Meta AI handed hackers the keys to 20,000+ Instagram accounts
Attackers opened a chat with Meta's AI support bot and talked it into resetting passwords on accounts they didn't own. Per Help Net Security, 20,225 accounts were taken over between April 17 and early June through a bug in Meta's "High Touch Support" recovery path that never verified the requester's email matched the account.
The community's verdict, per cybersecurity coverage on HN: nobody "broke in" โ this was an authorization failure, not a clever exploit. Reported victims included an Obama-era White House handle and a US Space Force chief master sergeant.