< Back to all clusters
[TECHNOLOGY] · United States, Germany, France, South Africa · 7 sources

Meta AI Support Bot Breach Compromises Over 20,000 Instagram Accounts

Between mid‑April and the end of May 2026, a flaw in Meta’s AI‑powered “High Touch Support” (HTS) chatbot let attackers reset Instagram passwords without verifying the associated email address. The bot generated password‑reset links that were sent to email accounts controlled by the hackers, allowing them to take full control of the accounts, even bypassing two‑factor authentication.

Meta reports that roughly 20,225 Instagram accounts were affected, including high‑profile profiles such as the Obama‑era White House page, Sephora’s official account and a senior officer of the U.S. Space Force. Compromised accounts were subsequently offered for sale on the Dark Web, with rare usernames fetching high prices.

After discovering the issue on 31 May, Meta immediately disabled the HTS tool, invalidated all generated reset links, forced password changes, and placed the affected accounts into a security‑check process. The company urged users to enable two‑factor authentication and said it will restore the chatbot only after a thorough fix to the email‑verification step.

The incident has sparked broader concerns about granting AI systems privileged access to security‑critical workflows, highlighting the need for stronger verification and human oversight in automated account‑recovery processes.