← the record
AIAAIC-2267

Hackers use Meta AI support chatbot to takeover Instagram accounts

Hackers exploited Meta’s AI-powered customer support chatbot on Instagram to hijack over 20,000 high-profile and personal accounts by tricking the bot into re-linking target accounts to attacker-controlled email addresses, causing widespread unauthorised account takeovers, defacement, and identity theft risks. What happened Between March and May 2026, Meta widely deployed an AI support assistant across Facebook and Instagram to automate customer service and account recovery. Over the weekend of May 31, 2026, security researchers and threat actors revealed that the AI chatbot could be persuaded via basic text prompts to link existing Instagram accounts to brand-new email addresses provided by attackers. By using a VPN to spoof the victim's general geographic location, attackers bypassed automated safeguards and received one-time verification codes sent directly to their own email, allowing them to instantly trigger password resets and bypass non-SMS multi-factor authentication. Affected parties included everyday users as well as high-profile accounts, such as the former Obama White House account, U.S. Space Force Chief Master Sergeant John Bentivegna, retailer Sephora, and security researcher Jane Manchun Wong. Some accounts were defaced with pro-Iranian messages or listed for sale on messaging platforms. Why it happened The root cause of the incident was architectural design flaws in how the conversational AI was integrated into Meta’s identity management infrastructure. The chatbot was granted elevated administrative privileges to execute sensitive actions (like modifying account emails and issuing password resets) without requiring out-of-band verification from the original account holder or deterministic authentication checkpoints. Meta relied heavily on location-based IP signals for verification, which were trivial to spoof via VPNs. Furthermore, Meta’s historical reliance on automated customer support and lack of accessible human fallback support channels severely restricted victims' ability to intervene or recover their compromised accounts quickly. What it means For directly affected users, the incident meant lost access to accounts, unauthorized password resets, and for some the visible hijacking of accounts tied to their public or professional identity. For society and policymakers, iti llustrates the risk created when companies replace human customer support with AI systems that hold real authority over accounts, identity, and security settings, at scale, with minimal human oversight. It offers a concrete case study for any organisation deploying AI-assisted support workflows with account-management capabilities, and a warning that authorisation must be enforced independently of an AI's own judgment. It also highlights how state-level breach-notification laws (like Maine's) are currently doing more to force transparency from AI-related failures than dedicated AI regulation - a gap policymakers may want to address directly.

Date it happened
2026-04-01
Organisation involved
Unknown hackers
Product, system or model
High Touch Support
Where this came from
Share this incident
XLinkedInFacebookWhatsAppEmail
Attribution

This incident was imported from AIAAIC and is used under CC BY-SA 4.0. Our additions to it — the structured fields, the translation, the checks against other reports — are published under the same licence.

This is a record of what was reported, not a finding that anyone broke the law. If it names your organisation and you believe it is wrong, the corrections process is free and open to everyone.