
Global technology giant Meta said a vulnerability in its AI-assisted account recovery tool for Instagram enabled third parties to hijack more than 20,000 accounts and view users’ personal information.
Meta announced the data breach in a security incident notification filed with the Office of the Attorney General of Maine, stating that hackers exploited a vulnerability in High Touch Support, an AI-assisted support tool that enables users locked out of their Instagram accounts to reset their passwords.
According to the technology giant which owns major technology platforms like Facebook, Instagram, WhatsApp, Messenger and Threads, hackers communicated with HTS and requested the AI-enabled support tool to send password reset links for approximately 20,225 Instagram accounts via email.
HTS is configured to send password reset links to email addresses associated with respective Instagram accounts. However, in this instance, a vulnerability in a separate code path prevented the tool from verifying if the email address provided by the hackers matched the email addresses associated with the Instagram accounts for which the requests were placed.
"As a result, when an individual provided an email address not previously associated with the account, the system incorrectly sent a password reset link to that unassociated email rather than rejecting the request," Meta said. "This allowed unauthorised third parties to receive a password reset link for accounts they did not own. Upon resetting the password, the unauthorised party was able to log in to the account if the account holder had not enabled two-factor authentication (2FA)."
Meta said the vulnerability enabled the hackers to log in to the Instagram accounts of more than 20,000 users and view their personal information that included email addresses, phone numbers, dates of birth, profile photos, profile bios, Instagram posts and content, account activity, direct messages and communication, and information about connected accounts and linked services.
Meta said it discovered the vulnerability on 31st May, 2026, and immediately disabled the AI-assisted support tool to prevent further exploitation and invalidated all existing password reset links that had been generated through the vulnerable path. This ensured that the hackers could no longer use the password reset links obtained via email to log in to victims’ Instagram accounts.
The company added that it has instructed all impacted users to reset their passwords and re-authenticate through secure and verified channels. It also enrolled all affected Instagram accounts into a "mandatory security checkpoint requiring authentication before any account access, preventing any continued unauthorised access to users’ accounts."
"Prior to re-launching the tool, Meta will fix the authentication check in the Instagram recovery entry point to ensure proper verification of email addresses against existing account information before any password reset is initiated," Meta said.
"Additionally, Meta is conducting a comprehensive review of similar account recovery flows across Meta’s platforms to identify and remediate any potential issues," it added.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543