Cybersecurity

Meta AI Support Bot Let Hackers Steal Instagram Accounts

Hackers told Meta's AI support bot an account was theirs; the bot complied and linked attacker emails. Meta says the flaw is fixed and is notifying targeted users.

Meta AI Support Bot Let Hackers Steal Instagram Accounts — article cover

On June 1, 2026, 404 Media reported an attack technique that sounds almost absurd in its simplicity: hackers walked into Meta’s AI customer support chatbot, claimed they owned a target’s Instagram account, and asked the bot to link that account to an email address the hackers controlled. The bot complied. No Meta employee or contractor was ever in the loop, and victims could not find a way to escalate to a human.

Two days later, on June 3, TechCrunch reported that Instagram had started sending notifications to targeted users, telling them Meta had “detected some suspicious activity that suggests your Instagram may have been compromised.” The incident drags an architecture decision the industry is racing to adopt into plain view: when you give an AI agent the authority to recover accounts and reset passwords, the strength of its identity checks becomes the ceiling on your entire system’s security.

The Attack: Social Engineering a Chatbot

The technical sophistication required was close to zero. According to videos and screenshots circulating in Telegram hacking groups that 404 Media reviewed, attackers sent the support bot the target’s username along with their own email — roughly, “just link my new email address, this is my username” — then supplied a verification code, and the bot completed the binding. From there, a password reset locked out the real owner.

The context matters. In March 2026, Meta rolled out AI support across Facebook and Instagram, marketing it as delivering “solutions, not just suggestions” and able to resolve account issues “from start to finish,” including securely resetting your password. In other words, the agent was explicitly designed to perform account-level sensitive operations. Its identity verification, evidently, never matched that authority — and victims had no option to demand a human.

High-Profile Victims and the OG Handle Market

The victim list explains the blast radius. The dormant Obama White House Instagram account was reportedly compromised around May 31 (Meta disputes that account of events). The official account of Chief Master Sergeant John Bentivegna of the U.S. Space Force — the branch’s top enlisted guardian — was taken over by pro-Iran hackers for several hours on the evening of May 31, who posted pro-Iranian artwork and stories before the content was removed by 1 a.m. ET Monday; a Space Force spokesperson confirmed the compromise. Sephora’s account was also reported hit.

Most targets were ordinary users. The motive is the long-running gray market for “OG handles” — short usernames like common first names and country names — which command real prices. Hackers traded techniques and advertised stolen handles in a Telegram channel, while a steady stream of users complained publicly on X about losing their accounts.

Meta’s Response and the Open Questions

Meta spokesperson Andy Stone said Monday that “the issue that did happen has already been fixed,” and followed up that “some people may receive password reset notifications,” with security questions awaiting others at login. Meta secured the affected accounts on Monday, then sent the password reset emails — the wave of notifications covered in press reports on June 3.

Two questions remain unanswered. First, Meta declined to say how many users were hit; no figure exists anywhere. Second, at TechCrunch’s publication time, hackers in the Telegram channel were still discussing the technique and advertising stolen handles for sale, and TechCrunch noted it is hard to confirm every reported takeover used the same method. “Fixed” is, for now, Meta’s word alone.

Lessons for Anyone Building AI Support Agents

Every team wiring an LLM into a support flow should read this incident closely. Lesson one: authority must be paired with verification. An agent that can rebind email addresses and reset passwords needs identity proof as strong as a human agent would require — “the user said it was theirs” is not authentication, and prompt-based social engineering scales infinitely. Lesson two: “no path to a human” is a design flaw. Victims told 404 Media there was no escalation option, which let attacks complete silently. Lesson three: sensitive agent actions need anomaly detection. An account getting its email rebound and its password reset within minutes should trip an interlock, whoever — or whatever — approved it.

Zoom out and this is a squeeze on AI security from both directions. The same week, Anthropic’s analysis of AI-enabled cyber threats showed attackers pulling AI into the later stages of attack chains. Meta has now shown the mirror image: AI agents on the defense side are attack surface too. The perimeter is widening on both ends at once.

Sources

AI-assisted summary compiled from the sources above, reviewed by a human before publishing.

FOUND_THIS_USEFUL?

Support more practical AI articles, tutorials, and build notes.

BUY_ME_A_COFFEE
SHAREXEMAIL