Skip to content
The Coolest Info

The Coolest Info

  • Cronos blockchain bridge suffers attack with over $12 million in crypto lossesJuly 31, 2026
  • SEC Sues Mining Automatic and Founder Over Alleged $22M Crypto Mining SchemeJuly 20, 2026
  • AI-Generated Fake nVidia Employee LinkedIn Profiles Surface in Hiring ScamsJuly 20, 2026
  • The Download: OpenAI unveils GPT-Red and heat pumps rise in the USJuly 19, 2026
  • The Download: perimenopause misinformation and China’s latest AI leapJuly 19, 2026
  • A bug in AWS has caused some customers’ bills to spike from a few cents to billions of dollarsJuly 19, 2026
  • There’s now an API for mainlining Trump’s Truth Social postsJuly 19, 2026
  • France doubles down on restricting access to PolymarketJuly 19, 2026
  • I replaced my space heater and ceiling fan with one Dyson applianceJuly 19, 2026
  • A 600-mile road trip (and data) proves EV charging doesn’t suck anymoreJuly 19, 2026
  • Kimi: Threat or menace?July 19, 2026
  • Troubling new details emerge on diabetes ouster controversyJuly 19, 2026
  • Will AI fix prior authorization—or make it worse?July 19, 2026
  • Surprise! Facial recognition smart locks are actually goodJuly 19, 2026
  • Google is open-sourcing its 3D emojiJuly 19, 2026
  • Google might not kneecap the Pixel 11a with an old processorJuly 19, 2026
  • The future of physical games is not looking greatJuly 19, 2026
  • US Marshals arrest the Tate brothers in MiamiJuly 19, 2026
  • UK Sentences Two Scattered Spider Hackers Over 29 Million Transport for London AttackJuly 18, 2026
  • Coca-Cola Halts Fairlife US Dairy Production After Ransomware AttackJuly 18, 2026
  • OpenSSL HollowByte Flaw Lets 11-Byte Payload Freeze Server MemoryJuly 18, 2026
  • 7-Zip 26.02 Fixes Critical RCE Flaw Exploitable With Malicious ArchivesJuly 18, 2026
  • WordPress Core wp2shell RCE Flaws Get Public Exploits, Patch NowJuly 18, 2026
  • Microsoft Patches Record 570 Security Flaws in July 2026 Patch TuesdayJuly 18, 2026
  • OkoBot Malware Framework Targets Crypto Wallet Seed Phrases From Trezor and Ledger UsersJuly 18, 2026
  • News
  • Crypto Predictions
The Coolest Info

The Coolest Info

  • News
  • Crypto Predictions
  • Home
  • 2026
  • June
  • 8
  • Attackers Hijacked 20,000 Instagram Accounts Using Meta’s Own AI Support Tool
  • Security

Attackers Hijacked 20,000 Instagram Accounts Using Meta’s Own AI Support Tool

June 8, 2026June 11, 202603 mins

Over 20,000 Instagram accounts were hijacked after attackers figured out how to weaponize Meta’s AI-powered support system against its own users. The weapon of choice? A tool called High Touch Support (HTS) — designed to help locked-out users regain access to their accounts. Instead, it became the skeleton key that let attackers walk right in.

How the Attack Worked

Here’s the critical flaw: HTS didn’t properly verify whether an email address was actually associated with the Instagram account it was supposedly helping recover. Attackers exploited this gap to obtain password reset links for accounts they didn’t own. Once they had the link, they could reset the password, log in, and take full control — all without needing to touch the victim’s two-factor authentication.

The campaign started as far back as April 17, 2026, but Meta didn’t discover it until May 31. That’s a six-week window where attackers had free rein.

What Was Exposed

While Meta says it has no confirmed evidence of what data the attackers actually pulled, the potential exposure is significant. Anyone who got in could’ve accessed email addresses, phone numbers, dates of birth, entire post histories (photos, videos, stories), direct messages, profile information, and linked accounts. For some users, that’s essentially their entire digital life.

Meta disclosed the breach in a letter filed with Maine’s Office of the Attorney General, confirming 30 users in that jurisdiction alone were affected — though the global toll exceeds 20,000 accounts.

Meta’s Response

After user reports flooded social media, Meta VP of Communications Andy Stone responded that “the issue has been resolved and we are securing impacted accounts.” The company disabled the HTS tool entirely, invalidated all outstanding password reset links, and forced mandatory security checkpoints on every potentially compromised account.

Affected users had to reset their passwords again and re-authenticate from scratch. Before relaunching HTS, Meta says it’ll fix the authentication check to properly verify email addresses against account information — and it’s reviewing similar recovery flows across all its platforms.

The Bigger Pattern

This isn’t Meta’s first rodeo with security failures. Ireland previously fined the company $264 million over a 2018 Facebook data breach. And this incident highlights a growing concern: the security of AI-assisted support systems themselves. Companies are racing to deploy AI tools for customer service, but if those tools don’t have rigorous identity verification baked in, they become the weakest link in the chain.

What You Should Do Right Now

If you’re an Instagram user — and statistically, that’s most people reading this — take these steps now. Enable two-factor authentication using an authenticator app, not SMS. Make sure your recovery email is current and secured with its own 2FA. Check your account for unfamiliar login activity under Settings → Security → Login Activity. And be suspicious of any unexpected password reset emails, even if they look legit.

What’s Next

Meta says it’s auditing account recovery flows across all its platforms, which includes Facebook, WhatsApp, and Threads. That’s a good sign, but the real question is whether this kind of vulnerability exists in other companies’ AI support systems too. As more platforms roll out AI-assisted customer service, expect attackers to probe these tools for similar weaknesses. This won’t be the last time an account recovery system becomes an account takeover system.

Tagged: account hijacking AI security data-breach Instagram Meta

Post navigation

Previous: Trump’s AI Proposal Quietly Shifts the Playing Field Toward Anthropic
Next: 19,000 FIFA-Themed Domains and Counting: The 2026 World Cup Is a Playground for Cybercriminals

Related News

Cronos blockchain bridge suffers attack with over $12 million in crypto losses

July 31, 2026July 31, 2026

SEC Sues Mining Automatic and Founder Over Alleged $22M Crypto Mining Scheme

July 20, 2026July 20, 2026

AI-Generated Fake nVidia Employee LinkedIn Profiles Surface in Hiring Scams

July 20, 2026July 20, 2026

The Download: OpenAI unveils GPT-Red and heat pumps rise in the US

July 19, 2026

Recent Posts

  • Why Is The Crypto Market Down Today?
  • Bitcoin faces key hurdle in $81,000-$86,000 range to reach January high, analyst says
  • South Korea’s Mirae Asset Charting $109 Billion Path Through Digital X Strategy Report
  • Core Lightning Issues Urgent Security Patch Following Discovery of Multiple Vulnerabilities
  • Bithumb Secures Legal Victory Over Mistaken Bitcoin Credits Following Massive Error

Recent Comments

No comments to show.

Archives

  • August 2026
  • July 2026
  • June 2026

Categories

  • Cross-Pillar
  • Cryptocurrency
  • Finance
  • Security
  • Security Advisories
  • Technology
  • Uncategorized
  • Crypto Predictions
Online Newspaper - News / Magazine WordPress Theme 2026.
Back To Top