More than 20,000 Instagram accounts were hijacked after attackers found a way to abuse Meta’s internal AI-powered account recovery system. The tool, called High Touch Support (HTS), was supposed to help users get back into locked accounts. Instead, it handed the keys to criminals.
How It Worked
Meta’s HTS system — an AI-assisted tool used to process account recovery requests — had a critical design flaw. It didn’t verify whether the email addresses submitted were actually linked to the accounts being targeted. Attackers exploited this gap to request password reset links for accounts they didn’t own. The reset emails went to addresses the attackers controlled.
From there, they bypassed two-factor authentication entirely. No need to crack codes or intercept SMS messages — the reset flow just let them in. The first known attack happened on April 17, 2026, but Meta didn’t catch it until May 31 — over six weeks of unchecked access.
What Got Exposed
Once inside, attackers had full visibility into compromised accounts. That includes email addresses, phone numbers, dates of birth, all posts, photos, videos, direct messages, profile information, and any linked accounts. For influencers, business accounts, and anyone who uses Instagram as a primary channel, this is about as bad as it gets.
Meta confirmed the breach in a filing with Maine’s Office of the Attorney General. Andy Stone, Meta’s VP of Communications, said the “issue has been resolved” and that the company disabled HTS, invalidated all pending password reset links, and added mandatory security checkpoints for affected accounts.
The Bigger Problem
This isn’t a sophisticated zero-day exploit. It’s a basic authentication logic error — the kind of check that should have been caught in a code review. The fact that an AI-powered support tool could be weaponized at scale without verifying something as fundamental as email-account linkage is a serious oversight.
Meta says it will fix the authentication check before relaunching HTS. But there’s no timeline for that, and no public post-mortem detailing how this made it into production. The company has form here: Ireland fined Meta $264 million over a 2018 Facebook data breach involving similar access token failures.
What You Should Do
If you’re an Instagram user — especially one with a business or creator account — check your login activity and connected email addresses right now. Change your password, make sure your recovery email is current, and enable app-based two-factor authentication rather than SMS. If anything looks unfamiliar, disconnect it. This breach may be “resolved” on Meta’s end, but the attackers had weeks of access. Assume anything in those compromised accounts could be copied.
What’s Next
Expect regulators to take interest, particularly given the delayed disclosure window and the scale of personal data involved. The Maine AG filing is likely just the start. More importantly, this incident should make every platform question whether their AI-assisted support tools have been properly audited for abuse. If the recovery flow is easier to exploit than the actual account security, you’ve built a backdoor — whether you meant to or not.
