iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
Anthropic to Meet White House Commerce Officials Over Suspension of AI Tools Fable 5 and Mythos 5 Facebook's New AI Tools Offer Photo-Editing and Question-Answering, But Little That's New AMD Marketing Campaign Criticizes MacBook Neo for Gaming, but Critics Question the Strategy India Launches WT-MARUT, First Digital Platform for Wind Energy Supply Chain Tracking AI Reshapes Workforce Skills: PwC Study Shows Human Skills in Greater Demand India's trade with West Asia gradually improving: Commerce Secretary Rajesh Agrawal Cass Report: Freight Volume Recovery On Track for Second Half of 2026 India Receives 32% Deficient Rains During June 1-15, IMD Data Shows ANNAM.AI and Syngenta Partner to Deliver AI-Driven Climate-Smart Agriculture to Indian Farmers Microsoft CEO Satya Nadella warns AI dominance could 'hollow out entire industries' Anthropic to Meet White House Commerce Officials Over Suspension of AI Tools Fable 5 and Mythos 5 Facebook's New AI Tools Offer Photo-Editing and Question-Answering, But Little That's New AMD Marketing Campaign Criticizes MacBook Neo for Gaming, but Critics Question the Strategy India Launches WT-MARUT, First Digital Platform for Wind Energy Supply Chain Tracking AI Reshapes Workforce Skills: PwC Study Shows Human Skills in Greater Demand India's trade with West Asia gradually improving: Commerce Secretary Rajesh Agrawal Cass Report: Freight Volume Recovery On Track for Second Half of 2026 India Receives 32% Deficient Rains During June 1-15, IMD Data Shows ANNAM.AI and Syngenta Partner to Deliver AI-Driven Climate-Smart Agriculture to Indian Farmers Microsoft CEO Satya Nadella warns AI dominance could 'hollow out entire industries'
Home ›› Technology ›› Ai ›› Ai Ethics ›› Meta confirms thousands of Instagram accounts were hacked by abusing its AI chatbot

Meta confirms thousands of Instagram accounts were hacked by abusing its AI chatbot

Meta confirmed that hackers abused a flaw in its AI chatbot to reset passwords for thousands of Instagram accounts, affecting at least 20,225 users. The attack exploited a bug that allowed the chatbot to send password reset links to unverified email addresses. This incident underscores the security risks enterprises face when deploying AI chatbots for account management and authentication.

iG
iGEN Editorial
June 14, 2026
Meta confirms thousands of Instagram accounts were hacked by abusing its AI chatbot

Enterprises deploying AI chatbots for customer-facing account management must reassess their security posture after Meta confirmed that thousands of Instagram accounts were hijacked through abuse of its AI-powered account recovery system. According to a data breach notification letter filed with Maine's attorney general's office and seen by this week in security, Meta notified at least 20,225 people that their accounts had been compromised, including 30 people in Maine. The hacks began around April 17 and lasted until early June, when Meta secured the chatbot.

How the Chatbot Was Tricked

As previously reported by 404 Media and TechCrunch, hackers exploited a vulnerability in Meta's AI-assisted account recovery system for Instagram. The flaw allowed anyone to reset the password of any account that did not have two-factor authentication enabled. The chatbot could be tricked into sending a password reset verification code to an email address controlled by the attacker, rather than the account holder's email on file. The chatbot complied simply upon request.

In its breach notice, Meta explained: "The tool itself worked properly and functioned as intended; however due to a bug in a separate code path, the system did not properly verify that the email address provided by the individual requesting a password reset matched the email address associated with that user’s Instagram account." As a result, an unauthorized third party could provide an email address not associated with the account, and the system incorrectly sent a password reset link to that unassociated email. This allowed the hackers to reset the password and take over the account fully.

Scope of the Compromise

The data breach notification detailed that the compromise allowed hackers to take over the entire Instagram account and any linked accounts. Attackers could obtain contact information, dates of birth, and profile information, as well as access the person's posts, direct messages, and account activity. Meta stated it is "unaware" of what personal information was accessed during the hacks, though an email to Meta's press line was not returned as of early Saturday.

Key Fact Detail
Total affected accounts 20,225
Affected accounts in Maine 30
Hack start date April 17, 2026
Hack end date Early June 2026 (when chatbot was secured)
Root cause Bug in code path: chatbot did not verify email address matched account
Mitigation Chatbot disabled, code path removed, affected users instructed to reset passwords

Enterprise Implications for AI Chatbot Security

For enterprise technology leaders, the Instagram hack serves as a cautionary tale. AI chatbots are increasingly deployed for password resets, account recovery, and customer authentication across supply chain platforms, trade finance portals, and logistics systems. The flaw here was not a failure of the AI model itself, but of the integration logic—a separate code path that bypassed email verification. Meta confirmed that it has disabled the AI chatbot for now, removed the offending code path, and is checking other chatbots across its platforms to prevent a repeat incident.

Enterprise CTOs should review their own AI-assisted account recovery systems to ensure that any password reset or authentication request is robustly validated against the user's registered contact information. This incident also reinforces the importance of enforcing two-factor authentication (2FA) for all accounts, as the hack was only possible against accounts without 2FA enabled.

Meta's Response

Meta instructed impacted users to reset their passwords and re-authenticate through secure, verified channels. The company said the hacks lasted from April 17 until the time of disclosure in early June, when it secured the chatbot. The incident comes soon after Meta laid off thousands of employees while rewarding top performers, highlighting the potential operational risks when AI systems are deployed without sufficient guardrails.


Sources:

Keep Reading

Recommended Stories

Novo Nordisk Reveals Clinical Trials Data Breached in Cyberattack, Patient IDs Exposed Technology

Novo Nordisk Reveals Clinical Trials Data Breached in Cyberattack, Patient IDs Exposed

Novo Nordisk, the maker of Ozempic and Wegovy, confirmed a cyberattack that breached pseudonymized clinical trial data, including patient IDs, biomarkers, and lifestyle factors. The company stated no personally identifiable information (PII) was exposed and core operations remain unaffected. Third-party cybersecurity experts are investigating.

June 15, 2026
Instagram expands algorithm personalization, but not for accounts you follow Technology

Instagram expands algorithm personalization, but not for accounts you follow

Instagram has expanded its algorithm personalization feature to the main feed, allowing users to control which topics they see more or less of. However, the feature does not support requests to see more posts from accounts the user follows, a limitation that frustrates creators and businesses. Instagram chief Adam Mosseri explained that the change is powered by large language models and aims to give users more agency, but acknowledged that the decline of the 'following' feed was a consequence of shifting user behavior.

June 15, 2026
AI Innovation Meets Identity Security Reality for Global Trade Networks Technology

AI Innovation Meets Identity Security Reality for Global Trade Networks

Anthropic's Claude Mythos AI model promises defensive capabilities but also expands attack surfaces. Keeper Security warns that identity security fundamentals remain unchanged, with credential-based attacks still the primary threat. Trade organizations must manage non-human identities and enforce least privilege controls.

June 15, 2026
FBI Dismantles AI-Powered Phishing Service That Used Over a Million URLs to Steal Credit Cards Technology

FBI Dismantles AI-Powered Phishing Service That Used Over a Million URLs to Steal Credit Cards

The FBI dismantled a Chinese phishing-as-a-service operation called Outsider Enterprise, seizing servers, cryptocurrency, and a Telegram bot. The three-year-old service generated around 9,000 fake websites and over a million fraudulent URLs, resulting in theft of 3.8 million credit card records and $1.9 billion in losses. Google filed a civil lawsuit and reported that criminals sent 2.5 million fraudulent SMS messages in just two weeks.

June 15, 2026