Meta’s AI Chatbot Helped Hackers Take Over 20,000 Instagram Accounts
Meta confirmed 20,225 Instagram accounts were hijacked through a flaw in its AI support chatbot. Here’s exactly what happened, who was affected, and how to protect your account.
What Happened
A bug in Meta’s own AI support system gave hackers an easy path into thousands of Instagram accounts no special tools, no code, no hacking skills required. The attacker simply asked the chatbot to hand over access. It did.
Meta confirmed the breach in a filing with the Maine Attorney General’s office on June 6, 2026. The total number of affected accounts: 20,225. Among them were the Obama-era White House Instagram page, the account of U.S. Space Force Chief Master Sergeant John Bentivegna, and beauty retailer Sephora.
How the Attack Worked — Step by Step
The exploit targeted Meta’s “High Touch Support” (HTS) — an AI-assisted account recovery tool Meta launched in March 2026 for users locked out of their accounts.
Here is what the attack looked like in practice:
- The attacker picked a target account — often a short, high-value username or a dormant high-profile profile.
- They connected to a VPN and set their location near the target’s suspected region to avoid triggering Instagram’s automated location-based protections.
- They opened Meta’s AI Support Assistant and requested the chatbot add a new email address to the target’s account.
- The chatbot sent a verification code — not to the account owner’s registered email, but to the email address the attacker provided.
- The attacker entered the code, and the chatbot displayed a “Reset Password” button.
- A new password was set. The original account owner was locked out.

Meta’s own breach notice acknowledged the core failure: “The tool itself worked properly and functioned as intended; however, due to a bug in a separate code path, the system did not properly verify that the email address provided by the individual requesting a password reset matched the email address associated with that user’s Instagram account.”
The accounts that had two-factor authentication (2FA) enabled were protected. Accounts without 2FA were fully exposed.
Who Was at Risk — and Why It Stayed Hidden So Long
The attack targeted two types of accounts specifically:
- Dormant high-profile accounts — pages like the Obama White House Instagram, inactive since 2017, with no active owner monitoring them.
- Short, rare usernames — two and three-character handles that carry real resale value on underground markets, sometimes selling for hundreds to thousands of dollars.
Both categories share one thing: no active owner checking in daily. That made unauthorized access harder to detect quickly.

Security researcher Jane Wong, whose account was also compromised, told TechCrunch: “The password got changed without my knowledge and I was getting different password reset attempts throughout yesterday. Quite concerning.”
The attack did not require the hacker to be logged into the target account at any point. The entire process happened through Meta’s own support interface.
What Meta Did After Discovery
Once Meta identified the vulnerability on May 31, 2026, it took the following steps:
- Disabled the affected AI-assisted support tool immediately
- Invalidated all password reset links generated through the compromised workflow
- Required additional authentication for all potentially affected accounts
- Notified impacted users to reset their passwords
- Filed a breach notice with the Maine Attorney General, which triggered public disclosure
The fix addressed the verification gap — the system now cross-checks that any email provided during a password reset matches the one already registered to the account.

The Bigger Problem This Exposed
This incident is not just about one bug. It points to a structural risk in how AI is being deployed for account security functions.
When Meta rolled out its AI Support Assistant in March 2026, the product page described it as offering “Solutions, not just suggestions” — with the ability to reset passwords and handle critical account maintenance. That capability, given to a system without sufficient verification checks, created the attack surface hackers exploited.
Users who lost their accounts reported another problem: there was no way to reach a human support agent. The AI was the only option, and the AI was the problem.
This is not unique to Meta. Across platforms, AI-powered support is replacing human agents for cost and scale reasons. The Instagram incident is the clearest example yet of what happens when account-level control is handed to an automated system before the verification logic is hardened.
How to Protect Your Instagram Account Right Now
These steps reduce your risk significantly:
Enable two-factor authentication immediately. This was the single factor that separated protected accounts from compromised ones in this attack. Go to Settings → Accounts Centre → Password and Security → Two-Factor Authentication. Use an authenticator app rather than SMS where possible.
Check your registered email address. Go to Settings → Accounts Centre → Personal Details → Contact Info. Confirm the email on file is one you actively monitor and control.
Review your account activity. Settings → Your Activity → Login Activity shows all recent login sessions and locations. Any unfamiliar entry warrants an immediate password change.
Use a strong, unique password. Accounts with reused passwords are vulnerable even after a breach is patched, because leaked credentials from other platforms can be used to request further resets.
If you want to check what public information is visible on your Instagram profile without logging in, tools like HideViewer retrieve publicly available profile data anonymously — useful for auditing your own public-facing information.
What This Means for Account Security Going Forward
Meta has patched this specific vulnerability. But the underlying question — how much control should an AI support system have over account access? — remains open.
Account security depends on verification chains. Every step in a password reset or account recovery process is only as strong as its weakest verification check. In this case, the chatbot’s ability to process email changes without confirming ownership of the existing account was that weak link.
For users, the practical lesson is straightforward: two-factor authentication is no longer optional. For platforms, this incident is a live case study in why AI deployment in security-critical workflows requires more rigorous testing before public rollout.
