惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Blog — PlanetScale
Blog — PlanetScale
G
Google Developers Blog
Microsoft Security Blog
Microsoft Security Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
腾讯CDC
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Jina AI
Jina AI
雷峰网
雷峰网
T
Tailwind CSS Blog
爱范儿
爱范儿
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
酷 壳 – CoolShell
酷 壳 – CoolShell
大猫的无限游戏
大猫的无限游戏
月光博客
月光博客
博客园 - 司徒正美
I
InfoQ
Engineering at Meta
Engineering at Meta
Vercel News
Vercel News
小众软件
小众软件
U
Unit 42
Google DeepMind News
Google DeepMind News
D
DataBreaches.Net

Enterprise – Silicon Republic

Recovery readiness a missing link in cyber resilience, finds report EU finally gets its hands on Anthropic’s Mythos New Irish dispute body to tackle illegal online content launched Rhysida leaks 5.7TB of sensitive Berlin state data in major hack ‘Keeping OT security up to date is more than patching systems’ HSE fined €645,000 for storing records in decrepit conditions Boston Scientific cyberattack: Cork staff asked to work remotely Report: Only sectors aiding AI adoption sure to grow from it Why connectivity and cybersecurity can't be treated separately French authorities investigating hack of national tax authority Why employee retention is at the heart of the cyber skills gap Levi Strauss corporate data stolen in cyberattack Levi Strauss corporate data stolen in cyberattack How might a system ‘leak secrets’ without being hacked? What is a side-channel attack in cybersecurity? OpenAI agents breach Modal client system after Hugging Face hack OpenAI agents breach Modal client system after Hugging Face hack Report: EMEA businesses not reaping benefits from their AI spend Report: EMEA businesses not reaping benefits from their AI spend Transport for London hackers jailed for five and a half years Transport for London hackers jailed for five and a half years Commission refers Ireland to CJEU for failing to enact cyber rules Commission refers Ireland to CJEU for failing to enact cyber rules Cloudflare to block AI crawlers from ad-supported webpages by default Cloudflare to block AI crawlers from ad-supported webpages by default Google ordered to pay Klarna nearly $2bn in abuse-of-power row Google ordered to pay Klarna nearly $2bn in abuse-of-power row Upcoming iPhone 18 model leaked in Tata Electronics hack New iPhone 18 models reportedly leaked in Tata Electronics hack Data breaches going unreported – Irish compliance survey
More than 20,000 Instagram accounts hacked using Meta AI bug
Suhasini Srinivasaragavan · 2026-06-08 · via Enterprise – Silicon Republic

Contact information, direct messages and connected accounts were all potentially compromised, Meta said.

Hackers used Meta AI to hack into 20,225 Instagram accounts, Meta reported in a US local government data breach notice on 5 June.

According to the notice to the attorney general for Maine, the breach occurred on 17 April, but wasn’t discovered by the company until more than a month later, on 31 May.

The company explained that hackers exploited a now-resolved bug in its AI-assisted support tool designed to help Instagram users access their account after being locked out.

“HTS (high touch support) is an AI-assisted support tool designed to help users who are locked out of their Instagram accounts regain access,” said Amber Hannah, Meta’s associate general counsel for incident response.

“Users can request support from HTS and, as part of that process, can ask that a password reset link be sent to their email address.

“The tool itself worked properly and functioned as intended; however, due to a bug in a separate code path, the system did not properly verify that the email address provided by the individual requesting a password reset matched the email address associated with that user’s Instagram account.”

The bug allowed hackers to avoid triggering Instagram’s automated account protections, enabling password reset links to be sent to an email not connected to the account. Bad actors were then able to reset passwords to gain access to victims’ accounts if they did not have two-factor authentication enabled.

The hack affected prominent figures’ accounts, including the inactive Instagram handle for the Obama-era White House, beauty retailer Sephora and a senior US Space Force official.

Meta said that hackers could have potentially accessed sensitive data, including contact information, direct messages and communications, and connected accounts and linked services, such as email IDs. The company said that it would fix the bug before relaunching the AI tool.

In 2024, the Irish Data Protection Commission (DPC) fined Meta €251m for a 2018 data breach affecting approximately 29m Facebook accounts. The same year, the watchdog fined Meta €91m for improperly storing passwords.

In 2023, the company was fined €1.2bn by the DPC for violating GDPR guidelines by transferring users’ personal data outside of the EU.

AI-enabled cybercrime is fast becoming a sore point for companies, as attacks become more frequent and sophisticated. Just last month, hackers stole 8TB of data from the Taiwanese electronics manufacturer Foxconn, while medical equipment manufacturing giant Stryker was hit by a global cyberattack in March.

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.