Meta has confirmed that a vulnerability in its AI-assisted account recovery system allowed hackers to hijack over 20,000 Instagram accounts by tricking the chatbot into resetting user passwords.
Key Points
- Meta notified 20,225 individuals that their Instagram accounts were compromised between April 17 and this week.
- The breach occurred because a chatbot bug failed to verify that password reset requests matched the email address associated with the target account.
- Hackers gained full access to compromised profiles, including private direct messages, contact information, and account activity.
- Meta has disabled the affected AI chatbot and removed the flawed code path to prevent further unauthorized password resets.
- The company is currently auditing other AI chatbots across its platforms to identify and mitigate similar security vulnerabilities.