Safety3 min read

Meta's AI Support Bot Handed Hackers Instagram Account Access

June 5, 2026Synthesized from 6 sources: The Guardian, Ars Technica, Engadget, MIT Technology Review, Simon Willison, The Verge

Meta's AI-powered Instagram support chatbot, rolled out globally in March 2026 with the ability to perform real account changes, was used by hackers to steal hundreds of accounts including a dormant US government profile, with the vulnerability circulating in hacker circles for months before a patch arrived.

Meta spent late 2025 and early 2026 building a case for AI-powered customer support. In December it previewed the concept, promising faster and simpler account recovery. In March it rolled the tool out globally across Facebook and Instagram, marketing it with the line "solutions, not just suggestions." The assistant could reset passwords, relink email addresses, and manage account access, all without a human ever reviewing the request.

That design choice created the opening. A hacker with a free VPN, a target username, and a few minutes of typing could walk the chatbot through a full account takeover. The bot had no way to verify who it was talking to. It treated a location-matched IP address as sufficient proof of identity, sent a verification code to whatever email the hacker provided, and displayed a password reset button once that code was entered. The original owner received no warning at any point.

The flaw was not a sophisticated technical breach. As security researcher Ian Goldin put it, AI chatbots create a new kind of attack surface, and the risk here is essentially the same as socially engineering a human support agent: the bot is designed to be helpful, and it was.

The accounts that drew public attention were striking. The dormant Obama White House Instagram profile, silent since January 2017 and still followed by 2.4 million people, was used to post pro-Iranian propaganda images. The account of US Space Force Chief Master Sergeant John Bentivegna was filled with similar content. Sephora's brand account was also reportedly caught up in the wave.

But the bulk of the theft was commercial, not political. Hackers specifically targeted short, rare Instagram usernames, the kind that carry significant resale value in private online markets. Security researcher Dark Web Informer tracked stolen accounts appearing for sale in Telegram groups in real time, with some batches valued at over half a million dollars combined. The operation was organized and fast: accounts were stolen and resold within minutes.

The vulnerability had been circulating in hacker communities since at least March, according to multiple reports. That means roughly three months passed between the exploit becoming known and Meta patching it on May 29. Meta's public response was terse. Its VP of communications posted a single line: "This issue has been resolved and we are securing impacted accounts." The company's formal statement described it as a flaw that "allowed an external party to request password reset emails," a framing that understates what actually happened.

A complicating detail sits just outside this story. Eleven days before the hacks became public, Meta cut roughly 8,000 jobs, about 10 percent of its entire workforce. Among those let go were members of its integrity team, the group responsible for detecting malicious activity, and staff from its cybersecurity division. Meta has not confirmed any link between those cuts and this incident. No causal connection has been established. But the sequence is visible: the company shed its safety and security headcount, accelerated its push to replace human support with AI, and within two weeks its AI support tool became the entry point for a large-scale account theft operation.

There is a broader point here that goes beyond this specific incident. When a company gives an AI tool the power to make irreversible changes, like changing the email address on an account, the security of the whole system rests entirely on how well that AI can tell a legitimate user from an attacker. Meta's tool could not. Users who lost accounts have reported that there is no way to escalate to a human, meaning the AI that enabled the theft is also the only channel available to try to undo it.

For anyone running a business presence on Instagram or Facebook, the immediate step is simple: enable two-factor authentication using an authenticator app rather than SMS alone. The hackers who published the exploit confirmed it did not work against accounts with that protection active. Dormant accounts, old campaign handles, retired brand pages, any account that carries your name and has followers, are worth the same protection. They have value to someone else even if you have forgotten about them.

Stay informed

Get AI intelligence like this delivered to your inbox.