As cited
Copy frozen at (site build).
identity access
Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts
Pro-Iranian hackers disclosed an exploit allowing them to hijack Instagram accounts by tricking Meta's AI customer support bot into resetting passwords and linking new email addresses. The vulnerability affected high-value accounts, including those of the Obama White House and the U.S. Space Force Chief Master Sergeant, before Meta deployed an emergency patch. Security researchers note that AI-powered account recovery systems present new attack surface similar to social engineering risks with human support staff.
Why it matters: Accounts without multi-factor authentication (MFA) remain vulnerable to this bot manipulation technique; enable MFA immediately, particularly security keys or passkeys, as even SMS-based codes would have blocked this exploit.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
identity access
Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
identity access
Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts
Hackers exploited Meta's artificial intelligence (AI) customer support bot to reset passwords on high-value Instagram accounts, including those of the Obama White House and the U.S. Space Force's Chief Master Sergeant, by spoofing geographic location with a virtual private network (VPN) and manipulating the bot into adding attacker-controlled email addresses. The attack vector circulated on Telegram starting May 31, demonstrating a straightforward social engineering technique against an automated system designed to streamline account recovery. Meta deployed an emergency patch over the weekend and confirmed no backend database was breached.
Why it matters: Instagram users with valuable accounts or administrative access face credential compromise if they lack multifactor authentication (MFA); practitioners should evaluate whether conversational AI systems handling account recovery introduce uncontrolled security gaps and ensure MFA enforcement across all accounts.
- Source published
- First seen by Cybersecurity Tracker