Skip to main content
TechnologyJun 8, 2026· 2 min read

Meta Admits AI Flaw on Instagram: Over 20,000 Accounts Compromised

Meta capitulates in front of a structural vulnerability of its virtual assistant, confirming the hijacking of at least 20,225 Instagram accounts. A months-long exploitation campaign has exposed the limits of a hasty integration of artificial intelligence into critical security systems, highlighting how the rush to implement automated solutions can compromise the stability of platforms.

The details emerge from the data breach notification sent by the company to the office of the Attorney General of Maine, shedding light on a dynamic that is as banal in its execution as it is devastating in its effects. The attack targeted the AI-assisted account recovery system of Instagram directly. The attackers exploited a flaw in the logical flow of the chatbot to force password resets on profiles that had not activated two-factor authentication (2FA).

The flaw in Instagram was in the password recovery code. The mechanism tricked the virtual assistant into sending the verification code to an email address controlled by the hacker, ignoring the original address registered on the platform and bypassing standard security protocols. The technical explanation provided by Meta highlights a classic misalignment problem in security controls.

Although the chatbot performed its nominal functions correctly, a separate segment of code did not verify the match between the email provided by the external user and the one associated with the profile for which the credential reset was requested. The system sent the reset link to the unassociated address instead of rejecting the request, handing over the keys to accessing accounts to cybercriminals.

Once control was obtained, the malicious actors could access the entire ecosystem of the victim, including linked profiles, personal information (such as birth dates and contact details), direct messages, and overall activity. The intrusion campaign began on April 17 and remained active until the recent deactivation of the service, leaving thousands of users exposed for an extended period.

To mitigate the damage, Meta has removed the flawed line of code and temporarily disabled the chatbot on Instagram. The group is conducting similar checks on all other virtual assistants across its platforms to prevent similar flaws. It is noteworthy that the vulnerability exists within a complex corporate context, characterized by significant cuts to technical staff amid massive investments and strong incentives to accelerate the development of AI-based technologies.

The company now urges all potentially affected individuals to change their credentials through secure and verified channels, seeking to defend the infrastructure from logical flaws that enabled the incident.