17 Apr 2026 to 31 May 2026Event location unknownMeta AI support assistant
Meta announced the rollout of its AI support assistant on Facebook and Instagram on 19 March 2026. Meta's filing with the Maine Attorney General (notice dated 5 June 2026) says unauthorized third parties exploited a vulnerability in its AI-assisted Instagram account recovery tool (High Touch Support) to receive password reset links for accounts they did not own, and the listing gives 17 April 2026 as the breach date and 31 May 2026 as the discovery date. Videos that attackers posted, as described by TechCrunch, 404 Media and Krebs on Security, show attackers asking the assistant in a chat to link a new email address to a target username. Reported victims include the security researcher Jane Manchun Wong, who posted that her password was changed without her knowledge, the Instagram account of the U.S. Space Force's Chief Master Sergeant, and the accounts of Sephora and a dormant Obama White House page (TechCrunch marks the last as disputed by Meta). Krebs and the BBC report pro-Iran defacement of some accounts, and TechCrunch reports that some victims were locked out and that short handles were offered for resale. The filing gives 20225 persons affected in total and 30 in Maine, and the notice calls the Maine figure an upper bound. Meta says the tool worked as intended, that a bug in a separate code path failed to check the email address, and (through a spokesperson to Gizmodo) that the failure was not due to the AI agent itself. Meta says it disabled the tool on 31 May 2026, the day it discovered the exploitation.
Contextual tracker case Low reported severity
AI involvement supported · Causal attribution disputed · 12 sources, 2 underlying accounts · Added 29/09/2026
20 May 2026United StatesMeta internal AI systems (reported)
On 20 May 2026 Meta began notifying about 8,000 employees (roughly 10 percent of its workforce) that they had been selected for layoff. On 13 July 2026 twenty-six anonymous employees who had taken or requested medical, pregnancy, parental or family leave, or a disability accommodation, sued Meta in the US District Court for the Northern District of California. The complaint alleges, on information and belief, that Meta used internal AI-assisted systems (including the Metamate assistant, keystroke and activity monitoring, AI-token-usage dashboards and algorithmic performance ranking) to score, rank and select employees, and that these inputs could not accumulate during protected leave, so plaintiffs on leave were disproportionately selected. Meta says workforce decisions were made by people, not AI, and that no selection decision was made by AI. On 17 July 2026 the court denied a temporary restraining order, recording that the parties dispute whether Meta used AI in the terminations and finding serious questions on the merits but no shown likelihood of success. One plaintiff was voluntarily dismissed on 3 August 2026. The preliminary injunction motion was argued on 24 August 2026 and taken under submission. The plaintiffs are pursuing their merits claims in arbitration and the allegations are unproven.
Contextual tracker case Medium reported severity
AI involvement disputed · Causal attribution disputed · 10 sources, 5 underlying accounts · Added 29/09/2026
Event date unknownEvent location unknownFacebook video face-scan check
In a public post to r/facebook on 28 September 2026, a user writes that their five-year-old Facebook account was hit with a security check that asked for a video face scan, which 'failed completely'. They say their face had changed a lot through recent life circumstances and 'The AI simply didn't recognize me.' Facebook then asked for ID, and 'the automated system instantly rejected' their government ID because their profile uses a shortened nickname. The poster says they are locked out of years of memories, friends and active Marketplace listings and are looking for a way to reach a human or download their data. Meta has said that video selfies used to regain access to compromised accounts are compared with the account's profile pictures using facial recognition; whether this check worked that way is not known. The account is uncorroborated.
Contextual tracker case Low reported severity
AI involvement reported · Causal attribution alleged · 2 sources · Added 29/09/2026
2 Sept 2026United StatesMeta AI
On 1 September 2026 Kalie Robins, a Utah travel creator, posted a short Instagram video of herself singing in the car with one of her daughters; it was also shown on Facebook. The next day she noticed Meta AI had placed suggested questions under the post, starting with 'Who's the child passenger?'. Clicking the prompts, she said, produced her two daughters' names, birth information, photos and videos drawn from her own and relatives' past posts, including a newborn photo from her mother's account and a picture she believed she had deleted years earlier, and a further prompt, 'Where does Kalie Robins live?', assembled older and newer posts into her likely location. Her 2 September reaction video drew more than 310,000 likes. Meta told reporters the prompts 'missed the mark', 'should never have been generated' and had been fixed, while saying the feature only surfaces information the user can already access; it disputed that a long-deleted photo was used, saying the photo had been deleted shortly before the video and remained briefly visible through a bug. Robins said Meta never contacted her and that the episode left her feeling she had 'failed' her children.
Contextual tracker case Low reported severity Involving minors Internal Action
AI involvement supported · Causal attribution supported · 4 sources · Added 18/09/2026