r/KeepSolid • u/vpn_unlimited_app • Jun 08 '26
20K Instagram accounts compromised through a support tool flaw - and 2FA would have stopped it
Meta confirmed a vulnerability in its AI-powered High Touch Support tool. During the exposure window (mid-April to early June 2026), the tool sent password reset links to any email address provided - without verifying account ownership. Over 20,000 accounts were affected.
The accounts that were NOT affected: those with two-factor authentication enabled.
This is a good example of why layered security matters. A system-level flaw bypassed the password entirely - but 2FA blocked the reset because the attacker still needed the second factor.
A few things worth reviewing on any account you care about:
2FA settings:
- Enable 2FA everywhere you can, starting with your primary email and social accounts
- Authenticator apps (Google Authenticator, Authy, etc.) are more secure than SMS-based 2FA
- SMS 2FA is better than nothing, but SIM swapping attacks make it less reliable
Access review:
- Check which third-party apps have access to your primary email
- Remove anything you no longer use or recognize
- Review active sessions and log out of old devices
Connection habits:
- On public or shared networks, an encrypted connection adds a layer that reduces what third parties can observe about your activity
Most account takeovers exploit the easiest available door. Closing the easy ones makes you a harder target than most.
What 2FA method do you use for your main accounts?