
Meta confirms 20,225 Instagram accounts were hijacked through its AI chatbot
Meta is notifying at least 20,225 people that their Instagram accounts were taken over by hackers who tricked its AI chatbot into resetting passwords on accounts without two-factor authentication.
Meta is notifying thousands of people whose Instagram accounts were hijacked during a months-long campaign that abused the company's AI chatbot, according to a data breach notification letter seen by the security publication this week in security. In a breach notice filed with Maine's attorney general's office late on Friday, Meta said it had notified at least 20,225 people that their accounts were compromised, including 30 people in Maine.
What the notice says
The compromises let attackers take over a person's entire Instagram account and any linked accounts. According to the notice, the data involved includes contact information, dates of birth and profile information, along with access to the person's posts, direct messages and account activity. Meta's filing states that the breach relates to "a vulnerability in an AI-assisted account recovery system for Instagram" that was exploited to "perform password resets on Instagram user accounts." According to Maine's listing, the hacks began around April 17 and lasted until this week, when Meta said it had secured the chatbot.
How the chatbot was tricked
As previously reported, hackers abused a flaw that allowed anyone to reset the password of any account that did not have two-factor authentication switched on. The bug let them trick the chatbot into sending a verification code to an email address controlled by the attacker rather than the account holder's email address on file, simply by asking it to. In its breach notice, Meta described the failure as a missing check in a separate code path: "The tool itself worked properly and functioned as intended; however due to a bug in a separate code path, the system did not properly verify that the email address provided by the individual requesting a password reset matched the email address associated with that user's Instagram account." The company added that when an address not previously associated with an account was supplied, the system sent a reset link to that unassociated email instead of rejecting the request, allowing unauthorized third parties to receive reset links for accounts they did not own. From there, the attackers could set a new password and take over the account as if they were its rightful owner.
Meta's response
Meta said it is "unaware" of what personal information, if any, was accessed during the hacks. The company confirmed it instructed affected users to reset their passwords and re-authenticate through secure, verified channels. Meta added that it has disabled the AI chatbot for now and removed the code path that allowed it to reset user accounts, and that it is reviewing other chatbots across its platforms to prevent a repeat incident. The campaign was discovered earlier this week and first reported by 404 Media and TechCrunch.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.