惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
P
Proofpoint News Feed
宝玉的分享
宝玉的分享
人人都是产品经理
人人都是产品经理
博客园_首页
爱范儿
爱范儿
博客园 - 叶小钗
aimingoo的专栏
aimingoo的专栏
S
SegmentFault 最新的问题
MyScale Blog
MyScale Blog
阮一峰的网络日志
阮一峰的网络日志
IT之家
IT之家
Microsoft Security Blog
Microsoft Security Blog
Blog — PlanetScale
Blog — PlanetScale
博客园 - 【当耐特】
Y
Y Combinator Blog
量子位
博客园 - 三生石上(FineUI控件)
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
T
The Blog of Author Tim Ferriss
月光博客
月光博客
有赞技术团队
有赞技术团队
Apple Machine Learning Research
Apple Machine Learning Research
A
About on SuperTechFans

Hackread – Cybersecurity News, Data Breaches, AI and More

Suspected Cyberattack Sends Fake Emergency Alert to Phones Across Brazil Operation Endgame Disrupts StealC, Amadey and SocGholish Malware Networks New GhostShell Hacking Group Targets Ukraine’s Drone Defense Sector Fake npm Packages Impersonate PostCSS Tool to Steal Chrome Passwords Best Crypto Payment Solutions for E-Commerce Businesses Internet Society Foundation Opens Global Call for Common Good Cyber Fund to Strengthen Cybersecurity LastPass Confirms Customer Data Breach After Klue OAuth Token Theft ‘Cordyceps’ CI/CD Flaw Exposes Microsoft, Google, Apache Repos to Pipeline Hijacking The Rise of AI-Powered Academic Fraud: Beyond Traditional Plagiarism New CryptoBandits Malware Uses USB Drives and Tor to Steal Crypto The Evolution of iGaming Fraud: What Security Teams Should Expect in 2027 2 Scattered Spider-Linked Hackers Plead Guilty Over £39M TfL Cyberattack Beats Studio Buds Flaw Could Let Nearby Attackers Eavesdrop on Users Texas Parks and Wildlife Data Breach Affects Over 3M License Customers Threat Hunting Beyond Alerts: Finding the Activity Detection Misses Scammers Use Fake GitHub Stars, VirusTotal Reviews to Spread Crypto Clipper Salesforce Disables Klue Integration After OAuth Token Theft Hits Customer Data MDR Provider Comparison: Time to Discover and Respond to Threats Meteor 3.0 Migration Helped Rocket.Chat Move Off End-of-Life Node.js Runtime Gcore Helps Ucom Safeguard Public Live Broadcast Infrastructure During Armenia’s Parliamentary Elections Nintendo America Employee Data Exposed After Shadowbyt3$ Targets TinyPulse eFAQ Publishes Investigation Into Alleged Scam Activity and Coordinated Reputation Attacks FIFA World Cup 2026: Hackers Target Football Fans With Fake Tickets Sites MacBook Neo vs Windows Laptops for Cybersecurity Tasks Operation Endgame Disrupts SocGholish Malware Infrastructure What Businesses Should Know Before Migrating Their CMS DragonForce Ransomware Abused Microsoft Teams to Hide Malware Activity Agentjacking: Researchers Show How One Fake Bug Report Can Hijack AI Coding Agents FortiBleed Attack Exposes Fortinet Firewall Credentials in 194 Countries SpyCloud Report Finds Phishing Attacks Surge as Employee Data Is Exposed at 86% of Fortune 100 Companies
Instagram Recovery Tool Bug Exposed 20,225 Accounts to Pa...
Waqas · 2026-06-08 · via Hackread – Cybersecurity News, Data Breaches, AI and More

Meta has disclosed a security incident involving an Instagram account recovery tool after attackers used a flaw to send password reset links to email addresses that were not connected to the targeted accounts.

According to a data breach notice filed with the Maine Attorney General’s Office, Meta Platforms said the issue affected 20,225 people in total, including 30 Maine residents. The incident occurred on April 17, 2026, and was discovered by Meta on May 31, 2026.

The problem involved Instagram’s “High Touch Support” system, an AI-assisted account recovery tool built to help users regain access when locked out of their accounts. As part of that process, users could request a password reset link by providing an email address.

Meta said the support tool itself functioned as designed, but a bug in a separate code path caused a serious validation failure. The system did not properly confirm that the email address entered during the recovery process matched the email address already linked to the Instagram account.

Because of that error, an unauthorized person could request a password reset for someone else’s Instagram account and have the reset link sent to an email address they controlled. If the targeted account did not have two-factor authentication enabled, the attacker could reset the password and access the account.

Meta said it is not aware of exactly what personal information was viewed. Still, the company listed several categories of account data that may have been accessible, including email addresses, phone numbers, dates of birth, profile information, posts, photos, videos, stories, direct messages, account activity, interaction history, and connected accounts or linked services.

The 30 Maine users identified in the filing were described as people whose passwords were reset through the support tool, who did not have two-factor authentication enabled, and whose Instagram accounts were likely accessed by an unauthorized party. Meta also said that the number is an upper limit because some of the account activity may have been carried out by legitimate account owners.

After finding the flaw, Meta said it disabled the AI-assisted support tool on the same day and invalidated all existing password reset links generated through the vulnerable path. The company also placed affected accounts behind a mandatory security checkpoint, requiring users to authenticate before regaining access.

Meta also said impacted users are being instructed to reset their passwords and re-authenticate through secure channels. The company also plans to notify affected users electronically on June 19, 2026, and recommend that they review account security settings and turn on two-factor authentication.

Before the tool is brought back, Meta said it will fix the authentication check in the Instagram recovery flow so that password reset requests are verified against existing account information. The company also said it is reviewing similar recovery flows on Meta platforms to look for related issues.

A Pattern Worth Watching

The Maine filing gives May 31, 2026, as the date Meta discovered the Instagram recovery tool vulnerability. Yet the disclosure arrives during a difficult week for Instagram’s account recovery systems.

On June 1, hackers abused Meta’s AI support bot to hijack major Instagram accounts, including the archived Barack Obama White House account, Sephora, and John Bentivegna, the Chief Master Sergeant of the U.S. Space Force. Those reports described attackers using Meta’s support automation to push through account recovery requests on accounts they did not own.

A few days later, another password reset problem was reported. On June 6, an Instagram glitch exposed full contact details for high-profile users through the password reset flow, including email addresses and a phone number linked to Meta CEO Mark Zuckerberg.

Instagram Glitch Exposes Zuckerberg’s Contact Info and Other Top Users’ Details
Images circulating on social media

Meta’s Maine notice does not say these later reports were part of the same incident. The filing is limited to the AI-assisted High Touch Support recovery tool and the 20,225 users whose accounts may have been affected through that path.

Nevertheless, Instagram users concerned about account security should review recent login activity, remove unfamiliar linked accounts, update their password, and enable two-factor authentication using an authenticator app or security key where available.