Ad

Meta has confirmed that a vulnerability in its AI-powered Instagram account recovery system allowed attackers to take control of more than 20,000 Instagram accounts. The flaw was found in Meta's High Touch Support (HTS) tool, which uses artificial intelligence to help users regain access to locked Instagram accounts.
Attackers exploited the flaw to obtain password reset links for accounts that did not have two-factor authentication enabled. This allowed them to gain unauthorized access to those accounts. Meta acknowledged the issue after weeks of complaints from Instagram users who reported being locked out of their accounts. Several high-profile accounts were affected, including the Barack Obama White House account, Sephora's Instagram account, and the Chief Master Sergeant of Space Force account.
Meta's vice-president of communications, Andy Stone, responded to an affected user on X, stating that the issue had been resolved and that the company was working to secure impacted accounts. The company formally disclosed the incident in a data breach notification filed with the Maine Office of the Attorney General. Meta discovered the vulnerability on May 31, 2026, and found that unauthorized parties had exploited the flaw to reset passwords on Instagram accounts. The breach may have started as early as April 17, 2026, which is believed to be the date of the first successful attack.
According to reports by 404 Media, the HTS system failed to verify if an email address provided during account recovery was actually linked to the targeted Instagram account. Attackers convinced the AI support bot to associate a victim's account with a new email address under their control. They then requested a password reset and received the reset code, which allowed them to access the account. Screenshots and videos circulating on Telegram showed hackers interacting directly with the AI support assistant. In some cases, attackers used VPN services to match the account owner's location, making their requests appear more legitimate.
Meta told Maine authorities that 30 users in the state were affected. The company estimated that more than 20,000 Instagram accounts were impacted globally. Meta said it cannot determine exactly what information attackers accessed. However, compromised accounts may have exposed email addresses, phone numbers, dates of birth, profile information, photos, videos, Stories, direct messages, account activity records, and details of linked services.
After discovering the flaw, Meta disabled the HTS recovery system and invalidated all password reset links generated through the tool. The company required additional security checks and password resets for potentially affected users before allowing them to regain access. Meta plans to strengthen its email verification process before relaunching the tool. The company is also reviewing similar recovery systems across its platforms.
The incident has increased scrutiny of Meta's efforts to replace traditional customer support with AI. Earlier this year, Meta expanded AI-powered support across Facebook and Instagram, allowing the system to handle password resets, account recovery, and security requests. The breach highlights the risks of relying on automated systems for critical security decisions without sufficient safeguards.
Ad

Instagram Introduces Reorder Grid Feature and Paid Subscription in India
Instagram has introduced the Reorder Grid feature, allowing users to rearrange posts on their profile. Meta also launched a paid subscription in India for Rs 299 per month, offering additional customisation tools and insights.
09-Jun-2026 05:30 AM

Honor X80 Pro Max Leak Reveals 11,000mAh Battery and 6.8-inch AMOLED Display
A recent leak suggests Honor may launch an X80 Pro Max with an 11,000mAh battery, 90W fast charging, and a 6.8-inch AMOLED display. The device is also expected to feature water resistance and advanced biometric security.
09-Jun-2026 02:30 AM

US Adds Alibaba, Baidu, BYD, and Unitree to Chinese Military Support List
The US Department of Defense has added Alibaba, Baidu, BYD, and Unitree to its 1260H list, targeting 188 Chinese firms linked to military support. This action may limit contracts and funding, increasing US-China tech tensions.
08-Jun-2026 09:30 PM

Samsung Releases One UI 8.5 Update for M15 and Xcover7 in Select Markets
Samsung has released the One UI 8.5 update for the Galaxy M15 in Korea and the Xcover7 in Southeast Asia. The update includes the May 2026 security patch and will expand to more regions soon.
08-Jun-2026 09:30 PM

Studies Link iPhone and Smartphones to Global Decline in Birth Rates Since 2007
Recent studies suggest the rise of the iPhone and smartphones contributed to a global decline in birth rates since 2007. Researchers found significant drops in fertility among young women in the US and similar trends worldwide.
08-Jun-2026 07:30 PM

OnePlus to Launch N Series Smartphones in India Under INR 20,000
OnePlus is set to introduce the N series, a new entry-level smartphone line for India priced below INR 20,000. The N series will launch in July 2026 and compete with Redmi, Realme, and Poco in the budget segment.
08-Jun-2026 07:30 PM
Ad
Ad












Ad
Ad