securityonline.info 6/8/2026, 8:57:57 AM · external

Instagram recovery bug lets attackers hijack 20k accounts

Instagram recovery bug lets attackers hijack 20k accounts

META has reported a serious security flaw in Instagram's account recovery system, allowing unauthorized access to user accounts. The vulnerability stemmed from a logic error in the High Touch Support AI tool, which failed to properly verify email addresses during password resets. As a result, 20,225 Instagram accounts were compromised. Following the incident, Meta promptly disabled the AI support feature and invalidated all active reset links. The company is implementing stronger validation checks for the tool and recommending users enable two-factor authentication to enhance security.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline