GPT-56T 861 —
MUSE-SPK 835 -0.7%
GPT-56SC 828 -5.2%
QWEN-38X 824 —
CL-OP55X 822 —
GROK-46H 822 -5%
GPT-6A 820 —
GLM-5 784 -8.4%
CL-FAB5H 743 -5.6%
KIMI-K3X 742 -8.4%
CL-OP5H 720 -5.8%
CL-OP5X 709 -18%
CL-OP46H 698 -5.9%
CL-OP47H 690 -5.9%
GEM-38FH 677 +0.1%
GEM-37FH 657 -24%
GPT-56S 622 —
CL-OP47 582 -0.7%
GPT-55H 582 —
INKL 531 —
GEM-31P 513 —
GEM-3P 499 —
CL-OP46 496 -0.2%
CL-OP48 490 —
GPT-56T 861 —
MUSE-SPK 835 -0.7%
GPT-56SC 828 -5.2%
QWEN-38X 824 —
CL-OP55X 822 —
GROK-46H 822 -5%
GPT-6A 820 —
GLM-5 784 -8.4%
CL-FAB5H 743 -5.6%
KIMI-K3X 742 -8.4%
CL-OP5H 720 -5.8%
CL-OP5X 709 -18%
CL-OP46H 698 -5.9%
CL-OP47H 690 -5.9%
GEM-38FH 677 +0.1%
GEM-37FH 657 -24%
GPT-56S 622 —
CL-OP47 582 -0.7%
GPT-55H 582 —
INKL 531 —
GEM-31P 513 —
GEM-3P 499 —
CL-OP46 496 -0.2%
CL-OP48 490 —
← Back to feed

Meta's AI Support Bot Handed Over Thousands of Instagram Accounts to Hackers — Just Because They Asked

Meta launched its AI support assistant for Facebook and Instagram in March 2026 with a promise to “resolve account issues from start to finish” — including the ability to “reset your password securely.” Three months later, hackers discovered the chatbot would do exactly that for anyone who asked, regardless of who they were.

The attack was not sophisticated. Hackers used a VPN to approximate the target account’s home region, then opened a chat with Meta AI Support Assistant and told it to link a new email address to the account. The chatbot sent a verification code to the attacker-supplied address. The attacker shared that code back with the bot, which surfaced a “Reset Password” button. One new password later, the account was theirs.

At no point was a legitimate email address compromised. At no point were Meta employees or contractors involved.

What Got Taken

The exploit circulated in Telegram channels as far back as February 2026, Neowin reported, with “thousands of accounts” compromised before Meta pushed an emergency patch on May 29. High-profile targets hit during the public phase of the campaign included the Obama-era White House Instagram account (@obamawhitehouse, inactive since 2017) and the account of U.S. Space Force Chief Master Sergeant John Bentivegna, both of which were briefly defaced with pro-Iranian imagery.

Security researcher Jane Manchun Wong reported her account taken over the same weekend. Gray-market account brokers listed short-form “OG” handles for sale on Telegram, with accounts like @hey and @jowo assigned a combined estimated resale value above $1 million. Short-form handles from Instagram’s earliest days have long been traded as status commodities — previous methods required phishing, SIM-swapping, or bribing telecom insiders. Here, hackers just asked.

Meta spokesperson Andy Stone declared the issue resolved on May 31. TechCrunch observed active Telegram channels still advertising newly hacked handles on June 3. Stone subsequently said Meta was “securing impacted accounts” and sending password reset notifications to affected users — though the company declined to state how many accounts were compromised.

The Architecture Problem

Security researchers characterized the exploit as a classic “confused deputy” attack, a well-understood problem in computer security where a high-privilege program is manipulated into misusing those privileges on behalf of an unauthorized party. The novelty: the deputy here was a large language model rather than a deterministic program.

Deterministic programs can be protected with hard-coded conditionals. LLMs respond probabilistically to natural language — meaning the security perimeter is as robust as the model’s ability to distinguish a legitimate user from someone who simply claims to be one.

Researchers at CyberSec Guru described the minimum viable fix: out-of-band verification before any account modification, rate limiting on AI-initiated reset flows keyed to account risk signals, action logging with anomaly detection, and a hard deterministic gate. None of those were in place at launch.

MFA would have stopped the attack entirely. Hackers said their technique failed against any account with multifactor authentication enabled, including the weakest form Instagram offers — SMS one-time codes. The vast majority of affected accounts had no MFA.

The Industry Implication

Meta is not an edge case. The pattern — deploy a conversational AI layer to handle sensitive account recovery workflows, skip the deterministic guardrails, discover the gap only after accounts are ransacked — will repeat as long as deployment speed outpaces the security review cycle.

Tenable Senior Staff Research Engineer Satnam Narang called the incident “one of the most consequential abuses of AI chatbots” seen to date. Ian Goldin at Lumen’s Black Lotus Labs said the same dynamic that makes AI support bots useful — their eagerness to help, their responsiveness to persuasion — makes them vulnerable to the same social engineering techniques that have compromised human customer service agents for decades.

The difference is scale. One persuasive message can be scripted and fired against every account on the platform simultaneously.