Meta AI support bug exposes 20,000 Instagram accounts
Meta disclosed that a flaw in its AI‑driven High Touch Support system allowed attackers to hijack more than 20,000 Instagram accounts. The bug let hackers change the recovery email address without verifying it, enabling password‑reset links to be issued for accounts that did not have two‑factor authentication enabled. The exploit was active from April 17, 2026 and was reported to U.S. authorities, including the Maine Attorney General's office.
Victims included high‑profile users such as the U.S. Space Force chief, the Sephora brand, former President Barack Obama and security researcher Jane Manchun Wong. Meta responded by disabling the AI support tool, revoking all attacker‑generated reset links and forcing affected users to verify their identity and change passwords. Vice President of Communications Andy Stone said, "the issue has been resolved and we are securing impacted accounts." The company plans to relaunch the service only after fixing the verification process and reviewing account‑recovery procedures across its platforms.