Meta is informing thousands of Instagram users that their accounts were allegedly hijacked. This was due to a security flaw in its AI-assisted account recovery system.
Recent reports have revealed that hackers used an AI-powered support tool to reset account passwords, impacting over 20,000 Instagram users. The incident has sparked renewed concerns about the risks of using AI systems for sensitive account support and security functions.
What happened with the Instagram hack?
The Instagram hack was linked to a vulnerability in Meta’s AI-assisted account recovery system. Hackers reportedly duped the support system into sending password reset links to email addresses they actually controlled. These emails were sent instead of to the email address linked to the legitimate account holder.
The attackers could then use the reset link to change the password on the account and take over the Instagram profile.
The problem was especially dangerous for accounts without two-factor authentication enabled. Without that extra layer of protection, compromised accounts were easier for hackers to take over.
More Than 20,000 Users Were Affected
Meta has reportedly notified 20,225 Instagram users whose accounts were targeted or compromised through the vulnerability.
The exposed account information may have included profile details, account activity, posts, direct messages, contact information, and other data tied to Instagram and linked accounts. Additionally, Meta has said it is not aware of exactly what personal information may have been accessed in every case.
Affected users were instructed to reset their passwords and secure their accounts through verified recovery channels.
Meta Says the Issue Has Been Fixed
Meta has said the vulnerability has been addressed. The company reportedly disabled the affected AI support function. In addition, it removed the code path that allowed the password reset issue to occur.
Meta is also reviewing similar chatbot systems across its platforms to help prevent the same type of exploit from happening again.
Why This Instagram Hack Matters
This incident underscores a rising concern around AI-driven customer support solutions, especially when those solutions are connected to account recovery, identity verification, or other sensitive systems.
AI chatbots can accelerate support, but they can also introduce new security holes if they are allowed to take actions without strict verification checks. In this instance, attackers were said to be able to fool the system into thinking they were legitimate owners of the accounts.
The Instagram hack is a reminder that social platforms need to be better protected before they offload more account support responsibilities to AI systems.
What Instagram users should do now
Instagram users should take a few basic steps to protect their accounts
Use a strong, unique password.
Check login activity for devices you don’t recognize.
Remove unknown email addresses or phone numbers from the account
Watch out for password reset and suspicious account recovery emails.
If you have received any notification from Meta, do not click on links from unknown messages or third-party sources. Instead, follow the official account recovery instructions of Instagram.
Big Questions on AI and Social Media Security
Meta and other social platforms are investing heavily in AI tools for moderation, support, advertising and user assistance. But this Instagram hack exposes the vulnerability of AI systems when they are given too much autonomy without adequate security measures.
Account safety will be a huge issue as social media companies replace manual support processes with automated AI tools. Platforms will need to prove that AI can do sensitive jobs which bad actors cannot game.
For now, the incident is a reminder that users should not rely only on platform security. Enabling two-factor authentication and regularly reviewing account settings remain two of the most important ways to protect an Instagram account.
