- A bug in the support chatbot made it easy to change associated emails without real validation.
- More than 20.000 users have fallen victim to this flaw, particularly affecting profiles with short, high-value names.
- The attackers used artificial intelligence tools and VPN networks to bypass standard security measures.
- The company has temporarily disabled the affected service while it implements more robust verification systems.
It seems that technological advances sometimes play tricks on us, and this time it's Mark Zuckerberg's company that has suffered. What was initially designed as an AI-based assistant to make life easier for Instagram users has ended up being the Trojan horse that has allowed an account theft on a rather worrying scale.
The problem has come to the forefront after it was revealed that thousands of people lost access to their profiles overnight, leaving many stunned to find their photos and contacts in the hands of strangers. This incident reignites the age-old debate about whether we are automating overly critical functions without having under control all the possible holes that cybercriminals are eager to find.
How did this leak occur in the Meta system?
It all started with the implementation of a new support system, internally called High Touch Support, intended to expedite account recovery through an intelligent chatbot. However, attackers discovered that this assistant was overly confident and allowed modification the recovery email just by asking for it, without carrying out the identity checks that any of us would expect from a company of this caliber.
To make matters even more complicated, the criminals didn't need to be computer geniuses, as the method spread like wildfire through Telegram channels. Using VPN connections to pretend they were in the same city that the victim, they managed to get Meta's AI to lower its guard and hand over the profile keys in a matter of minutes, even skipping two-step verification in many cases.
The most disturbing aspect of the matter is that, according to several security analysts, the system accepted identity verifications that were utterly botched. The use of... has even been documented. AI-generated videos designed to deceive to the platform's own facial recognition systems, demonstrating that Instagram's defense technology was unable to distinguish between a real human and a well-made synthetic montage.
Massive impact: from anonymous users to high-level profiles
Although any user could be a potential victim, hackers focused particularly on so-called "OG handles," which are simply very short or coveted usernames that They have a very high market value black market. These accounts were resold within hours through specialized forums, leaving the original owners with no possibility of reclaiming what was theirs.
But it didn't stop there, as figures like Barack Obama and major brands like Sephora also saw their profiles used to publish strange content or propaganda. In total, it is estimated that More than 20.000 people have seen affected by this bug, a number that has forced Meta to submit reports to the security authorities of several territories, including Europe and the United States.
In the specific case of Spain and the rest of the continent, concern is at its highest due to strict data protection regulations. The attackers not only stole the account, but also... They could access direct messages, contact details and dates of birth, which represents a privacy breach of considerable dimensions that could have repercussions in the form of administrative sanctions.

Andy Stone, from the company, has stated that the problem has already been patched and that they are working tirelessly to secure the affected accounts. As an emergency measure, they have The virtual assistant has been completely deactivated. support and all password reset links that were suspiciously generated during the weeks the attack lasted have been disabled.
Now, affected users have no choice but to be patient and go through a rather tedious manual verification process to recover their digital identity. This incident reminds us that, however modern a tool may be, We must never let our guard down and that it is essential to have external authentication methods, such as back up Instagramto prevent a simple bot from ruining our day and taking our digital memories with it.
This security breach that has jeopardized Meta demonstrates that the automation of critical support processes still has significant gaps in identity verification. With over twenty thousand accounts compromised and the use of deceptive techniques based on VPNs and synthetic videos, it is clear that The industry needs to rethink its protocols. before leaving security decisions solely in the hands of artificial intelligence. For now, the smart assistance service remains inactive while the company thoroughly reviews its systems on Facebook, WhatsApp, and its other platforms to prevent a similar blunder from happening again in the future.


