AI Is Going Just Great
← Timeline
·3d agoScaryMajormeta

Hackers hijacked Instagram accounts by social-engineering Meta's AI support chatbot

Published · updated · curated by AI Is Going Just Great

Source: techcrunch.com

"The password got changed without my knowledge and I was getting different password reset attempts throughout yesterday. Quite concerning." — Security researcher Jane Wong

Over the weekend of May 31–June 1, 2026, attackers discovered they could trick Meta's AI-powered support chatbot into adding a hacker-controlled email address to a victim's Instagram account — no access to the victim's real email required. The exploit involved spoofing a target's location via VPN, then simply asking the chatbot to register a new email, receiving a verification code, and using the bot's own "Reset Password" flow to lock the legitimate owner out. Victims included the dormant Obama White House Instagram account, the U.S. Space Force's chief master sergeant, and security researcher Jane Wong.

TechCrunch independently verified the attack by confirming that a verification code appeared in the hacker's public mailbox as shown in a step-by-step video posted to X. Instagram's spokesperson Andy Stone said the issue was fixed Monday, but the total number of compromised accounts remains unknown. The attack required zero technical sophistication beyond knowing how to open a chat window — the chatbot did the rest.