Mark RadarMARK RADAR
EN

Hackers Exploit Meta AI Support Flaw to Steal Instagram Accounts

7 reports · First detected 2026-06-01 · Last active 2026-06-07

Meta introduced an AI customer-support assistant to help Instagram users recover their accounts, but hackers were able to combine prompt injection with a VPN to bypass identity checks and reset passwords. The incident shows that enterprise AI systems with account-management privileges can become a new avenue for taking over high-value accounts if they lack rigorous verification controls.

Meta recently confirmed that the vulnerability was exploited for about 1.5 months, resulting in the theft of more than 20,000 Instagram accounts. None of the victims had enabled two-factor authentication, or 2FA. Meta has not disclosed the exact dates when the vulnerability was active, the identities of the affected accounts or the amount of losses, and urged users to enable two-factor authentication immediately to reduce their risk.

All Coverage

7 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR