Meta AI Credential-Manipulation Exploit
Four independent reporters describe a common mechanism: a vulnerability in Meta's AI systems that allegedly allows attackers to change the email address of a target Instagram account without possessing or verifying ownership of that email address. Once the email address is changed, the attacker controls the account's recovery pathway; any activity they perform on the account can trigger Meta's automated enforcement, leaving the original account holder permanently locked out with no appeal avenue. **Meta publicly acknowledged the exploit on June 1, 2026**: Andy Stone (@andymstone, Meta Director of Policy Communications) stated "This issue has been resolved and we are securing impacted accounts." Carmen Cuevas (@soycarmencuevas / @carmencuevas01, PA-2026-0036) documented that her account remained disabled as of June 6, 2026 — five days after Stone's statement — providing the clearest evidence in the dataset that the claimed fix was incomplete or that cascading disables from the exploit had already occurred before it was addressed.
Meta AI Credential-Manipulation Exploit
Evidence
- The attack vector was Meta's AI Support Assistant chatbot. TechCrunch (Lorenzo Franceschi-Bicchierai, June 1, 2026) verified the mechanism against a @DarkWebInformer video showing the step-by-step process: (1) attacker uses a VPN to spoof the target's geographic region, bypassing Instagram's automated account protections; (2) attacker opens a chat with Meta AI Support Assistant and requests that a new email address be added to the target's account; (3) the chatbot sends a verification code to the attacker's email address; (4) attacker shares the code with the chatbot; (5) chatbot presents a "Reset Password" button; (6) attacker sets a new password and takes over the account. TechCrunch independently verified that the hacker's email mailbox received the verification code. Source: https://techcrunch.com/2026/06/01/hackers-hijacked-instagram-accounts-by-tricking-meta-ai-support-chatbot-into-granting-access/
- Critical design flaw: the attack worked without the attacker ever possessing or taking over the legitimate email address linked to the victim's account. The chatbot accepted the attacker's request and dispatched the verification code to an unverified third-party address, bypassing the ownership check that a human support agent would have applied.
- What reporters said before the mechanism was confirmed: @CharlieeMeister (PA-2026-0033) described "the exploit allows a bad actor to change the email address of nearly any Instagram account without verification by manipulating Meta's AI." @kornbuilds (PA-2026-0024): "I had MFA/2FA on, account verified, facial scan, id scanned, everything protected. The exploit bypassed all of that, that's why it's an exploit." @cindie_zhu (PA-2026-0032) described months of credential stuffing precursors before eventual compromise on ~May 14, 2026 — consistent with sustained targeting before the chatbot-mediated takeover. All three reporters were accurate in their characterizations; the chatbot confirmed as the vector is the system that bypassed all standard protective measures.
- The common thread: standard protective measures (MFA/2FA, Meta Verified identity confirmation, facial scan, government ID on file) were insufficient because the attack did not require defeating them — it worked through the support chatbot's own tooling.
- The observed pattern after compromise: attacker gains account control via email address change → anomalous activity on the account (attacker's use, or simply the presence of changed account credentials) triggers Meta's automated integrity detection → Meta disables the account → original account holder attempts to appeal but cannot, because the email address on the account is no longer theirs → no appeal path survives. The permanent disable notice ("You cannot request another review of this decision") appears in all three records, and no restoration has been documented for any member of this cluster.
- This is a qualitatively different harm trajectory from organic over-enforcement: the original account holder is not merely suspended pending review, but is structurally locked out because the account's identity anchor (email address) has been transferred to the attacker before the enforcement action occurs.
- All four reporters in this cluster were Meta Verified subscribers at the time of the exploit:
- PA-2026-0024 (@kornbuilds / @korn): "Meta Verified, facial scan verified"
- PA-2026-0032 (@cindie_zhu): Meta Verified with passport and facial recognition scan
- PA-2026-0033 (@CharlieeMeister): "Meta Verified active subscriber"
- PA-2026-0036 (@soycarmencuevas / @carmencuevas01): Meta Verified active subscriber
- This convergence may reflect selection bias (Meta Verified users are more likely to publicly report and to use the Meta Verified language) or may reflect something about Meta Verified's implementation — if the exploit targets the Meta Verified identity confirmation pipeline specifically, then Meta Verified users would be disproportionately affected by design. This hypothesis cannot be confirmed from available evidence but warrants tracking in future records.
- If true, this would be a notable irony: Meta Verified is marketed partly as an account security layer, but the exploit may be exploiting that layer's own account management infrastructure.
- Andy Stone statement (June 1, 2026): @andymstone (Meta Director of Policy Communications) publicly stated: "This issue has been resolved and we are securing impacted accounts." Posted in reply to @howfxr's post linking a Cyber Security News article: "Instagram Meta AI Vulnerability Allegedly Enables Password Reset for Accounts."
- Andy Stone statement: https://x.com/andymstone/status/2061486724199379186 | Archive: https://archive.ph/2026.06.03-224746/https://x.com/andymstone/status/2061486724199379186
- Reply context (@howfxr): https://x.com/howfxr/status/2061347931786211677 | Archive: https://archive.ph/2026.06.03-224817/https://x.com/howfxr/status/2061347931786211677
- Carmen's post highlighting the exchange: https://x.com/soycarmencuevas/status/2062984325994303881 | Archive: https://archive.ph/2026.06.06-050519/https://x.com/soycarmencuevas/status/2062984325994303881
- This constitutes a strong platform acknowledgment — a named senior official (Director of Policy Communications) publicly addressing the specific exploit mechanism. Superseded as the dataset's strongest acknowledgment item by the Maine Attorney General data breach filing documented below. `platform_acknowledged` updated to true and `confidence_score` updated to 5 across all four cluster records (PA-2026-0024, PA-2026-0032, PA-2026-0033, PA-2026-0036).
- Fix documented as incomplete: @CharlieeMeister (PA-2026-0033) had previously stated Meta "claimed to have patched" it. Stone's June 1 statement is consistent with this framing. However, @carmencuevas01 (PA-2026-0036) was re-disabled on May 25 — before Stone's statement — and remained disabled on June 6 when Carmen highlighted Stone's post. This documents that the fix did not restore accounts already affected by the exploit, and that cascading disables had already propagated before the exploit was addressed. Whether the exploit itself was patched against future use remains unconfirmed by independent technical verification.
- Andy Stone second statement (June 3, 2026, 73K views): Stone stated: "Thank you for raising this. While we have already secured impacted accounts, we are now working to restore access to affected individuals. Some people may receive password reset notifications and some may be asked password security questions when they try and log into their accounts." This is stronger than the June 1 statement: it explicitly acknowledges that affected individuals had not yet been restored, and describes the remediation mechanism (password reset notifications, security questions). The statement was made in reply to @manipulate.
- Source: https://x.com/andymstone/status/2061930584486637611 | Archive: https://archive.ph/2026.06.04-092939/https://x.com/andymstone/status/2061930584486637611
- @manipulate post — exploit still active June 2, 2026: In the same thread, @manipulate confirmed: (a) the exploit was still active "almost two days post patch" (June 2); (b) "AI is not linear. The exploit evolves so long as the tooling is still there"; (c) showed an Instagram security email — "We detected some suspicious activity that suggests your Instagram account may have been compromised" — which appears to be the remediation notification mechanism Meta is deploying to affected accounts. The @manipulate framing is analytically significant: it articulates why a discrete "patch" may not fully contain an AI-driven exploit, since the attack surface adapts to the underlying AI tooling rather than a static vulnerability. This distinction matters for how the dataset interprets future records that cite the same mechanism post-June 1 — they should not be treated as evidence that no patch was attempted, but rather as consistent with an evolving attack surface.
- Maine Attorney General data breach filing (June 2026 — regulatory confirmation): Meta Platforms, Inc. filed a formal data breach notification with the Maine Attorney General documenting the "Meta AI Support Tool Incident." This is the strongest evidentiary item in the dataset for this finding: a government regulatory filing made by Meta's own legal counsel, constituting official corporate acknowledgment of the breach at scale.
- Official scale: 20,225 people affected. 30 Maine residents affected; 20,225 total affected individuals across all jurisdictions.
- Breach occurred: April 17, 2026. The exploit was active beginning April 17, 2026 — 44 days before it was discovered, and approximately 6 weeks before Andy Stone's June 1 public statement. The April 17 date also precedes the majority of enforcement actions in the dataset, which cluster from late May through June 2026. If enforcement of compromised accounts continued for weeks after the breach began, this is consistent with the dataset's documented wave pattern.
- Breach discovered: May 31, 2026. Meta discovered the breach one day before Andy Stone's June 1 public statement — consistent with a rapid public acknowledgment immediately following internal discovery. The 44-day discovery gap (April 17 – May 31) means the exploit was operational and causing harm during the entire period leading up to the enforcement wave in this dataset.
- Consumer notification date: June 19, 2026. As of this dataset's recording date (June 9, 2026), notifications to affected individuals had not yet been sent. Users whose accounts were disabled in the exploit cluster — including all five PA records attributed to this mechanism — may not have received official breach notification as of their intake date.
- No identity theft protection offered. Consistent with the support channel's documented failure to offer meaningful remediation (see appeal access failure patterns and data download tool failure).
- Official regulatory designation: "Meta AI Support Tool Incident." The PDF attached to the filing is titled "Meta_AI_Support_Tool_Incident_-_AG_Notification_ME.pdf" — this is the formal name Meta used in regulatory filings for this breach.
- Submitted by: Amber Hannah, Associate General Counsel, Meta Platforms, Inc. Phone: (650) 304-1284. Email: ahannah@meta.com. Filing address: 1601 Willow Road, Menlo Park, CA 94025-1452 — the Instagram LLC address confirmed in platform___Meta § Legal Contact, used here in a filing by Meta Platforms, Inc. rather than Instagram LLC specifically.
- Source: Maine AG Data Breach Notice viewer: https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/686120c8-63be-4e3c-b7ed-466d65b672f5.html | Notice PDF (access-restricted): https://www.maine.gov/cgi-bin/agviewerad/ret?loc=4169
- This filing supersedes all prior "platform acknowledgment" evidence in the dataset. Andy Stone's X posts were senior-official public statements; the Maine AG filing is a formal legal submission under Maine's data breach notification statute, made by in-house legal counsel, asserting a specific breach date, a specific scale, and a specific mechanism ("Meta AI Support Tool"). The `platform_acknowledged` field is already set to `true` across the four core cluster records; the Maine AG filing strengthens the evidentiary basis from social media statement to regulatory document.
- Three Telegram channels have been identified as active resale markets likely operating on inventory obtained via this exploit or similar credential-manipulation methods against Instagram/Meta accounts. These were surfaced by @matthewmades on X (https://x.com/matthewmades/status/2063379768855466436 — JS-rendered, content not retrievable via automated fetch; noted as referencing source).
- This represents the economic downstream layer of the exploit: accounts are stolen via the AI Support Assistant chatbot vector, then sold as inventory through Telegram storefronts. The existence of organized resale channels indicates that the exploit was not being used for isolated personal-grievance targeting alone — there is a commercial supply chain.
- Channel 1: @Pratesc — "الـقراصنة Pirates Shop🏴☠️" ("The Pirates Shop")
- URL: https://t.me/Pratesc
- Subscriber count (as of 2026-06-08): 1,423
- Channel name translates from Arabic as "The Pirates Shop" with explicit pirate flag branding. Description (Arabic): "ثكيل ولوصف عالي" + "I don't trust anyone!" Attributed to @MUGD0.
- The shop/marketplace framing is explicit. No specific account-type inventory confirmed from public metadata alone.
- Channel 2: @gmra_100 — "stock GMRA🐊"
- URL: https://t.me/gmra_100
- Subscriber count (as of 2026-06-08): 777
- Description: "Social media expert 💻☑ manager: @aaayym merktnig [sic: marketing]: @mmzzau ✅"
- "stock" in this context is consistent with account inventory framing. "Social media expert" is common self-description among account traffickers. Has a named manager (@aaayym) and marketer (@mmzzau) — structured enough to have distinct operational roles, suggesting an established operation rather than an ad-hoc seller.
- Channel 3: @vunros — "@vunros chat (Insta method)"
- URL: https://t.me/vunros
- Member count (as of 2026-06-08): 284 members, 69 online (~24% concurrent online rate — high for a channel this size, consistent with active trading)
- The channel title "Insta method" directly references an Instagram account takeover technique. This is the most explicit of the three in naming its subject matter. The high online-to-member ratio suggests active buyer/seller activity rather than passive content broadcasting.
- Cross-exploit scope note (added 2026-06-08): @vunros was cited by @MatthewMades (X, Thread 2/6: https://x.com/matthewmades/status/2063379768855466436) in the context of the “ban method” — a distinct attack vector involving VPN-assisted mass false reporting to trigger automated AI bans — not the AI chatbot credential exploit documented in this finding. @vunros’s pinned message (partially visible in Matthew’s embedded screenshot) appears to reference Instagram verification/credential activity. Taken together, this suggests @vunros may be a multi-exploit marketplace covering both the credential-manipulation vector documented here and the false-report ban method documented in false report brigading as weapon, rather than a single-technique storefront. This hypothesis is consistent with the “Insta method” framing but cannot be confirmed from public metadata alone.
- Curatorial note on @MatthewMades: His thread frames the ban method sympathetically — positioning targeted account holders as innocent business owners destroyed overnight by a flawed automated system — but directly links to @vunros and other channels as proof. This dual framing is consistent with genuine public interest documentation and with traffic-driving promotion of the same channels. The ambiguity is unresolved and should be carried forward if Matthew’s posts are used as a source in future records.
- Analytical note: the existence of these channels as a resale layer is structurally significant for the dataset. The Meta AI exploit lowered the cost of account takeover to the point where commercial resale became viable at scale — channels with hundreds to low thousands of subscribers suggest a market that is small enough to operate below major platform detection thresholds but large enough to represent a recurring business. The credential-manipulation vector is not a one-off — it is being operationalized as a supply mechanism for a secondary stolen-account market. This is relevant to PA-2026-0024 (@kornbuilds) as the anchor incident: if the @kornbuilds handle (short, recognizable) was targeted for resale value rather than personal grievance, the resale market context would explain the motivation.
- Cross-reference: PA-2026-0024 (@kornbuilds) remains the exploit cluster anchor. The resale market context does not change the mechanism documented above but adds a documented economic incentive layer explaining why this exploit was actively developed and used rather than reported responsibly.
Context
- Four independent reporters describe a common mechanism: a vulnerability in Meta's AI systems that allegedly allows attackers to change the email address of a target Instagram account without possessing or verifying ownership of that email address. Once the email address is changed, the attacker controls the account's recovery pathway; any activity they perform on the account can trigger Meta's automated enforcement, leaving the original account holder permanently locked out with no appeal avenue. Meta publicly acknowledged the exploit on June 1, 2026: Andy Stone (@andymstone, Meta Director of Policy Communications) stated "This issue has been resolved and we are securing impacted accounts." Carmen Cuevas (@soycarmencuevas / @carmencuevas01, PA-2026-0036) documented that her account remained disabled as of June 6, 2026 — five days after Stone's statement — providing the clearest evidence in the dataset that the claimed fix was incomplete or that cascading disables from the exploit had already occurred before it was addressed.
- An earlier version of this dataset's analysis attributed an OG-username targeting angle to this cluster, based on @korn (4 characters) and @ukio (4 characters) being short handles. This attribution was not confirmed. The short-handle observation for @korn and @ukio is noted as a weak co-occurring signal, not a confirmed motivation for this cluster.
- Meta's CISO Guy Rosen published "Agents Rule of Two: A Practical Approach to AI Agent Security" on October 31, 2025 at https://ai.meta.com/blog/practical-ai-agent-security/ and promoted it on X on November 3, 2025 (https://x.com/guyro/status/1985406678724988936). The framework addresses exactly the class of risk that materialized here.
- The Rule of Two states that AI agents must satisfy no more than two of these three properties simultaneously to avoid the highest-impact consequences of prompt injection: [A] can process untrustworthy inputs; [B] can access sensitive systems or private data; [C] can change state or communicate externally. If all three are required, the agent must not operate autonomously — it requires human-in-the-loop supervision or another reliable validation mechanism.
- The Meta AI Support Assistant, as deployed, satisfied all three simultaneously: [A] it processed requests from any member of the public, including attackers using VPNs to spoof locations; [B] it had access to account credentials and the email change pipeline; [C] it could make stateful account changes (adding an email address, sending verification codes, enabling password reset). The blog explicitly names this configuration — [ABC] — as requiring supervision. The chatbot had no such supervision.
- The gap between publication and incident: the framework was published ~7 months before the exploit became publicly reported (late May 2026). The support chatbot was not built in compliance with Meta's own CISO guidance.
- The user's analytical note: "the BBC-reported chatbot exploit could've only occurred if that guidance, referred to as a 'rule,' was not followed." This assessment is confirmed by the Rule of Two's own text and the confirmed attack mechanism. The framework was designed to prevent exactly this outcome; the product that enabled the exploit was built in violation of the framework.
- BBC coverage: A BBC article documented the account takeover exploit affecting Meta users (https://www.bbc.com/news/articles/c98rzr72dpyo). The BBC article is blocked from automated access; its content is corroborated by TechCrunch's confirmed mechanism and Andy Stone's public acknowledgment.
- @mariaandersenm (Maria Andersen) — corroborating source, not in incidents.jsonl: A Meta Verified customer who experienced the exploit and posted on X (June 2026) about being unable to get meaningful support from Meta. Source: https://x.com/mariaandersenm/status/2063899942469431780. Noted here as a corroborating witness to both the exploit pattern and the Meta Verified support failure; not intaked as a full incident record. Additional detail (June 9, 2026): In a reply thread under @Himanshu95258's restoration post, Maria Andersen stated her account had been suspended "at least 15 times over the past weeks." Treat as indicative rather than precise — the figure may be exaggerated, but the claim is consistent with repeated automated cycling under the re-enforcement-after-successful-adjudication pattern.
- This cluster should not be conflated with false report brigading as weapon. The mechanisms, victim experiences, and required policy interventions are distinct:
- Attack vector: Credential-manipulation exploit targets the account's identity infrastructure (email address, account recovery). False-report brigading targets the platform's enforcement pipeline by filing false reports. These are different attack surfaces.
- Victim experience: In credential manipulation, the original account holder is locked out before enforcement occurs — they lose account access twice (first to the attacker, then via platform disable). In brigading, the account holder retains their credentials throughout and experiences enforcement as a sudden external event.
- Attacker profile: Credential manipulation requires knowledge of a specific exploit and a specific target; it is higher-effort and more targeted. Brigading is lower-effort and scales easily to many targets.
- Policy intervention: Credential manipulation calls for hardening the account email-change and recovery pipeline against AI manipulation vectors. Brigading calls for detecting coordinated inauthentic reporting behavior.
- @DarkWebInformer: Tagged by both @kornbuilds (PA-2026-0024) and @cindie_zhu (PA-2026-0032). This is an X account that tracks cybersecurity exploits and dark web activity. They may have independent documentation of this exploit, its technical specifics, or its spread. Monitor for posts; any corroborating documentation from @DarkWebInformer would significantly strengthen the technical verification of the mechanism beyond reporter convergence.
- @andymstone (resolved): Tagged by @cindie_zhu (PA-2026-0032), @CharlieeMeister (PA-2026-0033), and @soycarmencuevas (PA-2026-0036). Andy Stone publicly responded on June 1, 2026 — see Platform Acknowledgment section above. This flag is resolved; @andymstone monitoring can be closed.
- Patch completeness (updated): Stone's June 3 statement confirms restoration is ongoing — victims were not yet restored as of June 3. The @manipulate post confirms the exploit was still active June 2. Carmen Cuevas's account (PA-2026-0036) remained disabled as of June 6. The @manipulate framing ("AI is not linear. The exploit evolves so long as the tooling is still there") provides the best available analytical explanation for why a patch may not cleanly close the attack surface. Track new reports citing the "Meta AI exploit" mechanism dated after June 1, 2026 — in light of @manipulate's framing, such cases should be assessed on whether the mechanism described matches the known pattern (email-change without verification) or represents a variant. PA-2026-0045 (@MasonVersluis reporting @megbzk) is the first post-acknowledgment attribution in the dataset: reporter explicitly uses “the recent Meta AI exploit” framing and tags @andymstone by name, consistent with using the public-discourse vocabulary from Stone’s June 1–3 statements. Enforcement date is approximate (~late May 2026, possibly pre-patch). Reporter’s note that Facebook and Threads accounts with identical content remain active is additional cross-platform evidence that enforcement was triggered by attacker activity, not by content. See PA-2026-0045 and cross platform enforcement inconsistency.
- Possible connection — PA-2026-0001 (@vhsdev, Facebook, May 23–26, 2026): The "too much activity" citation in PA-2026-0001 is behaviorally consistent with the downstream detection pattern in this cluster — anomalous account activity (here, plausibly generated by a stolen device with an authenticated session) triggering Meta's automated integrity system. The attack vector differs (stolen phone, not credential manipulation via Meta AI), but the enforcement mechanism is structurally the same. This is flagged as a possible connection, not a confirmed cluster member. See PA-2026-0001.
- Fourth cluster member (PA-2026-0036): @soycarmencuevas / @carmencuevas01 is the most complex case in this cluster: re-disabled five days after restoration, affecting a Meta Verified account with a documented informal internal acknowledgment of error predating Stone's public statement, with the longest documented enforcement timeline (Dec 2025 – present). This record uniquely bridges the re-enforcement cluster (PA-2026-0018, PA-2026-0027) and the Meta AI exploit cluster, and is the only cluster member to have post-acknowledgment continued harm documented by the reporter directly citing Stone's statement.
Pattern
- Four independent reporters describe a convergent mechanism, now confirmed by TechCrunch's independent verification (June 1, 2026): a vulnerability in Meta's AI Support Assistant chatbot allows attackers to change a target Instagram account's email address without owning or verifying that address, transferring the account's identity anchor before enforcement is triggered. The sequence in all four cases: email change → attacker activity triggers automated integrity detection → account disabled → original holder locked out because the recovery path belongs to the attacker. All four documented victims were Meta Verified subscribers with biometric verification on file. Meta publicly acknowledged the exploit on June 1, 2026 through a named senior official (Andy Stone, Director of Policy Communications), and issued a second statement June 3 confirming restoration was underway — but one victim remained disabled five days post-acknowledgment, and an independent observer (@manipulate) documented the exploit as still active two days post-patch. The @manipulate framing — "AI is not linear. The exploit evolves so long as the tooling is still there" — is the best available explanation for why a discrete patch may not fully close an AI-mediated attack surface. Variation within the cluster: the four cases share the outcome (permanent lockout, no appeal avenue) but differ in documented detail; @kornbuilds provides the most explicit statement that standard protective measures were bypassed; @carmencuevas01 provides the longest enforcement timeline and post-acknowledgment continued harm.
Significance
- This finding documents a qualitatively different harm category from organic over-enforcement: the platform's enforcement system is functioning as designed, but it is being weaponized as the final step in a third-party attack chain. The original account holder cannot interrupt the enforcement action because the account's identity anchor was transferred before enforcement occurred — making the standard appeal pathway structurally inaccessible by design. For platform accountability research, this raises a structural design question: if the same infrastructure used to verify identity in enforcement appeals (biometric confirmation, government ID) can be manipulated to strip a user of their account recovery pathway, then the appeal system is most inaccessible to the users who most need it. The Meta Verified irony — a paid security subscription whose identity verification pipeline may be the attack surface — is unconfirmed as a causal mechanism but is the strongest hypothesis in the dataset given that all four victims were Verified subscribers. Andy Stone's public statements constitute the strongest platform acknowledgment in the dataset, making this finding's evidentiary standing stronger than most; however, technical confirmation of the exact vulnerability mechanism beyond reporter convergence has not been independently established, and the patch's effectiveness against future exploitation remains unverified.
Supporting incidents
8 records| PA ID | Platform | Action Date | Action | Policy Cited | AI Involvement | Verification |
|---|---|---|---|---|---|---|
| PA-2026-0057 | Meta | Mar 26, 2026 | account-disable | Community Standards | DETECTION | Source confirmed |
| PA-2026-0045 | Meta | May 26, 2026 | account-disable | Community Standards | DETECTION | Source confirmed |
| PA-2026-0036 | Meta | Dec 12, 2025 | account-disable | — none cited | DETECTION | Platform confirmed |
| PA-2026-0033 | Meta | Jun 5, 2026 | account-disable | Community Standards | DETECTION | Platform confirmed |
| PA-2026-0032 | Meta | May 14, 2026 | account-disable | Community Standards on account integrity | DETECTION | Platform confirmed |
| PA-2026-0027 | Meta | May 24, 2026 | account-suspend | Community Standards on account integrity — fake accounts | DETECTION | Source confirmed |
| PA-2026-0024 | Meta | Jun 1, 2026 | account-disable | Community Standards | UNKNOWN | Platform confirmed |
| PA-2026-0018 | Meta | May 29, 2026 | account-disable | Community Standards on account integrity | DETECTION | Source confirmed |
- Platform
- Meta
- Date
- Mar 26, 2026
- Policy
- Community Standards
- AI Role
- DETECTION
- Verified
- Source confirmed
- Platform
- Meta
- Date
- May 26, 2026
- Policy
- Community Standards
- AI Role
- DETECTION
- Verified
- Source confirmed
- Platform
- Meta
- Date
- Dec 12, 2025
- Policy
- — none cited
- AI Role
- DETECTION
- Verified
- Platform confirmed
- Platform
- Meta
- Date
- Jun 5, 2026
- Policy
- Community Standards
- AI Role
- DETECTION
- Verified
- Platform confirmed
- Platform
- Meta
- Date
- May 14, 2026
- Policy
- Community Standards on account integrity
- AI Role
- DETECTION
- Verified
- Platform confirmed
- Platform
- Meta
- Date
- May 24, 2026
- Policy
- Community Standards on account integrity — fake accounts
- AI Role
- DETECTION
- Verified
- Source confirmed
- Platform
- Meta
- Date
- Jun 1, 2026
- Policy
- Community Standards
- AI Role
- UNKNOWN
- Verified
- Platform confirmed
- Platform
- Meta
- Date
- May 29, 2026
- Policy
- Community Standards on account integrity
- AI Role
- DETECTION
- Verified
- Source confirmed