Brief IA

Meta: 20,000 Instagram Accounts Compromised by AI Chatbot Vulnerability

🛠️ AI Tools·Tom Levy·

Meta: 20,000 Instagram Accounts Compromised by AI Chatbot Vulnerability

Meta: 20,000 Instagram Accounts Compromised by AI Chatbot Vulnerability
Key Takeaways
1A flaw in Meta's AI chatbot compromised 20,225 Instagram accounts in seven weeks.
2Hackers used a faulty recovery tool to send reset links to unverified emails.
3Meta has disabled the chatbot and forced affected users to reset their passwords through secure channels.
💡Why it mattersThis incident highlights the potential vulnerabilities of AI tools in managing users' sensitive data.
Le brief IA que lisent les pros

Le brief IA que les pros lisent chaque soir

Les 7 actus IA du jour, décryptées en 5 min. Gratuit.

Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.

Choisis ton rythme

Gratuit · Pas de spam · Désabonnement en 1 clic

📄
Full Analysis

A Critical Flaw in Meta's AI Chatbot

Meta recently revealed a significant flaw in its support AI chatbot, potentially affecting up to 20,225 Instagram accounts. This vulnerability, exploited over a period of seven weeks, allowed hackers to send password reset links to arbitrary and unverified email addresses. The recovery tool, known as "High Touch Support," was designed to help users regain access to their locked accounts. However, a bug in a separate code path enabled attackers to bypass email address verification, facilitating account takeovers.

In an official data breach notification, Meta quantified for the first time the extent of this vulnerability. The hacking campaign lasted nearly seven weeks, and Meta sent a data breach notification to the office of the Attorney General of Maine, providing the first concrete figures on this campaign. At least 20,225 accounts were compromised, including 30 in Maine.

Timeline and Impact of the Attacks

The attacks began around April 17, 2026, and were only discovered on May 31. The hackers exploited a known flaw in the "High Touch Support" recovery system, which sent password reset links to any email address without verifying that it belonged to the account. Meta considers the figure of 20,225 as an upper limit, as some access attempts may have come from legitimate account holders.

The potentially accessible data includes contact information, birth dates, posts, direct messages, account activities, profile information, and related services. However, Meta states that it does not know which information was actually accessed. Thisweekinsecurity was the first to report the notification.

Meta's Response to the Compromise

In response to this flaw, Meta has disabled the AI chatbot, removed the faulty code path, and invalidated all generated password reset links. Affected users were required to go through a mandatory security checkpoint and reset their passwords via verified channels.

Before reactivating the tool, Meta plans to fix the email verification step in the recovery process and audit similar account recovery systems across all its platforms. This incident comes as Meta has laid off thousands of employees while heavily betting on AI. The AI support chatbot had previously been presented by Meta as a breakthrough for account security.

Brief IA — L'actualité IA en français

L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.