Skip to main content
LiMP VPN
All news

Meta AI Hijacked 20,000 Instagram Accounts in 2026

Meta AI Hijacked 20,000 Instagram Accounts in 2026

In short: Between April and May 2026, Meta's AI-powered High Touch Support (HTS) tool for Instagram allowed attackers to hijack accounts using only a username. More than 20,000 accounts were at risk — including those of government organisations and celebrities. Every account with two-factor authentication enabled survived intact. In August 2026, at DEF CON, Meta received the Pwnie Award for the "Most Epic Fail" in security.

How AI support became a hacking tool

In March 2026, Meta launched an updated AI-powered support system for Instagram — High Touch Support (HTS). Designed to automate account recovery and email changes without a human operator, it looked like a convenience improvement. In practice, it became one of the platform's largest security vulnerabilities of 2026.

The critical flaw was simple: the system did not verify whether the email address provided by the requester matched the email actually linked to the target account. An attacker needed only to give the bot a victim's username and supply their own email — HTS would send a genuine password reset link to that address. After clicking the link, the attacker changed the password and gained full control of the page.

According to researchers, attacks began on approximately April 17, 2026, but the vulnerability was not discovered until May 31 — nearly six weeks later. During that window, over 20,000 accounts were potentially compromised. Stolen profiles were immediately listed for sale in private Telegram channels specialising in rare usernames: short, desirable handles like @hey or @jowo fetch anywhere from thousands to hundreds of thousands of dollars on underground markets.

Who was affected: from ordinary users to the White House

The scheme worked against any account without two-factor authentication — regardless of how prominent. Notable victims included:

  • The historical White House account from the Obama administration era
  • The page of US Army Master Sergeant John Bentivegna
  • The corporate account of beauty retailer Sephora

For each compromised account, the potentially exposed data included contacts, linked email addresses and phone numbers, private messages, photos and videos, and all profile information. Meta was forced to place potentially affected accounts into mandatory verification mode and invalidated all password reset links that HTS had generated during the attack period.

Attack technique: AI as an unwitting accomplice

The attack required no hacking tools or technical skills. The flow:

  1. The attacker opened a chat with Instagram's AI support bot.
  2. Named the target account's username and claimed it as their own.
  3. Requested an email change, supplying their own email address.
  4. HTS, without performing verification, sent a password reset link to the attacker's email.
  5. The attacker clicked the link and gained full control of the account.

To pass additional geo-checks, attackers used proxy services and IP-masking tools so their requests appeared to originate from the victim's region. Only one mechanism reliably protected accounts: enabled two-factor authentication — not a single account with 2FA active was compromised. For a complete guide to locking down your accounts, see our article on how to protect your account from takeover.

Pwnie Awards 2026: Meta's security failure goes official

In August 2026, at the annual DEF CON conference, Meta received a Pwnie Award — the informal "anti-prize" of the cybersecurity world — in the "Most Epic Fail" category. The security community identified two core problems:

  • An AI system granted control over account access had no basic data verification from day one.
  • The vulnerability was exploited for almost six weeks before discovery — meaning anomaly monitoring was also inadequate.

The incident established a new threat class: AI support systems as an attack vector. Strong passwords and unique email addresses offer no protection when the service itself issues a password reset link to unauthorised parties. An attacker does not need to breach a database or trick a user — they just need to say the right words to the chatbot.

How to protect your Instagram account right now

The HTS vulnerability has been patched, but the threat class will persist — other services are also deploying AI support, and some may repeat the same mistake. Security experts recommend:

  • Enable 2FA immediately. This was the only measure that guaranteed protection in this incident. In Instagram: Settings → Accounts Centre → Password and Security → Two-Factor Authentication. Use an authenticator app rather than SMS — SMS codes are vulnerable to SIM-swap attacks.
  • Verify your linked email. It should be current and protected with its own 2FA.
  • Enable login alerts. Instagram notifies you of every new sign-in, helping you spot a breach quickly.
  • Use a password manager. A unique strong password per service means one compromised account cannot cascade into others.
  • Encrypt your traffic on public networks. When logging into social media over public Wi-Fi, session cookies can be intercepted at the network level. LiMP VPN encrypts your connection and keeps your session data invisible to others on the same network.

Sources

Meta AI Hijacked 20,000 Instagram Accounts in 2026