Particle.news

Instagram Bug Sent Password Resets to Attacker Emails and Compromised 20,225 Accounts

A coding error in Instagram’s AI High Touch Support sent password-reset links to attacker-controlled emails, prompting account lockdowns and regulatory notices.

Overview

  • Meta says the exploit likely began in mid‑April and the company discovered the issue at the end of May before disclosing that roughly 20,225 Instagram accounts were potentially affected on June 7.
  • A bug in a separate code path allowed the AI-driven High Touch Support recovery flow to accept an attacker-supplied email and send a password-reset link without verifying it matched the account’s registered address.
  • Meta disabled the High Touch Support flow, invalidated all reset links created through the vulnerable path, and placed impacted accounts behind mandatory security checks.
  • The company warns that exposed data could include contact information, birth dates, messages, posts, profile details and linked accounts, and reports say multi-factor authentication blocked many takeover attempts.
  • Multiple law firms have opened class-action investigations and regulators have been notified, and the incident has renewed questions about giving AI systems direct authority over account recovery processes.