
Instagram AI chatbot breach may have affected over to 20,000 accounts, Meta discloses
Quick Answer
Meta disclosed that a security breach in its Instagram AI chatbot compromised at least 20,225 accounts.
Quick Take
For nearly seven weeks, the chatbot sent password reset links to random email addresses without verifying ownership, undermining its initial promise of enhanced account security.
Key Points
- Over 20,225 Instagram accounts were compromised due to the chatbot breach.
- The breach lasted for nearly seven weeks, affecting user account security.
- Password reset links were sent to arbitrary email addresses without verification.
- The AI chatbot was initially marketed as a security enhancement for accounts.
- Meta's disclosure marks the first time specific numbers have been revealed.
Source Excerpt
Meta has put a number on the security breach in its AI support chatbot for Instagram for the first time: at least 20,225 accounts were compromised. For nearly seven weeks, the system sent password reset links to arbitrary email addresses without verifying they belonged to the account. The chatbot had previously been marketed as a win for account security.
Want this in your inbox every morning?
Daily brief at your local 8am — bilingual EN/中文, free.
More from The Decoder
See more →
An AI model programmed nonstop for 19 days on a single MirrorCode task that cost $2,600 to run
Epoch AI's MirrorCode benchmark reveals Claude Opus 4.7 as the leader with a 56% solve rate, reconstructing a 16,000-line toolkit in 14 hours. Despite this, all models tested struggle with the most complex tasks, highlighting limitations in current AI capabilities. The single task consumed $2,600 over 19 days, raising questions about cost-effectiveness in AI development.

