Meta has disclosed that more than 20,000 Instagram accounts were compromised in a significant security incident involving its AI-powered account recovery system.
Over 20,000 Instagram Accounts Hijacked in Meta AI Support System Breach

According to Meta, a total of 20,225 Instagram users had their accounts taken over after cybercriminals exploited a vulnerability in the company’s High Touch Support (HTS) platform. The AI-assisted support tool is designed to help users regain access to their accounts when they are locked out or experience login issues.
The incident was first highlighted by cybersecurity news outlet BleepingComputer, which reported that attackers discovered a flaw in the HTS system that allowed them to request password reset links for targeted Instagram accounts without properly verifying account ownership.
How the Attack Worked
Investigators found that the vulnerability stemmed from the support system’s failure to verify whether the email address submitted during the recovery process was actually associated with the targeted Instagram account.
By exploiting this weakness, attackers were able to obtain legitimate password reset links and gain unauthorized access to victim accounts. Once inside, cybercriminals could change account credentials, lock out the original owners, and potentially use the compromised profiles for scams, phishing campaigns, or other malicious activities.
The attack proved especially effective against accounts that did not have two-factor authentication (2FA) enabled. Accounts protected by 2FA had an additional layer of security that made unauthorized access significantly more difficult.
Meta Responds
Meta said it has since addressed the vulnerability and implemented additional safeguards to prevent similar attacks from occurring in the future. The company is also contacting affected users and encouraging all Instagram account holders to review their security settings.
Cybersecurity experts say the incident highlights the growing risks associated with AI-powered support systems. While automated tools can improve customer service efficiency, any weakness in identity verification processes can create opportunities for attackers to bypass traditional security measures.
Security Experts Urge Users to Enable 2FA
Following the breach, security professionals are advising Instagram users to immediately enable two-factor authentication, use strong and unique passwords, and regularly review account recovery settings.
Experts also recommend monitoring account activity for suspicious logins, unauthorized password changes, or unfamiliar email addresses linked to accounts.
Growing Concerns Over AI-Based Support Systems
The breach has sparked broader discussions within the cybersecurity community about the security challenges posed by AI-driven customer support platforms. As companies increasingly rely on automation to handle account recovery and user assistance, ensuring robust identity verification remains critical.
While Meta says the vulnerability has been fixed, the incident serves as a reminder that even advanced AI systems can introduce new attack surfaces if security controls are not properly implemented.
The company has not yet disclosed whether any personal user data beyond account access was exposed during the breach. Investigations into the full scope of the incident are ongoing.








