Over 20,000 Instagram accounts stolen in Meta AI support hack
Meta says more than 20,000 Instagram accounts were hijacked through a flaw in its AI-assisted support tool.
Intelligence analysis by GPT-5.4 Mini

Attackers abused Meta's High Touch Support recovery system to trigger password resets for Instagram accounts without properly verifying email ownership. Meta says it has secured affected accounts, disabled the tool, and is reviewing similar recovery flows.
A broken help desk at a store gave the wrong people new keys to lockers. The thieves used that mistake to open Instagram accounts, so Meta had to lock things down, make people change passwords, and fix the help desk rule.
Analysis
What happened
Meta disclosed that attackers exploited a flaw in its AI-assisted Instagram recovery tool, called High Touch Support (HTS), to reset passwords and take over accounts. The core issue was that the tool did not properly verify whether an email address actually belonged to the Instagram account being recovered.
Scope and impact
According to the breach letter filed with Maine's Office of the Attorney General, Meta said the vulnerability potentially affected 30 users in that jurisdiction. Separately, the company said more than 20,000 Instagram accounts were hijacked in the wider incident. Meta also said it does not yet know exactly what information may have been accessed, but the possible exposure could include email addresses, phone numbers, dates of birth, posts, photos, videos, stories, direct messages, account activity, profile details, and linked services.
What Meta did
After learning about the abuse, Meta disabled the HTS support system and revoked the password reset links it had generated. It also placed potentially affected accounts into a mandatory security checkpoint and required users to reset passwords again and re-authenticate. Meta said it will fix the authentication check before relaunching the tool and is reviewing similar recovery flows across its platforms.
Why this stands out
This was not a break-in through a stolen password alone. It was a failure in the account recovery process, which is supposed to help legitimate users regain access. The incident shows that support and recovery systems need the same level of verification as login flows, especially when they can generate password reset links.
The report also notes that the attack appears to have started on April 17, while Meta said it discovered the issue on May 31, 2026. That gap suggests the abuse may have continued until the company identified and shut down the flaw.
Key points
- Meta says more than 20,000 Instagram accounts were hijacked through its AI-assisted support system.
- Attackers abused a flaw in High Touch Support by triggering password resets without proper email verification.
- Meta says potentially exposed data could include messages, posts, profile details, and linked services.
- The company disabled the tool, revoked reset links, and forced affected users through extra security checks.
- Meta says it will fix the verification step and review similar recovery flows across its platforms.
Meta says it disabled the abused recovery tool, revoked the reset links, and added extra checks for affected accounts. If the planned verification fix and wider review work as intended, the same mistake should be harder to repeat across Meta's platforms.
The incident shows that account recovery systems can be an easier target than the login page itself. If similar flows elsewhere at Meta have the same weakness, attackers could keep finding ways to trigger unauthorized resets and access private account data.



