Meta: 20,000 Instagram Accounts Compromised by AI Chatbot Vulnerability

Le brief IA que les pros lisent chaque soir
Les 7 actus IA du jour, décryptées en 5 min. Gratuit.
Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.
Choisis ton rythme
Gratuit · Pas de spam · Désabonnement en 1 clic
A Critical Flaw in Meta's AI Chatbot
Meta recently revealed a significant flaw in its support AI chatbot, potentially affecting up to 20,225 Instagram accounts. This vulnerability, exploited over a period of seven weeks, allowed hackers to send password reset links to arbitrary and unverified email addresses. The recovery tool, known as "High Touch Support," was designed to help users regain access to their locked accounts. However, a bug in a separate code path enabled attackers to bypass email address verification, facilitating account takeovers.
In an official data breach notification, Meta quantified for the first time the extent of this vulnerability. The hacking campaign lasted nearly seven weeks, and Meta sent a data breach notification to the office of the Attorney General of Maine, providing the first concrete figures on this campaign. At least 20,225 accounts were compromised, including 30 in Maine.
Timeline and Impact of the Attacks
The attacks began around April 17, 2026, and were only discovered on May 31. The hackers exploited a known flaw in the "High Touch Support" recovery system, which sent password reset links to any email address without verifying that it belonged to the account. Meta considers the figure of 20,225 as an upper limit, as some access attempts may have come from legitimate account holders.
The potentially accessible data includes contact information, birth dates, posts, direct messages, account activities, profile information, and related services. However, Meta states that it does not know which information was actually accessed. Thisweekinsecurity was the first to report the notification.
Meta's Response to the Compromise
In response to this flaw, Meta has disabled the AI chatbot, removed the faulty code path, and invalidated all generated password reset links. Affected users were required to go through a mandatory security checkpoint and reset their passwords via verified channels.
Before reactivating the tool, Meta plans to fix the email verification step in the recovery process and audit similar account recovery systems across all its platforms. This incident comes as Meta has laid off thousands of employees while heavily betting on AI. The AI support chatbot had previously been presented by Meta as a breakthrough for account security.
Brief IA — L'actualité IA en français
L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.