{"meta":{"exportedAt":"2026-10-01T07:38:19.842Z","formatVersion":2,"selection":{"q":"actor","system":"","harm":"","context":"","country":"","role":"","relation":"contextual","evidence":"","year":"","response":"","severity":"","verification":"","view":"incidents","sort":"added"},"totalIncidents":1,"coverage":{"cases":1,"countries":0,"languages":1,"unknownLocation":1,"locationPending":0,"unknownLanguage":0,"unknownDate":0,"lawsuits":0,"regulatory":0,"minors":0,"coreRelations":0,"contextualRelations":1,"mixedRelations":0,"unknownRelations":0,"relationPending":0,"relationUnknown":0},"countingNote":"Distinct public cases in this selection. People counts apply within individual cases only; cross-case person overlap has not been resolved. No population incidence estimate.","affectedCountNote":"Interpret person counts with affectedCountStatus and the reported effects. Unquantified zeros are placeholders, not a measured zero.","source":"AI incidents","publisher":"NOPE","url":"https://nope.net/incidents","license":"CC BY 4.0"},"incidents":[{"id":"2026-meta-instagram-ai-assisted-account-recovery-tool-exploited-to-reset-passwords","caseFacts":{"claims":[{"id":"c1","status":"corroborated","evidence":[{"locator":"the system incorrectly sent a password reset link to that unassociated email rather than rejecting the request","relation":"supports","source_id":"s1"},{"locator":"This allowed unauthorized third parties to receive a password reset link for accounts they did not own","relation":"supports","source_id":"s1"},{"locator":"The chatbot can be seen sending a verification code to the email address provided by the hacker","relation":"supports","source_id":"s3"},{"locator":"TechCrunch was able to verify that the hacker’s public email mailbox, which was displayed in the video, effectively received the verification code.","relation":"supports","source_id":"s3"}],"assertion":"Through Meta's AI-assisted account recovery support system (High Touch Support), third parties received password reset links or verification codes for Instagram accounts they did not own, sent to an email address that was not associated with the account.","causal_attribution":"Two evidential bases: Meta's own notice to the Maine Attorney General (a party's account of its own system) and videos the attackers posted, in which TechCrunch confirmed that the mailbox shown received the verification code. TechCrunch's check covers that one delivery. It did not test which Meta tool sent the code or who owned the target account, and the videos were not opened for this review. The link between the chat assistant in the videos and High Touch Support is made by press reports and by Meta's spokesperson referring to the AI agent. No inspected document names both. Meta says the tool worked as intended and the failure lay in a separate code path (see c5), so the AI component's own contribution is disputed."},{"id":"c2","status":"reported","evidence":[{"locator":"the hacker opened a chat with Meta AI Support Assistant and asked the bot to add a new email address to the target’s account.","relation":"supports","source_id":"s3"},{"locator":"which prompts the chatbot to show a button to “Reset Password.”","relation":"supports","source_id":"s3"},{"locator":"One video shows a hacker starting a conversation with Meta’s AI support bot and asking it to link the target account with a new email address","relation":"supports","source_id":"s5"},{"locator":"using a VPN connection with an IP address that is in or near the target’s usual hometown","relation":"supports","source_id":"s6"},{"locator":"The bot followed through with the request - sending a code to the hacker's email which, when verified, was followed by an email with a link to change their password.","relation":"supports","source_id":"s7"}],"assertion":"Attackers asked Meta's AI support assistant in a chat to add or link a new email address to a target Instagram username, and some used a VPN to appear in the target's location. In one video the assistant then sent a verification code to that address and showed a button to reset the password.","causal_attribution":"Every account of the chat steps traces to videos and screenshots the attackers posted on Telegram and X. TechCrunch checked one displayed mailbox. The other videos were not independently reproduced."},{"id":"c3","status":"reported","evidence":[{"locator":"the unauthorized party was able to log in to the account if the account holder had not enabled two-factor authentication (2FA)","relation":"supports","source_id":"s1"},{"locator":"The hackers who released the video on Telegram said their exploit failed to work against any accounts that had MFA enabled.","relation":"supports","source_id":"s6"}],"assertion":"Meta's notice says the account could be logged into after the password reset if the account holder had not enabled two-factor authentication. Krebs on Security reports that the attackers who posted the video said the exploit failed against accounts with multi-factor authentication.","causal_attribution":"Meta's statement about its own system and the attackers' own statement as relayed by Krebs. Neither was tested independently."},{"id":"c4","status":"reported","evidence":[{"locator":"it can also take action for you on a growing set of requests directly within Facebook and in the future, on Instagram, including:","relation":"supports","source_id":"s12"},{"locator":"Resetting passwords","relation":"supports","source_id":"s12"},{"locator":"We’ve also started rolling out the support assistant to people who need help logging into their Facebook and Instagram accounts, starting with select cases in the US and Canada","relation":"supports","source_id":"s12"}],"assertion":"Meta announced the Meta AI support assistant for Facebook and Instagram on 19 March 2026, described it as able to take action on requests including resetting passwords directly within Facebook and, in the future, on Instagram, and said it had started rolling it out to people who need help logging into Facebook and Instagram accounts, starting with select cases in the US and Canada.","causal_attribution":"Meta's own product announcement. The announcement does not say which tool the exploited flow used. The link between this assistant and the High Touch Support tool named in Meta's notice is made by the press reports and by the notice's own description of an AI-assisted account recovery system."},{"id":"c5","status":"disputed","evidence":[{"locator":"The tool itself worked properly and functioned as intended; however due to a bug in a separate code path, the system did not properly verify that the email address provided by the individual requesting a password reset matched the email address associated with that user’s Instagram account.","relation":"supports","source_id":"s1"},{"locator":"Some of our internal backend checks failed in this instance, but it wasn’t due to the AI agent itself, and we’ve addressed the underlying cause.","relation":"supports","source_id":"s11"},{"locator":"Hackers simply told Meta’s AI chatbot that they were the owners of the target’s account, and asked the bot to link that person’s account to an email they controlled. The chatbot complied with the request","relation":"contradicts","source_id":"s4"}],"assertion":"Whether the failure lay in the AI agent or in a separate code path is disputed. Meta's notice says the tool worked as intended and that a bug in a separate code path did not check the requester's email address against the account, and a Meta spokesperson told Gizmodo that some internal backend checks failed and that this was not due to the AI agent itself. TechCrunch describes the chatbot as complying with the attackers' request.","causal_attribution":"Meta's account of its own system. TechCrunch's description of the chatbot as complying with the request is a reporter's characterisation from the attackers' videos and does not test where in Meta's system the check failed."},{"id":"c6","status":"reported","evidence":[{"locator":"Date(s) Breach Occured: 04/17/2026","relation":"supports","source_id":"s2"},{"locator":"Date Breach Discovered: 05-31-2026","relation":"supports","source_id":"s2"},{"locator":"May 31, 2026, Meta discovered that there was a vulnerability in an AI-assisted account","relation":"supports","source_id":"s1"},{"locator":"same day the exploitation was identified by Meta, the following actions were taken to","relation":"supports","source_id":"s1"},{"locator":"the AI-assisted support tool removing the vulnerable code path from production","relation":"supports","source_id":"s1"}],"assertion":"Meta's notice lists 17 April 2026 as the date the breach occurred (as 04/17/2026) and 31 May 2026 as the date it discovered the vulnerability, and says Meta disabled the AI-assisted support tool on the same day the exploitation was identified.","causal_attribution":"Meta's own dates for its own system. The notice letter gives the discovery date and no start date. The 17 April date appears only in the listing form, and the basis for it is not stated."},{"id":"c7","status":"reported","evidence":[{"locator":"Total number of persons affected (including residents): 20225","relation":"supports","source_id":"s2"},{"locator":"Total number of Maine residents affected: 30","relation":"supports","source_id":"s2"},{"locator":"reset through the support tool, did not have 2FA enabled on their account and whose Instagram accounts were likely accessed by an unauthorized party.","relation":"supports","source_id":"s1"},{"locator":"This number represents an upper bound of the users impacted as some of the accounts may have been accessed legitimately by account owners.","relation":"supports","source_id":"s1"}],"assertion":"The Maine Attorney General listing of Meta's submission gives 20225 as the total number of persons affected and 30 as the number of Maine residents. The notice defines the Maine figure as users whose passwords were reset through the tool, who had no two-factor authentication and whose accounts were likely accessed by an unauthorized party, and calls it an upper bound because some accounts may have been accessed legitimately by their owners.","causal_attribution":"Meta's own estimate. The notice's upper-bound wording is written for the Maine figure. The inspected notice does not say whether the total of 20225 counts accounts or people, how many were taken over, or how many are organisational accounts."},{"id":"c8","status":"reported","evidence":[{"locator":"“The password got changed without my knowledge and I was getting different password reset attempts throughout yesterday,” said Wong.","relation":"supports","source_id":"s3"},{"locator":"And I got repeatedly logged out from the IG iOS app[.] Quite concerning.","relation":"supports","source_id":"s10"},{"locator":"it took about five to 10 minutes to reinstate her account","relation":"supports","source_id":"s9"},{"locator":"Wong, who previously worked at Meta as a security engineer, said in a post on X her Instagram password was \"changed without my knowledge\"","relation":"supports","source_id":"s7"}],"assertion":"Jane Manchun Wong, a security researcher and former Meta employee, posted on X that her Instagram password was changed without her knowledge, that she received password reset attempts and was repeatedly logged out of the app, and told Reuters that reinstating her account took about five to ten minutes.","causal_attribution":"Her own public statements, relayed by four outlets. The X post itself was not opened. Wong does not say in the quoted statements how her account was accessed, and the outlets connect it to the exploit."},{"id":"c9","status":"reported","evidence":[{"locator":"and the account of the U.S. Space Force’s chief master sergeant","relation":"supports","source_id":"s4"},{"locator":"the account of the U.S. Space Force’s chief master sergeant","relation":"supports","source_id":"s3"},{"locator":"the Chief Master Sergeant of the U.S. Space Force were briefly defaced with pro-Iranian images and messages over the weekend","relation":"supports","source_id":"s6"},{"locator":"the Chief Master Sergeant of Space Force’s account","relation":"supports","source_id":"s5"}],"assertion":"TechCrunch and Krebs on Security report that the Instagram account of the U.S. Space Force's Chief Master Sergeant was compromised, and Krebs reports that it was briefly defaced with pro-Iranian images and messages.","causal_attribution":"Reporters' accounts based on screenshots the attackers posted. The account holder is not quoted in the inspected sources and is described here by office only. Whether the account is a personal or an official office account is not stated."},{"id":"c10","status":"reported","evidence":[{"locator":"including the Barack Obama White House account , the Chief Master Sergeant of Space Force’s account , and Sephora’s account","relation":"supports","source_id":"s5"},{"locator":"The Sephora corporate page and the account belonging to the Chief Master Sergeant of the U.S. Space Force were also hit.","relation":"supports","source_id":"s10"},{"locator":"The Instagram accounts for the Obama White House and the Chief Master Sergeant of the U.S. Space Force were briefly defaced","relation":"supports","source_id":"s6"},{"locator":"The former US president's account reportedly posted pro-Iran content before it was recovered.","relation":"supports","source_id":"s7"},{"locator":"the dormant Obama White House account (which Meta disputed)","relation":"context","source_id":"s4"}],"assertion":"Outlets named the Sephora corporate account and a dormant Obama White House account among the compromised accounts, and Krebs and the BBC report that the Obama White House account was defaced with pro-Iran content. TechCrunch's 3 June report lists the Obama White House account among apparent victims with the parenthetical '(which Meta disputed)'. Both are organisational or institutional accounts and are not counted as affected persons.","causal_attribution":"Reporters' accounts. The Guardian, Gizmodo and Reuters name Sephora on the strength of 404 Media's reporting, so Sephora rests on one chain. TechCrunch does not say what Meta disputed about the Obama White House account. The BBC reports that Meta's spokesperson called claims that world leaders' accounts were hacked totally false."},{"id":"c11","status":"reported","evidence":[{"locator":"allowing the hacker to reset the target account’s password and take control of the account — in some cases locking out the victims.","relation":"supports","source_id":"s4"},{"locator":"locking users out of their accounts and prompting a wave of complaints on platforms including X and Reddit.","relation":"supports","source_id":"s9"},{"locator":"One X user wrote that they had been unable to find \"human support\" after their Instagram account was hacked.","relation":"supports","source_id":"s7"},{"locator":"Everyday users complained of similar hijackings on Reddit and X over the weekend.","relation":"supports","source_id":"s8"}],"assertion":"Some victims were reported locked out of their accounts, and one person wrote on X that they could not find human support after their Instagram account was hacked.","causal_attribution":"Reporters' summaries of complaints on X and Reddit. The individual posts were not opened and the complainants are not identified."},{"id":"c12","status":"reported","evidence":[{"locator":"TechCrunch has seen examples of allegedly hacked handles featuring common forenames or names of countries","relation":"supports","source_id":"s4"},{"locator":"(It’s important to note that it’s hard to know for sure if all these accounts were hacked due to the same technique.)","relation":"supports","source_id":"s4"},{"locator":"hijack a number of valuable (read: short) Instagram account names that allegedly have a resale value of more than a half million dollars.","relation":"supports","source_id":"s6"},{"locator":"404 Media has seen text files of huge lists of “OG,” or high-value, original usernames","relation":"context","source_id":"s5"}],"assertion":"Short Instagram handles were reported taken in the campaign and offered for resale. TechCrunch saw examples of allegedly hacked handles being advertised for sale and notes it is hard to know whether all were taken with this technique. Krebs reports that the attackers claimed the resale value of the short handles they took exceeded half a million dollars.","causal_attribution":"The resale and value claims come from attackers' Telegram posts as relayed by TechCrunch and Krebs. No sale was confirmed and the owners are not identified."},{"id":"c13","status":"reported","evidence":[{"locator":"\"This issue has been resolved and we are securing impacted accounts,\" Meta spokesperson Andy Stone told users in a statement on X","relation":"supports","source_id":"s7"},{"locator":"On Monday, Instagram spokesperson Andy Stone said in a reply to Wong’s post and others that the issue was now fixed.","relation":"supports","source_id":"s3"},{"locator":"Invalidated all existing password reset links that had been generated through the vulnerable path","relation":"supports","source_id":"s1"},{"locator":"potentially affected accounts into a mandatory security checkpoint requiring authentication before any account access","relation":"supports","source_id":"s1"},{"locator":"impacted users to reset their passwords and re-authenticate through secure, verified channels","relation":"supports","source_id":"s1"}],"assertion":"A Meta spokesperson said on X on 1 June 2026 that the issue was resolved and Meta was securing impacted accounts. Meta's notice says that it disabled the tool, invalidated existing password reset links generated through the vulnerable path, enrolled potentially affected accounts in a mandatory security checkpoint and told impacted users to reset their passwords.","causal_attribution":"Meta's statements about its own response. TechCrunch reports that the response did not end the reports (see c14)."},{"id":"c14","status":"reported","evidence":[{"locator":"On Tuesday, however, more Instagram users claimed to have had their accounts hacked.","relation":"supports","source_id":"s4"},{"locator":"who claimed to still be able to exploit Meta’s AI chatbot, and they were advertising apparently hacked handles for sale","relation":"supports","source_id":"s4"}],"assertion":"TechCrunch reported on 3 June 2026 that more Instagram users claimed to have had accounts hacked after Meta said the issue was resolved, and that members of a Telegram channel claimed they could still exploit the chatbot.","causal_attribution":"Claims by users and Telegram members as relayed by TechCrunch. The claims were not verified, and Meta's notice says the tool was disabled on 31 May 2026."}],"effects":[{"label":"A named security researcher reported that her Instagram password was changed without her knowledge and that she was logged out, and she told Reuters the account was reinstated in about five to ten minutes","claim_id":"c8","direction":"negative"},{"label":"The Instagram account of the U.S. Space Force's Chief Master Sergeant was reported compromised and briefly defaced with pro-Iranian content","claim_id":"c9","direction":"negative"},{"label":"Some account holders were reported locked out of their Instagram accounts, and one reported being unable to reach human support","claim_id":"c11","direction":"negative"},{"label":"Short Instagram handles were reported taken and offered for resale on Telegram","claim_id":"c12","direction":"negative"}],"sources":[{"id":"s1","url":"https://www.maine.gov/cgi-bin/agviewerad/ret?loc=4169","kind":"regulatory_filing","access":"read","language":"en","translation_note":"Notice PDF read directly. Its text layer separates words with U+200B characters and detaches the first letter of some paragraphs, so locators from this source are given with those characters read as spaces.","independence_group":"meta-own-statements"},{"id":"s2","url":"https://web.archive.org/web/20260609035813id_/https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/686120c8-63be-4e3c-b7ed-466d65b672f5.html","kind":"official_record","access":"read","language":"en","translation_note":"","independence_group":"meta-own-statements"},{"id":"s3","url":"https://techcrunch.com/2026/06/01/hackers-hijacked-instagram-accounts-by-tricking-meta-ai-support-chatbot-into-granting-access/","kind":"news_report","access":"read","language":"en","translation_note":"","independence_group":"attacker-posted-videos"},{"id":"s4","url":"https://techcrunch.com/2026/06/03/instagram-is-alerting-users-who-were-targeted-by-hackers-during-ai-chatbot-attacks/","kind":"news_report","access":"read","language":"en","translation_note":"","independence_group":"attacker-posted-videos"},{"id":"s5","url":"https://www.404media.co/hackers-simply-asked-meta-ai-to-give-them-access-to-high-profile-instagram-accounts-it-worked/","kind":"news_report","access":"read","language":"en","translation_note":"Read through an Internet Archive capture of 1 June 2026 (20260601172133) because the live page is paywalled. The capture carries the full article.","independence_group":"attacker-posted-videos"},{"id":"s6","url":"https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/","kind":"news_report","access":"read","language":"en","translation_note":"","independence_group":"attacker-posted-videos"},{"id":"s7","url":"https://www.bbc.com/news/articles/c98rzr72dpyo","kind":"news_report","access":"read","language":"en","translation_note":"","independence_group":"attacker-posted-videos"},{"id":"s8","url":"https://www.theguardian.com/technology/2026/jun/01/meta-ai-hack-obama-sephora-instagram","kind":"news_report","access":"read","language":"en","translation_note":"","independence_group":"attacker-posted-videos"},{"id":"s9","url":"https://insideretail.us/how-the-sephora-instagram-hack-exposed-metas-ai-weakness/","kind":"wire_report","access":"read","language":"en","translation_note":"","independence_group":"attacker-posted-videos"},{"id":"s10","url":"https://gizmodo.com/hackers-tricked-meta-ai-into-handing-out-access-to-major-instagram-accounts-2000766087","kind":"news_report","access":"read","language":"en","translation_note":"","independence_group":"attacker-posted-videos"},{"id":"s11","url":"https://gizmodo.com/meta-says-thousands-of-instagram-accounts-were-breached-through-its-ai-support-assistant-2000768770","kind":"news_report","access":"read","language":"en","translation_note":"","independence_group":"meta-own-statements"},{"id":"s12","url":"https://about.fb.com/news/2026/03/boosting-your-support-and-safety-on-metas-apps-with-ai/","kind":"official_statement","access":"read","language":"en","translation_note":"","independence_group":"meta-own-statements"}],"version":1,"ai_roles":["others_use","institutional_use"],"contexts":["privacy","everyday_life"],"unknowns":["How many people or organisations lost control of an account is not established. Meta's listing gives 20225 persons affected and the notice calls the Maine figure an upper bound, and the notice does not say how many accounts were organisational or how many were taken over.","Meta says it is unaware of what, if any, personal information was accessed. Whether any messages or data were read is unknown.","The start date rests on Meta's listing (17 April 2026), and the notice does not state its basis. 404 Media quotes a Telegram channel documenting the hack saying the exploits were 'getting abused after quietly working for months', and separately says that the same account originally posted in Telegram about the vulnerability 'at the end of March' (the year is not stated). Neither statement gives a start date for exploitation. Meta's announcement of 19 March 2026 says the support assistant was previewed 'in December' (year not stated in the passage) and that help with logging in was starting in select cases in the US and Canada, so no inspected source establishes the earliest date of exploitation.","The end date is Meta's date for disabling the tool (31 May 2026). TechCrunch reported unverified claims of continued exploitation on 3 June 2026.","The X posts, the Telegram videos and the Reddit complaints were not opened. Reporters' descriptions of them are used.","The notice does not say how many accounts were restored to their owners, and the listing shows 19 June 2026 as the date of consumer notification in a capture taken on 9 June 2026.","Figures of about 34,000 accounts targeted and a SimpliSafe account appeared only on an aggregator page that attributes the first figure to Meta without a citation and are not used."],"geography":{"basis":"Meta's notice to the Maine Attorney General counts 30 Maine users among those potentially impacted. The countries of the other affected people, the attackers (who reportedly used VPNs to appear in the target's location) and Meta's systems are not stated in the inspected sources, and the country of the named security researcher is not stated.","court_countries":[],"event_countries":[],"affected_person_countries":["US"]},"publication":{"basis":"Meta's notice to the Maine Attorney General (a PDF read directly) and the Maine listing (an archived capture) document Meta's own account of the exploited AI-assisted tool, the dates and the affected count. Nine news reports and Meta's March announcement were read in full. The mechanism claim has two independent chains (Meta's filing and attacker-posted videos checked by TechCrunch). Harm to named account holders rests on their own statements or on reporters relaying attacker-posted screenshots, so those claims stay at reported status. Only one account holder who spoke publicly is named. The office holder is described by office only.","reviewed_on":"2026-09-29"},"ai_involvement":{"basis":"Meta's notice to the Maine Attorney General describes the affected system as an AI-assisted account recovery system (High Touch Support) and says it sent a password reset link to an email address not associated with the account. TechCrunch reports that no Meta employee or contractor took part in the exploit chats and checked one attacker mailbox for the code. Meta says the tool worked as intended, that the failure was a bug in a separate code path that did not verify the email address, and (to Gizmodo) that the failure was not due to the AI agent itself. Whether the AI component or the separate code path caused the failure is disputed and was not tested.","status":"supported"},"person_relations":["made_decision_about"]},"name":"Third parties exploit Meta's AI-assisted Instagram account recovery tool to reset passwords, with account takeovers reported (17 April to 31 May 2026)","summary":"Meta announced the rollout of its AI support assistant on Facebook and Instagram on 19 March 2026. Meta's filing with the Maine Attorney General (notice dated 5 June 2026) says unauthorized third parties exploited a vulnerability in its AI-assisted Instagram account recovery tool (High Touch Support) to receive password reset links for accounts they did not own, and the listing gives 17 April 2026 as the breach date and 31 May 2026 as the discovery date. Videos that attackers posted, as described by TechCrunch, 404 Media and Krebs on Security, show attackers asking the assistant in a chat to link a new email address to a target username. Reported victims include the security researcher Jane Manchun Wong, who posted that her password was changed without her knowledge, the Instagram account of the U.S. Space Force's Chief Master Sergeant, and the accounts of Sephora and a dormant Obama White House page (TechCrunch marks the last as disputed by Meta). Krebs and the BBC report pro-Iran defacement of some accounts, and TechCrunch reports that some victims were locked out and that short handles were offered for resale. The filing gives 20225 persons affected in total and 30 in Maine, and the notice calls the Maine figure an upper bound. Meta says the tool worked as intended, that a bug in a separate code path failed to check the email address, and (through a spokesperson to Gizmodo) that the failure was not due to the AI agent itself. Meta says it disabled the tool on 31 May 2026, the day it discovered the exploitation.","incidentDate":"2026-04-17","incidentEndDate":"2026-05-31","incidentKind":"bounded_series","incidentDatePrecision":"range","exposurePattern":"unknown","reportedDate":"2026-06-01","aiSystem":"Meta AI support assistant / High Touch Support (AI-assisted Instagram account recovery tool)","aiProduct":"Meta AI support assistant","aiCompany":"Meta","severity":"low","verificationStatus":"credible","harmCategories":[],"harmOutcomes":["other_material_harm","reputational_harm"],"harmOutcomeSummary":"Reporters and Meta's notice report that third parties reset passwords on Instagram accounts and, where the account had no two-factor authentication, could log in. A named security researcher reports her password was changed without her knowledge and that reinstating the account took about five to ten minutes. Krebs on Security and the BBC report that some high-profile accounts were briefly defaced, TechCrunch reports that some victims were locked out and that short handles were offered for resale, and Meta says it does not know what personal information, if any, was accessed. Meta's filing gives 20225 persons affected in total, and its notice calls the Maine figure an upper bound.","frameworkFacets":[],"causationStatus":"disputed","participantUsersAffectedMin":0,"otherPeopleHarmedMin":2,"affectedCountStatus":"partial","affectedCountEvidence":"Two account holders are counted: the security researcher who posted that her account was taken over, and the office holder whose Instagram account TechCrunch and Krebs on Security report as compromised. TechCrunch's 3 June article says this account 'appeared to be' among the victims, no statement from the office holder or from Meta about this account was inspected, and whether it is a personal or an official account is not stated. Sephora and the Obama White House account are organisational or institutional accounts and are not counted. Other victims (everyday users, short-handle holders) are unquantified. Meta's listing of 20225 persons affected is not counted: the notice calls the Maine figure an upper bound and does not say how many accounts were taken over or how many were organisational.","victimAgeRange":"unknown","platformType":"assistant","primarySourceUrl":"https://www.maine.gov/cgi-bin/agviewerad/ret?loc=4169","primarySourceLabel":"Meta incident notification to the Maine Attorney General (5 June 2026)","firstPublishedAt":"2026-09-29T21:16:54.181323+00:00","updatedAt":"2026-09-30T01:17:45.477765+00:00","scopeVersion":"facts-v3","tags":["historical-2026"]}]}