Hackers use Meta AI support chatbot to hijack Instagram accounts
Hackers use Meta AI support chatbot to hijack Instagram accounts
Occurred: April 2026
Page published: July 2026
Hackers exploited Meta’s AI-powered customer support chatbot on Instagram to hijack over 20,000 high-profile and personal accounts by tricking the bot into re-linking target accounts to attacker-controlled email addresses, causing widespread unauthorised account takeovers, defacement, and identity theft risks.
Between March and May 2026, Meta widely deployed an AI support assistant across Facebook and Instagram to automate customer service and account recovery.
Over the weekend of May 31, 2026, security researchers and threat actors revealed that the AI chatbot could be persuaded via basic text prompts to link existing Instagram accounts to brand-new email addresses provided by attackers.
By using a VPN to spoof the victim's general geographic location, attackers bypassed automated safeguards and received one-time verification codes sent directly to their own email, allowing them to instantly trigger password resets and bypass non-SMS multi-factor authentication.
Affected parties included everyday users as well as high-profile accounts, such as the former Obama White House account, U.S. Space Force Chief Master Sergeant John Bentivegna, retailer Sephora, and security researcher Jane Manchun Wong.
Some accounts were defaced with pro-Iranian messages or listed for sale on messaging platforms.
The root cause of the incident was architectural design flaws in how the conversational AI was integrated into Meta’s identity management infrastructure.
The chatbot was granted elevated administrative privileges to execute sensitive actions (like modifying account emails and issuing password resets) without requiring out-of-band verification from the original account holder or deterministic authentication checkpoints.
Meta relied heavily on location-based IP signals for verification, which were trivial to spoof via VPNs.
Furthermore, Meta’s historical reliance on automated customer support and lack of accessible human fallback support channels severely restricted victims' ability to intervene or recover their compromised accounts quickly.
For directly affected users, the incident meant lost access to accounts, unauthorized password resets, and for some the visible hijacking of accounts tied to their public or professional identity.
For society and policymakers, iti llustrates the risk created when companies replace human customer support with AI systems that hold real authority over accounts, identity, and security settings, at scale, with minimal human oversight. It offers a concrete case study for any organisation deploying AI-assisted support workflows with account-management capabilities, and a warning that authorisation must be enforced independently of an AI's own judgment. It also highlights how state-level breach-notification laws (like Maine's) are currently doing more to force transparency from AI-related failures than dedicated AI regulation - a gap policymakers may want to address directly.
High Touch Support
Developer: Meta
Country: Global
Sector: Media/entertainment/sports/arts
Purpose: Provide customer support
Technology: Generative AI
Issue: Accountability; Privacy/surveillance; Security; Transparency
Harm: Identity theft; Privacy loss; Reputational damage
March 2026. Meta rolls out its AI-powered "High Touch Support" assistant across Facebook and Instagram.
April 17, 2026. Exploitation of the flaw begins, according to Meta's later breach notification.
~May 29, 2026 Meta patches the underlying vulnerability.
May 31-June 1, 2026. Wave of high-profile Instagram account takeovers becomes public, reported first by 404 Media and TechCrunch.
June 1–2, 2026. Meta says the issue has been fixed; more users report hacked accounts the following day, and hackers claim continued success.
June 5, 2026. Meta notifies the Maine Attorney General's office that more than 20,000 accounts may have been affected.
June 8-9, 2026. Meta's filing becomes public, confirming 20,225 affected accounts; Meta begins notifying impacted users.
AIAAIC Repository ID: AIAAIC2267