI Chatbot Just Became a Password-Reset Backdoor for 20,000+ Instagram Accounts

    Meta has confirmed a significant security breach involving its AI chatbot, which allowed hackers to hijack over 20,000 Instagram accounts between April 17 and early June 2026. The vulnerability enabled attackers to reset passwords and change email ad...

    2 months ago
    Read Full Article
    Hacker News

    Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

    Meta has confirmed that thousands of Instagram accounts were hacked due to vulnerabilities in its AI support chatbot, which allowed unauthorized access to accounts by enabling password resets without proper authentication. This exploitation has raise...

    2 months ago
    Read Full Article
    VentureBeat

    Meta's AI support agent bound recovery emails for anyone who asked. Your SOC never saw an alert.

    Meta's AI support agent was exploited by hackers to bind recovery emails to Instagram accounts, enabling unauthorized password resets without alerts to security operations centers (SOCs). This incident involved attackers requesting changes through th...

    2 months ago
    Read Full Article
    MIT Technology Review

    The Download: AI hacking beyond Mythos, and chatbots’ impact on our brains

    Hackers exploited a vulnerability in Meta's AI support chatbot, allowing them to hijack Instagram accounts, including those of high-profile users, by simply requesting password resets without proper authentication. This incident raised significant co...

    2 months ago
    Read Full Article
    MIT Technology Review

    The Meta hack shows there’s more to AI security than Mythos

    Hackers exploited a vulnerability in Meta's AI customer support chatbot, allowing them to hijack Instagram accounts, including high-profile ones like the Obama White House account. By simply requesting email changes and password resets, attackers byp...

    2 months ago
    Read Full Article