Industry

Meta reveals Instagram AI chatbot breach affected over 20,000 accounts

Meta disclosed that a flaw in its AI-powered Instagram support chatbot allowed hackers to compromise up to 20,225 accounts over nearly seven weeks. The bug in the 'High Touch Support' recovery tool sent password reset links to unverified email addresses. Meta has disabled the chatbot, invalidated the links, and forced affected users to reset passwords.

Neura News

Neura News

Neura Market Editorial

June 8, 20262 min read
Meta reveals Instagram AI chatbot breach affected over 20,000 accounts

Meta has disclosed that a vulnerability in its AI-powered support chatbot for Instagram may have affected up to 20,225 user accounts. The company revealed the number for the first time in a data breach notification filed with the Maine Attorney General's office.

The hacking campaign ran for nearly seven weeks, starting around April 17, 2026, according to the notification. The flaw was discovered on May 31. At least 20,225 accounts were compromised, including 30 accounts belonging to Maine residents.

Breach details

Attackers exploited Meta's AI-powered support chatbot, which was designed to help locked-out users regain access to their accounts. The tool, called "High Touch Support," contained a bug in a separate code path. This bug meant the system never checked whether the email address provided by a user actually belonged to the Instagram account in question.

As a result, hackers were able to send password reset links to any email address without verification. The attackers then used those links to take over the target accounts. Meta called the 20,225 figure an upper bound, noting that some access attempts may have come from legitimate account holders.

The data that was potentially exposed includes contact information, birth dates, posts, direct messages, account activity, profile information, and linked services. Meta stated that it does not know which information was actually viewed by the attackers.

The #1 Newsletter in AI

Stay ahead of the AI curve

The most important updates, news, and content — delivered weekly.

No spam. Unsubscribe anytime.

Thisweekinsecurity first reported on the notification.

Meta's response

As an immediate response, Meta disabled the AI chatbot and removed the faulty code path. The company also invalidated all password reset links that had been generated through the affected system. Affected users were placed into a mandatory security checkpoint and were asked to reset their passwords through verified channels.

Before reactivating the tool, Meta plans to fix the email verification step in the recovery process. The company also intends to audit similar account recovery systems across all of its platforms.

The incident comes at a time when Meta has laid off thousands of employees while betting heavily on artificial intelligence. The AI support chatbot had previously been marketed by Meta as a win for account security.

Related on Neura Market

More from Neura News

General

Open-weight AI mirrors Kubernetes ecosystem shift

Tobi Knaup, co-founder of Mesosphere, draws parallels between the rise of Kubernetes and the current trajectory of open-weight AI models. He argues that open-weight models are becoming a neutral substrate for innovation, attracting a global ecosystem of developers, startups, and enterprises. The piece warns against US restrictions on Chinese open-weight models, advocating instead for American leadership through open releases, procurement strategies, and standards.

Jul 25·7 min read
General

Open-weight AI mirrors Kubernetes rise, US warned on bans

The author, a Mesosphere co-founder, draws parallels between the rise of Kubernetes and the current open-weight AI ecosystem. He argues that open-weight models are becoming a neutral platform for innovation, and warns that US restrictions on Chinese open-weight models could isolate American developers from a global ecosystem. The piece urges the US to compete by releasing frontier models, using procurement to create demand, building the stack, and setting standards rather than imposing bans.

Jul 25·7 min read
Industry

Power line failure reveals AI data center grid risks and solutions

A fallen power line near Washington, DC caused over 3 gigawatts of data center load to vanish from the PJM grid in seconds, spiking voltage across the region. The event, which made lights flicker from Northern Virginia to Chicago, highlights a growing problem as AI data centers become larger and more concentrated. Experts warn that without better coordination or technology like ON.Energy's battery-backed uninterruptible power supply, such disruptions will become more frequent and severe.

Jul 25·5 min read