Instagram Recovery Tool Bug Exposed 20,225 Accounts to Password Reset Abuse

https://hackread.com/wp-content/uploads/2026/06/instagram-recovery-tool-bug-accounts-password-reset-1024x576.jpg

Meta has disclosed a security incident involving an Instagram account recovery tool after attackers used a flaw to send password reset links to email addresses that were not connected to the targeted accounts.

According to a data breach notice filed with the Maine Attorney General’s Office, Meta Platforms said the issue affected 20,225 people in total, including 30 Maine residents. The incident occurred on April 17, 2026, and was discovered by Meta on May 31, 2026.

The problem involved Instagram’s “High Touch Support” system, an AI-assisted account recovery tool built to help users regain access when locked out of their accounts. As part of that process, users could request a password reset link by providing an email address.

Meta said the support tool itself functioned as designed, but a bug in a separate code path caused a serious validation failure. The system did not properly confirm that the email address...

Copyright of this story solely belongs to hackread.com. To see the full text click HERE