Meta AI Flaw Allowed Instagram Account Hijacks, Password Resets

Meta AI Flaw Allowed Instagram Account Hijacks, Password Resets | Quick Digest
A critical vulnerability in Meta's AI-powered support tool allowed attackers to hijack over 20,000 Instagram accounts by tricking the bot into resetting passwords. The flaw, active since April 2026, enabled unauthorized email changes and password resets without proper identity verification. Meta has since patched the issue, securing affected accounts.

Key Highlights

  • Meta's AI support bot vulnerability enabled Instagram account takeovers.
  • Attackers exploited the flaw to reset passwords via prompt injection.
  • Over 20,000 Instagram accounts were compromised globally.
  • High-profile accounts including Obama White House were targeted.
  • Meta patched the vulnerability by disabling the AI tool and invalidating links.
  • No backend database breach; the flaw was in AI's logic layer.
A significant cybersecurity vulnerability in Meta's AI-powered account recovery system, known as High Touch Support (HTS), allowed malicious actors to hijack over 20,000 Instagram accounts. The flaw, which Meta identified on May 31, 2026, and confirmed to have been exploited as early as April 17, 2026, permitted unauthorized password resets without adequate identity verification. The exploitation method involved attackers engaging with the Meta AI support chatbot, designed to assist users with account recovery, and manipulating it through a form of social engineering or 'prompt injection'. Attackers would typically use a Virtual Private Network (VPN) to spoof their geographic location, making it appear as if they were in the target account owner's region, thereby bypassing initial security flags. Once connected to the AI assistant, the attacker would claim to be the legitimate account owner and request to link the target Instagram account to a new email address, which was controlled by the attacker. Due to a bug in a separate code path, the Meta AI system failed to properly verify if the provided email address matched the one already associated with the user's Instagram account. Consequently, the AI bot would dutifully send a one-time verification code to the attacker's email address. Upon receiving and relaying this code back to the chatbot, the attacker was then presented with an option to reset the account's password, effectively gaining full control. This sophisticated yet alarmingly simple exploit bypassed standard security measures, including two-factor authentication (2FA) in many cases, as the system treated the AI-initiated recovery flow as an authoritative ownership claim. Videos and screenshots detailing this exploit circulated widely on platforms like Telegram, enabling even low-sophistication actors to perform account takeovers. Among the compromised accounts were several high-profile Instagram profiles, including the archived Barack Obama White House account, the Chief Master Sergeant of the U.S. Space Force, and the beauty retailer Sephora. The takeover of the Obama White House account, which had been dormant since 2017, saw it briefly defaced with pro-Iranian images and messages. Security researchers like Jane Manchun Wong also reported being affected. Meta responded swiftly to the crisis. On May 31, 2026, the company disabled the vulnerable AI-assisted HTS support tool and invalidated all existing password reset links generated through the exploited workflow. They also implemented a mandatory security checkpoint for affected accounts, requiring users to reset their passwords and reauthenticate through secure, verified channels. Meta emphasized that the issue was a flaw in the AI's logic layer and not a breach of its backend database or systems, meaning no direct database access or credential theft occurred. This incident highlights the inherent risks of offloading critical security and account recovery functions to AI chatbots without robust, independent verification mechanisms. Experts warned that AI agents should not be able to execute sensitive identity actions without hard authorization, least privilege, auditability, and out-of-band verification. The incident also raised questions about Meta's decision to aggressively invest in AI infrastructure while simultaneously reducing its human workforce, including integrity and cybersecurity teams. The company has committed to fixing the authentication check in the Instagram recovery entry point to ensure proper verification of email addresses before any password reset is initiated and is conducting a comprehensive review of similar account recovery flows across its platforms.

Frequently Asked Questions

What was the Instagram Meta AI vulnerability?

The vulnerability was a flaw in Meta's AI-powered High Touch Support (HTS) tool that allowed attackers to trick the bot into resetting Instagram account passwords. The AI failed to verify if a new email address provided for recovery matched the account's existing email, enabling unauthorized password resets.

How did hackers exploit the Meta AI vulnerability?

Hackers exploited the flaw by using prompt injection and often a VPN to spoof location. They would engage the Meta AI support bot, claim to be the account owner, and ask the bot to link the target account to an attacker-controlled email. The bot would then send a password reset code to this new email, allowing the attacker to take over the account.

How many Instagram accounts were affected?

Meta confirmed that over 20,000 Instagram accounts were compromised due to this vulnerability. This included high-profile accounts such as the archived Obama White House Instagram, Sephora, and a U.S. Space Force official.

Has Meta fixed this vulnerability?

Yes, Meta identified and patched the vulnerability on May 31, 2026. They disabled the affected AI-assisted support tool, invalidated existing password reset links, and required affected users to reset their passwords through secure channels.

Does this vulnerability mean Meta's systems were breached?

No, Meta clarified that there was no breach of their backend database or systems. The vulnerability was a logic flaw within the AI-powered account recovery tool, where the AI's internal processes for verifying identity were insufficient, rather than a direct intrusion into Meta's infrastructure.

Read Full Story on Quick Digest