Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Anthropic Expands Claude Mythos AI Preview to 1 Project Glasswing
June 2, 2026
Critical KMW CCTV Flaw Lets Attackers Vulnerability Gain
June 2, 2026
Researcher Claims Microsoft MSRC Dismissed Dependency Confusion
June 2, 2026
Home/CyberSecurity News/Instagram Meta AI Flaw Allegedly Allows Account Password Res
CyberSecurity News

Instagram Meta AI Flaw Allegedly Allows Account Password Res

A critical flaw within Meta’s AI-powered account recovery tool on Instagram enabled attackers to hijack high-value accounts, leveraging the chatbot to forward password reset codes without requiring...

David kimber
David kimber
June 1, 2026 3 Min Read
7 0

A critical flaw within Meta’s AI-powered account recovery tool on Instagram enabled attackers to hijack high-value accounts, leveraging the chatbot to forward password reset codes without requiring verification.

Security researchers ZachXBT and Dark Web Informer were among the first to publicly expose the vulnerability, revealing that threat actors had found a way to manipulate Instagram’s Meta AI assistant a tool designed to help users recover access to their accounts.

Attackers engaged the AI chatbot in conversation and prompted it to forward password reset codes to unauthorized parties, entirely bypassing identity verification checks. The flaw stemmed from insufficient controls in how the AI processed account recovery requests, effectively allowing anyone who knew a target’s username to initiate the takeover process.

The exploit was not a traditional server breach Meta confirmed no backend systems were compromised. Instead, the vulnerability lived in the AI’s logic layer, which lacked proper rate-limiting or authentication enforcement before acting on reset requests.

High-Value Instagram Accounts Targeted

Attackers deliberately targeted premium, short-handle Instagram accounts, including high-profile usernames such as @hey and @jowo — known in underground markets for their resale value.

🚨 Instagram had an exploit that allowed you to use Meta AI to reset passwords to accounts with no MFA on them. The exploit was patched a short time ago.pic.twitter.com/PEUwLvmllj

— Dark Web Informer (@DarkWebInformer) June 1, 2026

These coveted accounts, some valued at over $1 million combined, were quickly flipped through private Telegram channels before Meta could intervene. The speed of the operation highlighted how organized and financially motivated threat actors have become in exploiting social media platform vulnerabilities.

Dark Web Informer confirmed the sales activity, tracking stolen account listings circulating across Telegram groups in real time — a tactic increasingly common in the account-takeover-as-a-service ecosystem.

Meta moved to patch the vulnerability late Friday after reports surfaced online. In an official statement, the company said: “We fixed an issue that allowed an external party to request password reset emails for some Instagram users. There was no breach of our systems and people’s Instagram accounts remain secure.

We fixed an issue that let an external party request password reset emails for some people. There was no breach of our systems and your Instagram accounts are secure.

You can ignore those emails — sorry for any confusion.

— Instagram (@instagram) January 11, 2026

Despite the patch, the incident raised serious questions about the security architecture surrounding AI-assisted support tools and their access to sensitive account recovery functions.

How to Protect Your Instagram Account

Accounts protected by two-factor authentication (2FA) were not compromised during this attack. Security experts now strongly recommend the following steps:

  • Enable app-based 2FA (e.g., Google Authenticator or Authy) instead of SMS-based verification.
  • Use a private, dedicated email not publicly associated with your Instagram profile.
  • Avoid reusing passwords across platforms; use a reputable password manager.
  • Regularly review login activity under Instagram’s Security Settings.
  • Store backup codes securely in case of emergency account recovery.

Meta’s hasty patch underscores a growing concern: as AI tools gain deeper access to account management functions, their vulnerability to social engineering becomes a critical attack surface that demands far stricter safeguards.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachExploitPatchSecurityThreatVulnerability

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Windows Netlogon RCE Vulnerability Actively Exploited

Next Post

Microsoft Won’t Sue Security Researchers After Nightmare-Eclipse

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Mustang Panda Deploys PlugX RAT via LNK Through Multi-Stage
June 2, 2026
SolyxImmortal Python Malware Steals Browser Data Passwords Cookies
June 2, 2026
Claude AI Down Globally: Users Report Widespread Service Issues
June 2, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us