Vulnerability  ·  2026-06-03

Meta AI Support Bot Social-Engineered to Add Attacker Email in Password-Reset Flow, Enabling Instagram Account Takeover

VulnerabilityHigh impactGlobal
Pro-Iran threat actors exploited Meta's AI customer support assistant during Instagram account recovery flows. By connecting via a VPN with a geolocation near the target's home city, requesting a password reset, and then chatting with the AI bot, attackers instructed the bot to add a new attacker-controlled email address to the account. The bot complied and sent a one-time reset code to the attacker's email, enabling full account takeover. High-value accounts including the Obama White House Instagram and the Chief Master Sergeant of the U.S. Space Force were briefly hijacked. Meta confirmed the issue and pushed an emergency patch.
Social engineering of an AI customer support bot via natural-language instruction during a legitimate password-reset flow. No back-end database breach occurred — the attack exploited the bot's willingness to follow user instructions for identity-binding changes without MFA or human review.
Meta Instagram AI support assistant (production deployment). Any AI-driven account-recovery or customer-support bot with authority to make identity-binding changes without MFA verification is vulnerable to this attack class.
Meta has deployed an emergency patch. For platform operators: remove unilateral authority from AI bots for identity-binding changes (email add, phone add, password reset); require strong MFA (passkey or hardware security key) before any recovery workflow completes; route anomalous recovery requests (new IP, new email, VPN geolocation) to human review. Users: enable MFA on all high-value accounts. Note: the Telegram-circulated exploit video confirmed it failed against any account with MFA enabled.
Sources
Krebs on Security — Hackers Used Meta's AI Support Bot to Seize Instagram AccountsSecurityWeek — Meta Says 20,000 Instagram Accounts Hacked via AI Tool AbuseMaine Attorney General — Meta Platforms Data Breach NoticeInfosecurity Magazine — Meta AI Bug Exposes Over 20,000 Instagram Accounts
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →