{"id":627398,"date":"2026-06-08T11:08:13","date_gmt":"2026-06-08T11:08:13","guid":{"rendered":"https:\/\/www.newsbeep.com\/uk\/627398\/"},"modified":"2026-06-08T11:08:13","modified_gmt":"2026-06-08T11:08:13","slug":"over-20000-instagram-accounts-stolen-in-meta-ai-support-hack","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/uk\/627398\/","title":{"rendered":"Over 20,000 Instagram accounts stolen in Meta AI support hack"},"content":{"rendered":"<p style=\"text-align:center\"><img loading=\"lazy\" decoding=\"async\" alt=\"Meta\" height=\"900\" src=\"https:\/\/www.newsbeep.com\/uk\/wp-content\/uploads\/2026\/06\/Meta.jpg\" width=\"1600\"\/><\/p>\n<p>Meta has revealed that 20,225 Instagram users had their accounts hijacked in a recent incident where attackers\u00a0used Meta&#8217;s AI-powered support system to reset passwords.<\/p>\n<p>As BleepingComputer reported one week ago, the threat actors <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/instagram-users-locked-out-after-meta-ai-abused-to-steal-accounts\/\" target=\"_blank\" rel=\"nofollow noopener\">exploited a flaw in the company&#8217;s High Touch Support (HTS) tool<\/a>,\u00a0an AI-assisted support system that\u00a0helps users regain access after being\u00a0locked out of their Instagram\u00a0accounts.<\/p>\n<p>By exploiting the fact that HTS didn&#8217;t verify whether email addresses were associated with the targeted Instagram accounts, they obtained password reset links that allowed them to log in and hijack accounts without\u00a0two-factor authentication (2FA) enabled.<\/p>\n<p> <a href=\"https:\/\/www.wiz.io\/reports\/state-of-ai-in-the-cloud-2026?utm_source=bleepingcomputer&amp;utm_medium=display&amp;utm_campaign=FY27Q1_INB_FORM_State-of-AI-Report-2026&amp;sfcid=701Vh00000aV1zBIAS&amp;utm_term=FY27-bleepingcomputer-article-970x250-June&amp;utm_content=State-of-AI-Report-2026\" rel=\"nofollow noopener\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/uk\/wp-content\/uploads\/2026\/06\/state-of-ai-report-970.jpg\" alt=\"image\" style=\"margin-top: 0px;\"\/><\/a><\/p>\n<p>&#8220;Users can request support from HTS and, as part of that process, can ask that a password reset link be sent to their email address. The tool itself worked properly and functioned as intended; however due to a bug in a separate code path, the system did not properly verify that the email address provided by the individual requesting a password reset matched the email address associated with that user\u2019s Instagram account,&#8221;\u00a0<a href=\"https:\/\/legacy.www.documentcloud.org\/documents\/28211657-meta-ai-support-tool-incident-ag-notification-bc-me\/\" target=\"_blank\" rel=\"nofollow noopener\">said<\/a> Amber Hannah, Meta\u2019s associate general counsel for incident response legal, in a data breach letter\u00a0recently\u00a0filed with Maine&#8217;s Office of the Attorney General.<\/p>\n<p>&#8220;As a result, when an individual provided an email address not previously associated with the account, the system incorrectly sent a password reset link to that unassociated email rather than rejecting the request. This allowed unauthorized third parties to receive a password reset link for accounts they did not own. Upon resetting the password, the unauthorized party was able to log in to the account if the account holder had not enabled two-factor authentication (2FA).&#8221;<\/p>\n<p>After a wave of user reports regarding these attacks hit social media platforms,\u00a0Andy Stone, Meta&#8217;s\u00a0vice president of communications,\u00a0<a href=\"http:\/\/x.com\/wongmjane\/status\/2061680602018140419\/photo\/2\" rel=\"nofollow noopener\">replied<\/a>\u00a0to one of the affected users, stating that the &#8220;issue has been resolved, and we are securing impacted accounts.&#8221;<\/p>\n<p>BleepingComputer has also contacted Meta last week for comment on this security breach, but we have yet to hear back.<\/p>\n<p>&#8220;We are writing to inform you that a vulnerability in an Instagram account recovery support tool\u00a0was used to potentially compromise the Instagram accounts of 30 users in your jurisdiction. All\u00a0accounts have been secured to prevent any continued unauthorized access,&#8221; Hannah\u00a0added. &#8220;On May 31, 2026, Meta discovered that there was a vulnerability in an AI-assisted account\u00a0recovery system for Instagram (&#8216;High Touch Support&#8217;\u00a0or &#8216;HTS&#8217;) that was exploited by\u00a0unauthorized third parties to perform password resets on Instagram user accounts.&#8221;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"Chat with the Meta's AI support HTS agent\" height=\"654\" src=\"https:\/\/www.newsbeep.com\/uk\/wp-content\/uploads\/2026\/06\/chat.jpg\" width=\"491\"\/>Chat with the Meta&#8217;s AI support HTS agent (@thecomfeed)<\/p>\n<p>While Meta didn&#8217;t specify when the attacks began in the breach letter, the filing on Maine&#8217;s OAG website says the breach occurred on April 17, which is likely the date of the first attack exploiting the HTS flaw.<\/p>\n<p>The company says it has no information on what personal information might have been accessed or stolen from the compromised accounts, but\u00a0noted\u00a0that the attackers could&#8217;ve gained access to affected Instagram users&#8217; contact information (email address and\/or phone number), dates of birth, social media posts and content (photos, videos, stories), direct messages and communications, account activity and interaction history, profile information (biography, profile photo), as well as other connected accounts and linked services.<\/p>\n<p>After discovering the incident, the company disabled the\u00a0HTS AI-powered support system and all password reset links it had generated to ensure that all future hijack attempts part of the same malicious campaign would be blocked.<\/p>\n<p>It also enrolled all potentially stolen accounts into a mandatory security checkpoint and asked all affected users to reset their passwords again and re-authenticate to secure and regain control\u00a0of the\u00a0compromised\u00a0accounts.\u00a0<\/p>\n<p>&#8220;Prior to re-launching the tool, Meta will fix the authentication check in the Instagram recovery\u00a0entry point to ensure proper verification of email addresses against existing account information\u00a0before any password reset is initiated,&#8221; Meta added.\u00a0&#8220;Additionally, Meta is conducting a comprehensive review of similar account recovery flows across Meta\u2019s platforms to identify and remediate any potential issues.&#8221;<\/p>\n<p>Prior\u00a0to this incident,\u00a0Ireland also <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/ireland-fines-meta-264-million-over-2018-facebook-data-breach\/\" target=\"_blank\" rel=\"nofollow noopener\">fined Meta $264 million<\/a> over a <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/ireland-fines-meta-264-million-over-2018-facebook-data-breach\/\" target=\"_blank\" rel=\"nofollow noopener\">2018 data breach<\/a> that exposed the names, email addresses, phone numbers, and physical locations of over 29 million\u00a0Facebook accounts.<\/p>\n<p>Meta was also\u00a0fined \u20ac265 million ($275.5 million) in November 2022 for <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/meta-fined-265m-for-not-protecting-facebook-users-data-from-scrapers\/\" target=\"_blank\" rel=\"nofollow noopener\">failing to protect Facebook users&#8217; data from scrapers<\/a>,\u00a0and another\u00a0\u20ac91 million ($100 million)\u00a0for <a href=\"https:\/\/www.bleepingcomputer.com\/news\/legal\/ireland-fines-meta-91-million-for-storing-passwords-in-plaintext\/\" target=\"_blank\" rel=\"nofollow noopener\">storing the passwords of hundreds of millions of users\u00a0in plaintext<\/a>.<\/p>\n<p>        <a href=\"https:\/\/hubs.li\/Q04jQ9z40\" target=\"_blank\" rel=\"noopener nofollow\"><br \/>\n            <img decoding=\"async\" alt=\"article image\" src=\"https:\/\/www.newsbeep.com\/uk\/wp-content\/uploads\/2026\/06\/bas-report.jpg\" class=\"b-lazy\"\/><\/a><\/p>\n<p>Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.<\/p>\n<p>The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.<\/p>\n<p>        <a class=\"article-link\" href=\"https:\/\/hubs.li\/Q04jQ9z40\" target=\"_blank\" rel=\"noopener nofollow\">Get the whitepaper<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"Meta has revealed that 20,225 Instagram users had their accounts hijacked in a recent incident where attackers\u00a0used Meta&#8217;s&hellip;\n","protected":false},"author":2,"featured_media":627399,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[554,733,4308,86,56,54,55],"class_list":["post-627398","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-artificial-intelligence","tag-artificialintelligence","tag-technology","tag-uk","tag-united-kingdom","tag-unitedkingdom"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/627398","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/comments?post=627398"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/627398\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media\/627399"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media?parent=627398"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/categories?post=627398"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/tags?post=627398"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}