Meta AI Recovery Flaw Hijacks Instagram Accounts
Coverage from BleepingComputer, Daily Hodl, and others

Meta disclosed that a validation flaw in Instagram's AI-assisted High Touch Support recovery system allowed unauthorized users to trigger password resets for accounts they did not control, potentially affecting up to 20,225 accounts.
Meta disabled the tool, invalidated reset links, and placed impacted accounts behind additional security checks, while the scope of accessed user data remains uncertain. The broader topic also includes a separate exposure of 17.5 million scraped Instagram records, highlighting risks from both account-recovery automation and large-scale collection of profile data.
The update mainly sharpens the framing of the Instagram recovery flaw while adding a separate, clearly distinct scraped-data incident. The new version also makes the mitigation steps more specific, including added security checks and re-authentication for impacted accounts.
The update adds a clearer technical cause and a more precise scale/timeline for the Instagram recovery abuse, while confirming the incident also triggered a Maine regulatory filing. It also reframes some related account-hijacking and data-scraping reports as broader context rather than confirmed parts of this breach.
