Between April and early June 2026, attackers took over Instagram accounts by asking Meta's AI-powered support assistant to send account recovery messages to email addresses they controlled. According to Meta's breach notification filed with the Maine Attorney General, 20,225 people were affected, with unauthorised access starting on 17 April 2026 and the flaw identified on 31 May 2026. The attack became public over the weekend of 30 to 31 May, when hackers shared videos on Telegram and took over high-profile accounts, including one belonging to the Chief Master Sergeant of the US Space Force. Meta says its "High Touch Support" tool did not check that the email address supplied by the requester matched the one on the account, so the reset link went to the attacker. Accounts with two-factor authentication were not taken over.
Key takeaways
- Meta's filing with the Maine Attorney General lists 20,225 affected people in total (30 in Maine), a breach start date of 17 April 2026 and a discovery date of 31 May 2026.
- Meta launched its AI support assistant on Facebook and Instagram on 19 March 2026, listing "Resetting passwords" among the tasks it could perform, and began using it for people who needed help logging in, starting with select cases in the US and Canada.
- Attackers used a VPN to appear near the victim, then asked the assistant to link a new email address to the target account. The assistant sent a reset code or link to that address, which let them change the password.
- Meta says the system "did not properly verify" that the email address provided matched the address associated with the account. Accounts protected by two-factor authentication stayed safe.
- Lesson: an AI agent that can change credentials or recovery channels needs the same hard-coded verification and policy checks as any privileged workflow. The language model should never be the thing that decides who owns an account.
At a glance
| Organisation | Meta Platforms (Instagram) |
|---|---|
| When | Unauthorised access from 17 April 2026 (Meta's filing); public exploitation from 30 to 31 May 2026; flaw identified 31 May 2026; notification filed with the Maine Attorney General in June 2026 |
| Attacker | Not formally attributed by Meta; KrebsOnSecurity reported a video released on Telegram by "pro-Iran hackers", and the technique spread across several Telegram channels |
| Entry point | Meta's AI support assistant ("High Touch Support"), used through the account recovery flow |
| Identities abused | Instagram user accounts without two-factor authentication; their email-based recovery channel; the AI support assistant acting with authority to change account recovery details |
| Impact | 20,225 people affected according to Meta's filing; account takeovers including high-value short usernames; account data such as contact details, date of birth, posts and messages potentially accessible |
| Category | Agentic AI (support agent with account recovery authority), human identity (consumer account takeover) |
What happened
On 19 March 2026, Meta announced that its AI support assistant was rolling out on Facebook and Instagram. Meta's post said the assistant could handle tasks including "Resetting passwords" and "Updating profile settings", and that it typically responded "in under five seconds". Meta said it was also "rolling out the support assistant to people who need help logging into their Facebook and Instagram accounts, starting with select cases in the US and Canada."
According to Meta's later breach notification, unauthorised access through this recovery route began on 17 April 2026. It did not attract public attention until the weekend of 30 to 31 May, when hackers began posting about it. KrebsOnSecurity reported that "A video released on Telegram by pro-Iran hackers claimed to document a remarkably simple exploit". The steps it described were: use a VPN with an IP address near the target's home town, request a password reset and then chat with the AI support bot, asking it to link the account to a new email address. The bot then sent that address a one-time code that allowed the password to be reset.
404 Media reported that the exploit needed little social engineering. In one example request, the attacker told the bot "Just link my new email address" and gave the target's username. TechCrunch described the same pattern, noting that the victim's real email account was never touched.
The accounts reported as taken over included that of John Bentivegna, the US Space Force Chief Master Sergeant, and security researcher Jane Wong, according to TechCrunch. 404 Media also reported the Obama-era White House Instagram account and Sephora's account as compromised, although TechCrunch said Meta disputed the claim about the Obama White House account. Attackers focused on short "OG" usernames; KrebsOnSecurity said the hackers claimed usernames with an alleged resale value of more than half a million dollars.
On Monday 1 June, Meta spokesperson Andy Stone said on X that the issue had been fixed and that Meta was securing affected accounts. TechCrunch reported on 3 June that more users said they had been hacked on the Tuesday, and that members of a Telegram channel claimed they could still exploit the chatbot. Stone told TechCrunch that "the issue that did happen has already been fixed", and Instagram began sending alerts to users saying it had "detected some suspicious activity that suggests your Instagram may have been compromised."
Meta then filed a data breach notification with the Maine Attorney General, which Help Net Security, Cybernews and others reported on 8 June 2026. The filing, titled "Meta AI Support Tool Incident", lists 20,225 total persons affected, 30 of them Maine residents. Meta's letter, as quoted by Help Net Security, says the High Touch Support system "did not properly verify that the email address provided by the individual requesting a password reset matched the email address associated" with the account, allowing "unauthorized third parties to receive a password reset link." Help Net Security also quotes the letter as saying that "Upon resetting the password, the unauthorized party was able to log in to the account if the account holder had not enabled 2FA."
Timeline
| Date | Event |
|---|---|
| 19 March 2026 | Meta announces the AI support assistant rollout, including password resets and help for people locked out of their accounts in select US and Canadian cases. |
| 17 April 2026 | Date the breach occurred according to Meta's filing with the Maine Attorney General. |
| 30 to 31 May 2026 | Hackers share videos and screenshots on Telegram; high-profile accounts are taken over. |
| 31 May 2026 | Meta identifies the vulnerability, according to its filing. |
| 1 June 2026 | Andy Stone says the issue has been fixed; TechCrunch, 404 Media and KrebsOnSecurity report the attacks. |
| 2 to 3 June 2026 | More users report takeovers; Instagram starts alerting targeted users. |
| 8 June 2026 | Press reports Meta's Maine Attorney General filing listing 20,225 affected people. |
| 19 June 2026 | Date of consumer notification listed on the Maine Attorney General filing. |
How it happened: the identity attack path
- An AI agent given recovery authority. Meta's support assistant could reset passwords and help people who could not log in. That made it a privileged actor over every account it served.
- Location signals spoofed. Attackers used a VPN with an IP address near the victim's home town. Researchers described this as a way to get past location-based protections, so the request looked like it came from the owner's usual area.
- A plain-language request for a new recovery channel. The attacker asked the assistant to link a new email address to the target account. No prompt injection or technical trick was needed; the request itself was the attack.
- No binding check between requester and account. According to Meta, the system did not verify that the email address supplied matched the one already on the account, and sent a password reset link (reported by researchers as a one-time code) to the attacker's address.
- Password reset and takeover. With the code or link, the attacker reset the password and logged in, locking out the owner.
- Two-factor authentication as the only backstop. Meta's letter and the hackers' own statements agree that accounts with two-factor authentication were not taken over by this method.
Impact
- Accounts: 20,225 people affected, according to Meta's filing with the Maine Attorney General, 30 of them Maine residents. Before the filing, TechCrunch said the total was unclear.
- Data: Help Net Security and Cybernews report that Meta's letter says contact information, dates of birth, posts, messages, account activity, profile information and linked services could have been accessible through a hijacked account.
- Response: according to Cybernews, Meta disabled the affected support system, invalidated existing password reset links, told users to reset passwords through secure channels and committed to fixing the "authentication check to make sure email addresses are properly verified" and to "a comprehensive review of similar account recovery flows across Meta's platforms."
- Victims: 404 Media reported that affected users said they had no route to a human support agent after losing their accounts.
What this means for identity security
This was a human identity breach carried out through an AI agent. The victims were ordinary account holders, but the actor that handed over their accounts was Meta's own support assistant. It had authority to change how an account is recovered, and it used that authority because someone asked it to in plain language. The underlying flaw, as Meta describes it, is an old one: a recovery flow that sends a reset to a channel the requester supplies instead of the channel on record. What changed is that a fast, always-available conversational agent designed to be helpful sat in front of it.
The key point for anyone deploying AI agents is where the trust decision lives. A language model can collect information and explain options, but deciding whether a person owns an account must be enforced by deterministic code and policy outside the model, with the agent unable to override it. Adding a new recovery email or phone number is a credential change, as sensitive as setting a password, and it should need proof from an existing factor, not a claim in a chat. Our AI Agent Authorisation Guide covers how to scope what an agent may do on a user's behalf.
The incident also sits in a line with help-desk social engineering against people, such as the MGM Resorts breach, where attackers talked support staff into resetting access. Replacing human agents with an AI agent did not remove that risk. It removed the human hesitation, and 404 Media's reporting suggests it also removed the human escalation path that victims needed afterwards. Location signals, which a VPN can spoof, are a risk signal, not an ownership check.
Recommendations
- Keep ownership decisions out of the model. Enforce account recovery rules in deterministic back-end checks that the AI agent calls but cannot bypass, as set out in the Agentic AI Security Guide.
- Treat recovery channel changes as credential changes. Require proof from an existing verified factor before adding a new email or phone number, and send reset links only to channels already on record.
- Give support agents least privilege. Separate read-only help from actions that change credentials, and route those actions through step-up verification or human approval.
- Push customers towards strong authentication. Two-factor authentication stopped this attack; passkeys and phishing-resistant factors go further. The CIAM Guide and Passwordless and Passkeys Guide explain the options.
- Monitor agent actions as privileged activity. Log every credential or recovery change an agent makes and alert on spikes, repeated requests for high-value accounts and new channels that do not match past account data.
- Red-team agents before launch. Test whether a plain request can make the agent change ownership details, following the Red Teaming AI Agents for Identity Abuse guide.
Frequently asked questions
How were Instagram accounts hacked through Meta AI?
Attackers used a VPN to appear near the victim, started the account recovery flow and asked Meta's AI support assistant to link a new email address to the account. The assistant sent a reset code or link to that address, which let them change the password and take over accounts that did not have two-factor authentication.
How many Instagram accounts were affected by the Meta AI support flaw?
Meta's breach notification filed with the Maine Attorney General lists 20,225 affected people in total, 30 of them Maine residents. The filing gives 17 April 2026 as the date the breach occurred and 31 May 2026 as the date it was discovered.
Did two-factor authentication protect Instagram accounts?
Yes. Meta's letter says the attacker could log in after resetting the password only if the account holder had not enabled two-factor authentication, and the hackers themselves said the exploit did not work against accounts with it enabled.
Related NHI Mgmt Group resources
EchoLeak 2025 · ForcedLeak 2025 · McDonald's McHire chatbot exposure · Top 10 Agentic AI Identity Issues · Human vs Non-Human Identity
How NHI Mgmt Group can help
AI agents that can reset passwords or change account details are privileged identities in their own right, and they need scoped permissions, enforced policy and monitoring like any other non-human identity. Our NHI Foundation Level Training Course helps teams govern AI agents and other non-human identities alongside the human accounts they act for.
References
- Maine Attorney General: Data Breach Notification, Meta Platforms, Inc. (8 June 2026)
- Meta: Boosting Your Support and Safety on Meta's Apps With AI (19 March 2026)
- TechCrunch: Hackers hijacked Instagram accounts by tricking Meta AI support chatbot into granting access (1 June 2026)
- TechCrunch: Instagram is alerting users who were targeted by hackers during AI chatbot attacks (3 June 2026)
- KrebsOnSecurity: Hackers Used Meta's AI Support Bot to Seize Instagram Accounts (1 June 2026)
- 404 Media: Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked (1 June 2026)
- Help Net Security: Hackers used Meta's AI support system to hijack over 20,000 Instagram accounts (8 June 2026)
- Cybernews: Meta admits Instagram recovery flaw enabled 20,000 account takeovers (8 June 2026)