Hackers likely hijacked over 20,000 Instagram accounts with Meta’s AI chatbot

https://platform.theverge.com/wp-content/uploads/sites/2/2026/06/meta-support-ai.webp?quality=90&strip=all&crop=0,18.313280042747,100,52.356395174696

Emma Roth is a news writer who covers the streaming wars, consumer tech, crypto, social media, and much more. Previously, she was a writer and editor at MUO.

Hackers likely took over 20,225 Instagram accounts using Meta’s AI support chatbot, the company confirmed in a notice filed with the state of Maine. In the notice, spotted earlier by Bleeping Computer, Meta blames a “bug” for the exploit that allowed attackers to hijack accounts without two-factor authentication simply by asking the chatbot for a password reset:

The tool itself worked properly and functioned as intended; however due to a bug in a separate code path, the system did not properly verify that the email address provided by the individual requesting a password reset matched the email address associated with that user’s Instagram account. As a result, when an individual provided an email address not previously associated with the account,...

Copyright of this story solely belongs to theverge.com. To see the full text click HERE