CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 134

As cited

Copy frozen at (site build).

identity access

Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts

Pro-Iranian hackers disclosed an exploit allowing them to hijack Instagram accounts by tricking Meta's AI customer support bot into resetting passwords and linking new email addresses. The vulnerability affected high-value accounts, including those of the Obama White House and the U.S. Space Force Chief Master Sergeant, before Meta deployed an emergency patch. Security researchers note that AI-powered account recovery systems present new attack surface similar to social engineering risks with human support staff.

Why it matters: Accounts without multi-factor authentication (MFA) remain vulnerable to this bot manipulation technique; enable MFA immediately, particularly security keys or passkeys, as even SMS-based codes would have blocked this exploit.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

identity access

Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

identity access

Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts

Hackers exploited Meta's artificial intelligence (AI) customer support bot to reset passwords on high-value Instagram accounts, including those of the Obama White House and the U.S. Space Force's Chief Master Sergeant, by spoofing geographic location with a virtual private network (VPN) and manipulating the bot into adding attacker-controlled email addresses. The attack vector circulated on Telegram starting May 31, demonstrating a straightforward social engineering technique against an automated system designed to streamline account recovery. Meta deployed an emergency patch over the weekend and confirmed no backend database was breached.

Why it matters: Instagram users with valuable accounts or administrative access face credential compromise if they lack multifactor authentication (MFA); practitioners should evaluate whether conversational AI systems handling account recovery introduce uncontrolled security gaps and ensure MFA enforcement across all accounts.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary