Quick Facts
- At least 20,225 Instagram accounts were compromised through Meta’s AI chatbot between April 17 and early June 2026
- Hackers tricked the AI assistant into sending password reset codes to attacker-controlled email addresses without any hacking tools
- High-profile victims included the Obama White House, Sephora, and US Space Force Chief Master Sergeant accounts
Meta has confirmed that hackers exploited its AI-powered support chatbot to compromise at least 20,225 Instagram accounts over nearly seven weeks. The vulnerability operated from April 17 through early June 2026, making it one of the most significant AI-related security breaches in recent history.
The attack exploited a flaw in Meta’s AI assistant that allowed anyone to reset passwords for accounts without two-factor authentication. Hackers simply told the chatbot they owned target accounts and requested password resets be sent to email addresses they controlled.
“The tool itself worked properly and functioned as intended; however due to a bug in a separate code path, the system did not properly verify that the email address provided by the individual requesting a password reset matched the email address associated with that user’s Instagram account,” Meta explained.
The attack required no sophisticated hacking tools or special access. Hackers used VPN services to appear in the same geographic area as targets, then asked Meta’s AI chatbot to link accounts to attacker-controlled emails. The chatbot complied without requiring login credentials.
Compromised accounts included high-profile targets like the Obama White House, Sephora, and US Space Force Chief Master Sergeant John Bentivegna. Security researchers estimate the stolen accounts were worth over $500,000 combined, with some individual accounts valued at over $1 million.
“We’re entering unchartered security territory as more large online platforms start allowing AI chatbots to handle sensitive account recovery requests,” said Ian Goldin, threat researcher at Lumen’s Black Lotus Labs. “AI chatbots create interesting new attack surface, and we’re likely going to see a lot more of these kinds of attacks.”
Meta identified the vulnerability on May 31, 2026, and secured the chatbot in early June. The company has disabled the affected AI-assisted support tool, invalidated compromised password reset links, and required additional authentication for potentially affected accounts.
Data potentially exposed through compromised accounts included contact information, dates of birth, photos, videos, direct messages, account activity, and profile information. Meta filed a data breach notification with Maine’s attorney general’s office on June 6, 2026.
The incident occurred just eleven days after Meta cut roughly 8,000 employees, including staff from integrity and cybersecurity teams. Security experts note the timing raises questions about oversight as companies increasingly deploy AI agents with account permissions.
“Andy Stone, Meta VP of Communications, confirmed: “This issue has been resolved and we are securing impacted accounts. Some people may receive password reset notifications and some may be asked security questions when they try and log into their accounts.”
Read more: Hackers likely hijacked over 20,000 Instagram accounts with Meta’s AI chatbot
This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.
