Published 2 days ago • loading... • Updated 2 hours ago
Over 20,000 Instagram Accounts Stolen in Meta AI Support Hack
Meta said the flaw let attackers send password reset links to unverified emails and potentially access contact information, direct messages and connected accounts.
Over 20,000 Instagram users had their accounts hijacked after attackers exploited a vulnerability in Meta's AI-assisted 'High Touch Support' system to reset passwords without authorization.
The HTS tool failed to verify if email addresses were associated with targeted accounts, allowing attackers to obtain password reset links and bypass two-factor authentication protecting the accounts.
Meta disabled the AI-powered support system and all generated password reset links, enrolling affected users into mandatory security checkpoints and requiring them to reset passwords again.
Andy Stone, Meta's vice president of communications, stated the 'issue has been resolved,' while a filing with Maine's Office of the Attorney General documented 30 compromised users in that jurisdiction.
Amid previous fines totaling $275.5 million for data protection failures, Meta will 'fix the authentication check' before relaunching the tool and conduct a comprehensive review of similar account recovery flows.