- A flaw in the HTS recovery tool allowed emails to be changed without verifying the user's real identity.
- The number of affected profiles amounts to 34.000, including highly relevant accounts and highly sought-after usernames.
- The attackers used VPN networks to spoof the geolocation of Meta's support chatbot.
- The company has temporarily suspended the affected service while it strengthens its internal verification protocols.
It's no secret that technology is advancing by leaps and bounds, but sometimes it seems to move so fast that security is left behind. What has happened with Meta in recent days is astounding, because a tool designed to help It has ended up being the users' worst enemy due to a technical oversight.
Instagram has caused quite a stir, as a flaw in its AI-powered support system has allowed thousands of people to lose access to their accounts in the blink of an eye. The magnitude of the problem is such that has called into question the reliability of these automated processes that increasingly manage more aspects of our digital lives without us even noticing.
A logical fallacy that has cost Meta dearly

The epicenter of this disaster lies in the High Touch Support (HTS) system, a feature that uses AI to expedite the recovery of locked profiles. Apparently, a major bug in a separate code path was preventing the system from functioning. will correctly verify the email address provided by the person requesting the password change, allowing the entry of emails that had nothing to do with the original.
The cybercriminals quickly realized the trick and got to work during April and May. All they had to do was talk to the chatbot and convince it that they were the legitimate owners, which turned out to be... surprisingly easy due to the autonomy with which this artificial intelligence operated, which did not request the necessary identity checks at the critical moment.
To bypass geographical controls, the attackers used VPN connections, tricking the system into believing they were physically in the same location as the victims. With this trick, the AI suspected nothing amiss and I sent the recovery link directly to the hackers' email instead of protecting the original user, leaving the profile completely exposed in a matter of minutes.
From celebrity accounts to the black market for usernames
This isn't just a simple scare for a few unsuspecting users, as the list of those affected is quite impressive. It ranges from Barack Obama's old account to profiles of major security companies, No one has been safe from this vulnerability which has circulated like wildfire through Telegram channels specialized in the trafficking of digital identities.
The big problem is that many of these profiles have very short usernames or usernames associated with powerful brands, the so-called "OG handles," which are worth a fortune on the black market. It is estimated that some 3.500 accounts have changed their name immediately after the theft, which makes it extremely difficult for the original owners to recover the stolen goods. Recover your previous Instagram names automatically through the platform's usual channels.
Although it was initially thought that the problem affected around 20.000 people, new information from internal documents suggests that the figure is higher. It could reach more than 34.000 usersIn addition to losing control of the profile, the attackers would have had access to sensitive data such as phone numbers, dates of birth, and private messages, representing a privacy breach that will have repercussions for a long time.
Safety and security measures for users

Meta has already taken drastic measures by disabling the faulty tool and forcing password resets on affected profiles to try to mitigate the damage. However, this serves as a stark reminder that We can't rely entirely on AI And having two-step authentication (2FA) enabled through external applications is, nowadays, absolutely mandatory if we want to avoid being scammed.
What happened makes it clear that integrating critical security processes into automated systems carries logical risks that aren't always detected before it's too late. From now on, the wisest course of action is periodically review our access pointsBe wary of any strange messages about email changes and pay close attention to official notifications, because at the end of the day, the best barrier against these technological failures is our own caution and common sense when managing our social networks.


