Skip to main content
Mallory
Back to intelligence
identity-authentication-vulnerabilitymass-credential-exposurebreach-disclosure-notificationcredential-access-method

Meta AI Recovery Flaw Enabled Instagram Account Takeovers at Scale

Updated 3h agoFirst seen Jun 1, 202629 sources

Meta disclosed that attackers exploited a flaw in its AI-assisted Instagram account recovery system, known as High Touch Support (HTS), to reset passwords for accounts they did not own. Reporting tied the abuse to earlier takeovers of high-profile and valuable accounts including the archived Obama White House profile, Jane Manchun Wong, Sephora, a senior U.S. Space Force official, and sought-after short handles such as @hey and @jowo, some of which were briefly defaced or advertised for resale on Telegram. Multiple reports said attackers used VPNs or residential proxies to appear near a victim’s usual location, then manipulated Meta’s support workflow to add an attacker-controlled email address or receive a reset link without compromising the victim’s inbox.

Meta later said the vulnerable code path failed to verify that the submitted recovery email matched the email already associated with the target account, exposing 20,225 users between roughly April 17 and the end of May; successful takeovers were generally possible when victims had not enabled two-factor authentication. The company said it discovered the exploitation on May 31, disabled the HTS tool, invalidated reset links, forced affected accounts through security checkpoints and password resets, and plans to notify impacted users while reviewing similar recovery flows across its platforms. The incident drew broader scrutiny because an AI-driven support layer was allowed to perform privileged identity and recovery actions without deterministic verification, turning customer support into an account-takeover path.

Share:
Meta AI Recovery Flaw Enabled Instagram Account Takeovers at Scale
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
Jun 19, 2026just now

Meta schedules notifications to affected users

Meta said it plans to notify impacted users on 2026-06-19 about the Instagram recovery incident. The notice would require password resets and re-authentication before access is restored through verified channels.

Instagram Recovery Tool Bug Exposed 20,225 Accounts to Password Reset Abuse
Jun 8, 20262d ago

Meta discloses 20,225 Instagram accounts were exposed

Meta disclosed in filings reported on June 8 that a validation flaw in its AI-assisted High Touch Support recovery tool exposed 20,225 Instagram accounts to unauthorized password resets and possible takeover when two-factor authentication was not enabled. The company said it does not know exactly what data attackers accessed but warned that profile data, messages, account activity, and linked-service information may have been viewed.

Meta AI Recovery Tool Flaw Exposed 20,000+ Instagram Accounts - Security Affairs

Meta disables HTS and secures affected accounts

After discovering the flaw, Meta disabled the High Touch Support tool, invalidated reset links generated through the vulnerable path, and placed affected accounts behind mandatory security checkpoints. The company also required password resets and re-authentication and said it would review similar recovery flows across its platforms.

Meta AI Recovery Tool Flaw Exposed 20,000+ Instagram Accounts - Security Affairs
Jun 1, 20269d ago

Meta fixes the AI support account-takeover issue

Meta said it fixed the Instagram AI support flaw after reports surfaced, with Andy Stone stating on Monday that the issue had been resolved and affected accounts were being secured. Multiple reports describe the remediation as an emergency patch or hotfix to stop the abusive recovery flow.

Hackers hijacked Instagram accounts by tricking Meta AI support chatbot into granting access | TechCrunch

Reports surface of notable Instagram account hijackings

By the end of May and start of June, multiple reports described takeovers of high-profile Instagram accounts including the Obama White House archive, Jane Manchun Wong, Sephora, and a senior U.S. Space Force official. Some compromised accounts were briefly defaced with pro-Iranian imagery, and stolen short-handle accounts were reportedly offered for resale on Telegram.

Hackers hijacked Instagram accounts by tricking Meta AI support chatbot into granting access | TechCrunch

Meta expands AI support to Facebook and Instagram

Meta announced in March that AI support would be expanded across Facebook and Instagram, including functions such as password resets and account security recovery. Another report says Meta began using the AI support assistant for customer service in March.

Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked
May 31, 202610d ago

Meta discovers exploitation of the HTS recovery flaw

Meta said it discovered the issue on 2026-05-31 after the vulnerable recovery path had been exploited in the wild. The company determined that the flaw affected Instagram account recovery by failing to validate that the submitted recovery email matched the account on file.

Meta AI Recovery Tool Flaw Exposed 20,000+ Instagram Accounts - Security Affairs

Telegram videos and instructions publicize the takeover method

Telegram channels circulated instructions and a demonstration video showing how attackers could use Meta's AI support workflow to add a new email address and reset a victim's password. One report explicitly anchors these posts and videos to May 31.

Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts - Krebs on Security
Apr 17, 20262mo ago

Attackers begin exploiting Instagram recovery flaw

Meta later disclosed that exploitation of the vulnerable AI-assisted High Touch Support recovery flow began on 2026-04-17. The flaw let password reset links be sent to email addresses not associated with the targeted Instagram accounts.

Meta AI Recovery Tool Flaw Exposed 20,000+ Instagram Accounts - Security Affairs
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.