logoalt Hacker News

Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

377 pointsby speckxyesterday at 6:35 PM140 commentsview on HN

Comments

Cyan488yesterday at 7:10 PM

> "The tool itself worked properly and functioned as intended; however due to a bug in a separate code path, the system did not properly verify that the email address provided by the individual requesting a password reset matched the email address associated with that user’s Instagram account," said Meta in its breach notice.

I'm not sure "worked properly" and "as intended" accurately describe this situation.

show 20 replies
johnyzeeyesterday at 9:57 PM

"Meta notified at least 20,225 people that their accounts had been compromised. [...]

The compromises allowed the hackers to take over the person's entire Instagram and any linked accounts, including obtaining contact information, dates of birth, and profile information, as well as the ability to access the person's posts, direct messages, and account activity [...]

the hacks began around April 17 and lasted until this week [...]"

This is staggering.

show 4 replies
webbdevyesterday at 8:22 PM

Meanwhile an account I created for a new product was permanently disabled by an automated system with no path for me to appeal to a human.

(If anyone at Meta/Instagram sees this I wrote a brief blog post with the details. Please help! https://addisonwebb.com/blog/2026-06-05-Can%20Someone%20at%2... )

show 7 replies
hero4hiretoday at 12:31 AM

People were reporting their accounts were being taken over with proper 2fa. Everyone had wondered how they hackers could take over accounts with little information, people were saying "inside job."

This is exactly the stupid explanation I expected. Your privacy and security. Meta. Serious Business.

loloquwowndueoyesterday at 7:13 PM

This was on hacker news a few days ago (https://news.ycombinator.com/item?id=48359102) - description of the “hack”, not the cockamamie confirmation by Meta.

dwa3592yesterday at 8:49 PM

I really hope this accelerates meta's decline. The world will adapt just fine without social media.

show 3 replies
Havocyesterday at 8:26 PM

>AI-assisted account recovery system

oh no...Meta what are you doing

show 2 replies
phyzomeyesterday at 8:12 PM

Corrected headline: "Meta confirms 1000s of Instagram accounts were hacked due to their insecure AI chatbot".

show 1 reply
jhhhyesterday at 8:15 PM

Why was 'can a user request a different email' not literally the first test that comes to mind when making something like this? Do they not test anything because the scale is too big?

show 4 replies
RgrTheShrubbryesterday at 11:43 PM

The AI passed the Turing Test by becoming the world's most trusting customer service rep.

dansquizsoftyesterday at 10:07 PM

You only have to look at both the ridiculiously terrible "Q&A chatbot" that is in FaceBook under some posts (do they still have this?) and the fact that their system can't tell the difference between an inappropriate and a non-inappropriate comment most of the time to understand just how far behind Meta is in AI...

whirlwinyesterday at 8:35 PM

I got a suspicious password reset request email today from Meta but it landed in my inbox. Luckily I have MFA and after checking audit logs inside IG upon logging in, I did not see anything suspicious.

show 1 reply
zahirbmirzayesterday at 8:39 PM

And who said cameras linked to Meta in their glasses were a good idea?

tomashertusyesterday at 11:20 PM

Move fast and break things.

smrtinsertyesterday at 11:30 PM

How do business owners hire people from Meta knowing these types of "bugs" get deployed with a shrug? Meta will survive them. Their business might not.

alvisyesterday at 10:28 PM

how on earth a password reset API would take both email address and account id as parameters? The chat bot is fine. I bet it's the API written by AI the issue

cyanydeezyesterday at 8:07 PM

"abusing" by using it's built in insecurity to do insecure things.

It's like, people abusing an open door. "Guys, just because we left the door open to your bedroom doesn't mean we're responsible".

God can only hope this is a business ending lawsuit.

show 2 replies
rvzyesterday at 7:44 PM

If this was a bank that had zero humans and the AI chatbot was abused to hand over sensitive information about their customers which led to this disaster, people would never trust their bank ever again and leave.

Meta believes that they can vibe-code their reputation down the drain by removing humans in the loop.

Applying a technical solution to a social problem almost always ends in disasters like this.

Reputation can’t be vibe-coded.

show 1 reply
Liongayesterday at 11:07 PM

Just AI Slop doing AI Slop things

plucyesterday at 8:58 PM

By "abusing" they mean "using"

show 1 reply
Fairburnyesterday at 10:08 PM

Are we winning yet?

_RPMyesterday at 8:28 PM

Probably some product manager pushed back on security considerations raised by engineers.

empireeyesterday at 10:28 PM

Yet another reminder that most of these chatbots get shipped way before they're ready. Loud marketing, security treated as an afterthought, all to ride the AI hype. LLMs open up a whole new attack surface and a lot of teams still treat prompt injection like a fun edge case. This is what happens when you ship the demo instead of the product.

paulpauperyesterday at 10:23 PM

Imagine how much $ ppl could have made hijacking famous accounts to promote crypto or other crap. I wonder how often this happened.