Attackers used Meta's AI-powered customer support assistant to hijack Instagram accounts by manipulating the bot's password-reset workflow, according to reporting from security researcher Brian Krebs. Instructions detailing the technique began circulating on Telegram in late May 2026, and hackers used it to briefly deface Instagram accounts tied to the Obama-era White House handle and U.S. Space Force Chief Master Sergeant John Bentivegna with pro-Iranian images and messages.
The exploit worked by connecting through a VPN configured to appear near the target's home location, then requesting a password reset and opening a chat with Meta's AI support assistant. The bot could be instructed to link the account to a new email address of the attacker's choosing, after which it sent a one-time verification code to that address, enabling a full password reset without the attacker ever needing access to the victim's original email account.
Ian Goldin, a threat researcher at Lumen's Black Lotus Labs, said the incident illustrates a new category of risk as more platforms hand sensitive account recovery tasks to conversational AI systems that can be persuaded or tricked in ways similar to human support agents. Meta communications director Andy Stone said on social media that the issue had been resolved and affected accounts secured. A security researcher reported that Meta pushed an emergency patch to close the flaw over the same weekend the exploit surfaced. Accounts protected by multi-factor authentication were not vulnerable to the technique, according to the hackers who documented it on Telegram.
Source: Krebs on Security - https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/
