iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
Relay Q: London Startup's AI Microphone Puts Hands-Free Voice Dictation on the Desktop Google Pixel 10a Crowned Best Budget Pixel in WIRED's Updated 2026 Buying Guide Global Steel Wire seeks fresh Santander terminal concession Veritas Shipmanagement books fresh ultramax pair at COSCO yard, Splash247 reports Seanergy linked to fresh newcastlemax at Hengli as dry bulk orderbook grows Weaker rupee may push foreign assets over FAST-DS Rs 1 crore limit, raising tax bill 45 Indian power plants face critically low coal stocks as monsoon hits supply SFL Makes Fresh $363m Car Carrier Play With Four LNG Dual-Fuel Newbuilds Iran Blacklist Threatens Hormuz Shuttle Tanker Lifeline for Gulf Crude Keyfield International Enters Dredging Market with $24.7m Vessel Acquisition Relay Q: London Startup's AI Microphone Puts Hands-Free Voice Dictation on the Desktop Google Pixel 10a Crowned Best Budget Pixel in WIRED's Updated 2026 Buying Guide Global Steel Wire seeks fresh Santander terminal concession Veritas Shipmanagement books fresh ultramax pair at COSCO yard, Splash247 reports Seanergy linked to fresh newcastlemax at Hengli as dry bulk orderbook grows Weaker rupee may push foreign assets over FAST-DS Rs 1 crore limit, raising tax bill 45 Indian power plants face critically low coal stocks as monsoon hits supply SFL Makes Fresh $363m Car Carrier Play With Four LNG Dual-Fuel Newbuilds Iran Blacklist Threatens Hormuz Shuttle Tanker Lifeline for Gulf Crude Keyfield International Enters Dredging Market with $24.7m Vessel Acquisition
Home ›› Technology ›› Ai ›› Ai Ethics ›› Meta confirms thousands of Instagram accounts were hacked by abusing its AI chatbot

Meta confirms thousands of Instagram accounts were hacked by abusing its AI chatbot

Meta confirmed that hackers abused a flaw in its AI chatbot to reset passwords for thousands of Instagram accounts, affecting at least 20,225 users. The attack exploited a bug that allowed the chatbot to send password reset links to unverified email addresses. This incident underscores the security risks enterprises face when deploying AI chatbots for account management and authentication.

iG
iGEN Editorial
June 14, 2026
Meta confirms thousands of Instagram accounts were hacked by abusing its AI chatbot

Enterprises deploying AI chatbots for customer-facing account management must reassess their security posture after Meta confirmed that thousands of Instagram accounts were hijacked through abuse of its AI-powered account recovery system. According to a data breach notification letter filed with Maine's attorney general's office and seen by this week in security, Meta notified at least 20,225 people that their accounts had been compromised, including 30 people in Maine. The hacks began around April 17 and lasted until early June, when Meta secured the chatbot.

How the Chatbot Was Tricked

As previously reported by 404 Media and TechCrunch, hackers exploited a vulnerability in Meta's AI-assisted account recovery system for Instagram. The flaw allowed anyone to reset the password of any account that did not have two-factor authentication enabled. The chatbot could be tricked into sending a password reset verification code to an email address controlled by the attacker, rather than the account holder's email on file. The chatbot complied simply upon request.

In its breach notice, Meta explained: "The tool itself worked properly and functioned as intended; however due to a bug in a separate code path, the system did not properly verify that the email address provided by the individual requesting a password reset matched the email address associated with that user’s Instagram account." As a result, an unauthorized third party could provide an email address not associated with the account, and the system incorrectly sent a password reset link to that unassociated email. This allowed the hackers to reset the password and take over the account fully.

Scope of the Compromise

The data breach notification detailed that the compromise allowed hackers to take over the entire Instagram account and any linked accounts. Attackers could obtain contact information, dates of birth, and profile information, as well as access the person's posts, direct messages, and account activity. Meta stated it is "unaware" of what personal information was accessed during the hacks, though an email to Meta's press line was not returned as of early Saturday.

Key Fact Detail
Total affected accounts 20,225
Affected accounts in Maine 30
Hack start date April 17, 2026
Hack end date Early June 2026 (when chatbot was secured)
Root cause Bug in code path: chatbot did not verify email address matched account
Mitigation Chatbot disabled, code path removed, affected users instructed to reset passwords

Enterprise Implications for AI Chatbot Security

For enterprise technology leaders, the Instagram hack serves as a cautionary tale. AI chatbots are increasingly deployed for password resets, account recovery, and customer authentication across supply chain platforms, trade finance portals, and logistics systems. The flaw here was not a failure of the AI model itself, but of the integration logic—a separate code path that bypassed email verification. Meta confirmed that it has disabled the AI chatbot for now, removed the offending code path, and is checking other chatbots across its platforms to prevent a repeat incident.

Enterprise CTOs should review their own AI-assisted account recovery systems to ensure that any password reset or authentication request is robustly validated against the user's registered contact information. This incident also reinforces the importance of enforcing two-factor authentication (2FA) for all accounts, as the hack was only possible against accounts without 2FA enabled.

Meta's Response

Meta instructed impacted users to reset their passwords and re-authenticate through secure, verified channels. The company said the hacks lasted from April 17 until the time of disclosure in early June, when it secured the chatbot. The incident comes soon after Meta laid off thousands of employees while rewarding top performers, highlighting the potential operational risks when AI systems are deployed without sufficient guardrails.


Sources:

Keep Reading

Recommended Stories