General

Meta confirms 20,225 Instagram accounts hacked via AI chatbot flaw

Meta notified at least 20,225 people that their Instagram accounts were compromised by hackers exploiting a bug in the company's AI chatbot. The flaw allowed attackers to bypass password resets on accounts without two-factor authentication. Meta has since disabled the chatbot and fixed the vulnerability.

Neura News

Neura News

Neura Market Editorial

June 6, 20263 min read
Meta confirms 20,225 Instagram accounts hacked via AI chatbot flaw

Meta has revealed that thousands of Instagram users had their accounts hijacked through a vulnerability in its AI chatbot system. The company filed a data breach notice with Maine's attorney general's office on Friday, disclosing that at least 20,225 people were affected, including 30 residents of Maine.

The notice, reviewed by this week in security, provides the first official count of compromised accounts in a hacking campaign that security reporters at 404 Media and TechCrunch covered earlier this week. The breaches allowed attackers to take over entire Instagram profiles along with any linked accounts. Hackers gained access to contact details, birth dates, profile information, posts, direct messages, and account activity.

Details of the Breach

Meta attributed the incident to a vulnerability in an AI-assisted account recovery feature for Instagram. The bug enabled attackers to perform password resets on accounts that did not have two-factor authentication enabled. According to the company's notice, the flaw existed in a separate code path that failed to verify whether the email address provided by the person requesting a password reset matched the one on file for that account.

"The tool itself worked properly and functioned as intended; however due to a bug in a separate code path, the system did not properly verify that the email address provided by the individual requesting a password reset matched the email address associated with that user's Instagram account," Meta said in the breach notice.

The company explained that when someone supplied an email address not previously linked to the account, the system incorrectly sent a password reset link to that unassociated email instead of rejecting the request. This allowed unauthorized third parties to receive password reset links for accounts they did not own. Once the reset was completed, the attackers could log in as the rightful account owner.

The #1 Newsletter in AI

Stay ahead of the AI curve

The most important updates, news, and content — delivered weekly.

No spam. Unsubscribe anytime.

How the Attack Worked

As previously reported, hackers abused Meta's AI chatbot by asking it to send a verification code to an email address they controlled. The chatbot complied because it did not check whether the email belonged to the account holder. Meta noted that the attacks began around April 17 and continued until this week, when the company secured the chatbot. Instagram started notifying affected users earlier this week by sending password reset notifications, though some users reported that the hacks were still occurring at that time.

Meta said it is unaware of exactly what personal information, if any, was accessed during the hacks. The company did not respond to a press inquiry seeking clarification as of early Saturday.

Meta's Response and Next Steps

Meta confirmed that it instructed impacted users to reset their passwords and re-authenticate through secure, verified channels. The company has disabled the AI chatbot for now and removed the code path that allowed it to reset user accounts. Meta also said it is reviewing other chatbots across its platforms to prevent a similar incident.

The circumstances leading to the chatbot's abuse remain unclear. However, the incident comes shortly after Meta laid off thousands of employees while granting stock incentives to top executives as the company continues to invest heavily in artificial intelligence.

Related on Neura Market:

More from Neura News

Industry

Monday.com Joins Tech Layoff Trend Citing AI as Factor

Monday.com announced it will lay off about 20% of its workforce, or over 600 employees, citing a restructuring tied to its AI-driven growth strategy. The Tel Aviv-based work management software company joins a growing list of major tech firms, including Amazon, Meta, and Microsoft, that have cited artificial intelligence as a factor in job cuts this year. A new Financial Times analysis shows U.S. tech companies have slashed nearly 140,000 jobs since January, with AI often cited as a reason.

Jul 26·12 min read
General

Open-weight AI mirrors Kubernetes ecosystem shift

Tobi Knaup, co-founder of Mesosphere, draws parallels between the rise of Kubernetes and the current trajectory of open-weight AI models. He argues that open-weight models are becoming a neutral substrate for innovation, attracting a global ecosystem of developers, startups, and enterprises. The piece warns against US restrictions on Chinese open-weight models, advocating instead for American leadership through open releases, procurement strategies, and standards.

Jul 25·7 min read
General

Open-weight AI mirrors Kubernetes rise, US warned on bans

The author, a Mesosphere co-founder, draws parallels between the rise of Kubernetes and the current open-weight AI ecosystem. He argues that open-weight models are becoming a neutral platform for innovation, and warns that US restrictions on Chinese open-weight models could isolate American developers from a global ecosystem. The piece urges the US to compete by releasing frontier models, using procurement to create demand, building the stack, and setting standards rather than imposing bans.

Jul 25·7 min read
Industry

Power line failure reveals AI data center grid risks and solutions

A fallen power line near Washington, DC caused over 3 gigawatts of data center load to vanish from the PJM grid in seconds, spiking voltage across the region. The event, which made lights flicker from Northern Virginia to Chicago, highlights a growing problem as AI data centers become larger and more concentrated. Experts warn that without better coordination or technology like ON.Energy's battery-backed uninterruptible power supply, such disruptions will become more frequent and severe.

Jul 25·5 min read