A support-focused artificial-intelligence chatbot used by Meta contained a security flaw that enabled attackers to take over other users' Instagram accounts. Exploiting the bug, attackers were able to change a profile's email address without accessing the original owner's mailbox, and subsequently reset the account password, thereby gaining full control of the targeted accounts.
Scale of the incident
According to Meta, the flaw was used to hijack 20,225 Instagram accounts. The company said that while the chatbot generally functioned as intended, it failed to verify that the email address provided by the person requesting a password reset actually matched the account owner's registered email.
Response and remediation
After an increasing number of complaint reports appeared online, Andy Stone, Meta's Vice President of Communications, replied to an affected user saying the issue had been fixed and that targeted accounts were being "secured." Bleeping Computer reports that this means unauthorized access was removed and profiles were returned to their rightful owners.
Potential risks
Meta noted it does not have definitive information about what personal data, if any, was accessed by unauthorized parties during the incident. However, the company warned that an attacker with full account access can view photos, personal information, and private messages, so the potential exposure could be significant.
Why this matters
The case highlights that authentication and input verification remain critical even for AI systems designed to assist with support tasks. A flaw in an automated system can put a large number of users at risk, underscoring the need for stricter security and verification protocols when deploying such tools.
Next steps
Meta has not provided detailed public information about internal fixes or further measures planned to prevent similar incidents in the future. The company is notifying affected users and taking steps to restore account security.



