Meta confirms 20,000+ Instagram accounts hacked via AI chatbot bug
Meta disclosed that a bug in its AI-assisted Instagram account recovery chatbot allowed hackers to hijack over 20,000 accounts by requesting password resets be sent to attacker-controlled email addresses. The flaw, active from mid-April until this week, bypassed verification of the account holder’s email, letting attackers take over profiles, messages, and linked data. Meta has disabled the chatbot, removed the vulnerable code path, and is forcing affected users to reset their passwords.