Meta Confirms AI Support Flaw Led to 20,225 Instagram Account Takeovers

Meta Confirms AI Support Flaw Led to 20,225 Instagram Account Takeovers

N
News Editor 01
2026-07-23 13:50:16
Meta said a flaw in its AI-powered account recovery flow allowed attackers to hijack 20,225 Instagram accounts over nearly seven weeks. All affected accounts lacked 2FA.
MetaInstagramAccount SecurityTwo-Factor AuthenticationAI Support

Meta has confirmed that attackers exploited a flaw in its AI-driven account recovery system to take over at least 20,225 Instagram accounts between April 17, 2026 and early June. The figure was disclosed in a data breach notice filed with the Maine Department of the Attorney General, giving the first precise count of affected users after earlier reports only referred to “thousands.”

The breach lasted nearly seven weeks and hit accounts without 2FA

The attacks continued for close to seven weeks before Meta patched the issue in early June. According to the disclosed details, the impacted accounts shared one key condition: none had two-factor authentication enabled. Without that second layer of verification, a successful password reset was enough to hand full control to the attacker.

The report also indicates that accounts protected by 2FA were outside the affected group. In this case, two-factor authentication appears to have been the only effective safeguard once the recovery flow was abused.

Attackers changed the email first, then completed the reset

The method was simple. Attackers first used a VPN to make their connection appear to come from the same region as the target account, which helped them bypass Instagram’s location-based automated protections. They then initiated a password reset and, during a conversation with Meta’s AI support system, asked for the account’s registered email address to be changed to one they controlled.

The AI system approved the request. A verification code was then sent to the attacker’s email address, and once that code was pasted back into the chat window, the bot displayed a “Reset Password” button. At no point did the attacker need access to the victim’s original email account.

Hijacked accounts exposed personal data, posts and direct messages

After taking control, attackers could access contact details, birth dates, profile information, posts, direct messages and account activity history. The source material says high-profile cases included the Obama White House Instagram account, inactive since 2017 and later used to post pro-Iranian content, and the official account of U.S. Space Force Chief Master Sergeant John Bentivegna.

The incident points to a basic failure in the recovery workflow. Meta’s AI system could interpret the account recovery request, but it did not perform a basic ownership check on the replacement email address. A feature built to reduce friction for legitimate users ended up reducing friction for attackers as well.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
500

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.