Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts

0
Medium
Vulnerabilityrce
Published: 06/01/2026 (06/01/2026, 17:32:50 UTC)
Source: Krebs on Security

Description

Hackers exploited a vulnerability in Meta's AI support assistant bot used for Instagram account recovery to hijack high-profile accounts, including those of the Obama White House and the U.S. Space Force Chief Master Sergeant. The attackers tricked the AI bot into linking a new email address to targeted accounts, enabling password resets and account takeovers. The exploit relied on using a VPN with an IP address near the victim's usual location and succeeded only on accounts without multi-factor authentication (MFA). Meta responded by deploying an emergency patch and securing impacted accounts.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/18/2026, 22:01:13 UTC

Technical Analysis

This incident involves an abuse of Meta's AI-powered customer support assistant for Instagram account recovery. Attackers used social engineering techniques to convince the AI bot to add a new email address to targeted accounts as part of the password reset process. Once the new email was linked, the bot sent a one-time code to that email, allowing attackers to reset the password and take control of the account. The exploit was demonstrated via a video circulated on Telegram by pro-Iran hackers. Meta confirmed the issue was resolved with an emergency patch and stated no backend database was breached. The vulnerability highlights the new attack surface introduced by AI chatbots handling sensitive account recovery workflows.

Potential Impact

The vulnerability allowed unauthorized attackers to hijack Instagram accounts by manipulating the AI support bot to reset passwords without proper verification. High-value accounts with short usernames were targeted and briefly defaced with pro-Iranian content. The exploit failed against accounts protected by any form of MFA, indicating that accounts without MFA were at risk. Meta confirmed that no backend data breach occurred, limiting the impact to account hijacking via the AI bot's password reset functionality.

Mitigation Recommendations

Meta has deployed an emergency patch to address the vulnerability in the AI support assistant bot and secured impacted accounts. Users are strongly advised to enable multi-factor authentication (MFA) on their Instagram accounts, as the exploit did not succeed against accounts with MFA enabled. No further user action is required to mitigate the vulnerability beyond enabling MFA. Monitor official Meta communications for any additional updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/","fetched":true,"fetchedAt":"2026-06-01T21:58:27.265Z","wordCount":886}

Threat ID: 6a1e0083e29bf47b504d5e28

Added to database: 06/01/2026, 21:58:27 UTC

Last enriched: 06/18/2026, 22:01:13 UTC

Last updated: 07/31/2026, 11:12:49 UTC

Views: 116

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses