Meta AI Support Bot Helped Hackers Hijack Instagram Accounts - MacRumors
Skip to Content

Meta AI Support Bot Helped Hackers Hijack Instagram Accounts

Meta's AI support assistant has been helping hackers get access to high-profile Instagram accounts, according to reports on social media. With no verification check, Meta AI would change the email address associated with an Instagram account, allowing the password to be updated.

meta ai
Meta introduced its AI support assistant back in December with the aim of making it easier for customers to access 24/7 account support. It can be used for reporting scams, getting information on content removal, and resetting passwords. The latter option is what bad actors were able to exploit.

The Instagram vulnerability showed up on social media over the weekend, with demonstrations of the simple steps taken to get access to an account. In one demo, a hacker asks Meta's support bot to change the email address linked to a target Instagram account, and the AI does it without question.

Meta's support did not do robust identity verification, and in some cases, it appears it bypassed two-factor authentication. All that was required was a VPN connection set to a location near the target account, which is trivial. Meta appeared to be verifying account ownership based on location. "Our systems recognize the device you usually use and familiar locations better than ever," reads Meta's blog post on its AI support agent. In some cases, users were asked to verify their identity with a selfie, which was bypassed using AI.

For a short period of time, the exploit was available to the public, and account takeovers ramped up. One security researcher said Telegram channels that offer black market Instagram services "made lots of $$$" with Meta's AI. 404 Media said hackers have been aware of the exploit since March.

Meta patched the issue over the weekend, and today, Meta's VP of communications Andy Stone said the issue has been fixed. Meta is now "securing impacted accounts."

Information about the Instagram attack vector comes after hackers were able to take over accounts for Sephora, the Chief Master Sergeant of the Space Force, researcher Jane Manchun Wong, developer Albert Renshaw who owned @albert, and the archived Barack Obama White House account. Multiple other users with desirable Instagram handles reported having their accounts taken.

Some users who have had their accounts stolen over the weekend were not able to use the AI to get their accounts back, and there was no option to speak with a human for help.

Popular Stories

Instagram Feature 2

PSA: Instagram Encrypted Messaging Ends on Friday, May 8

Tuesday May 5, 2026 8:24 am PDT by
Instagram will remove end-to-end encryption for direct messages between users from May 8, 2026. When the date comes around, Meta will potentially be able to see the contents of all messages between users on the social media platform. Encrypting messages has been an optional feature in Instagram since 2023, but in March of this year the social media platform quietly updated a help page to say ...
Instagram Feature 1

Warning: Instagram DMs Lose End-to-End Encryption Starting Today

Friday May 8, 2026 12:37 pm PDT by
As of today, end-to-end encryption for Instagram direct messages is no longer available. DMs that you send to people on Instagram will no longer feature full encryption, and your conversations are not protected from Meta. Meta can potentially see what's in messages shared between users on Instagram, and that information can be shared with law enforcement agencies worldwide. End-to-end...
meta instants

Meta Launches 'Instants' App for Sharing Disappearing Photos on Instagram

Wednesday May 13, 2026 11:32 am PDT by
Meta today announced the launch of Instants, a new image sharing option on the Instagram social network. Instants are ephemeral photos that disappear from Instagram after they're viewed by a user's friends or after a 24-hour period. Reactions and replies to Instants images show up in DMs instead of on the post. Instants photos are only displayed for a short period, but they are saved to a...

Top Rated Comments

awshucks Avatar
45 minutes ago at 03:30 pm
Wow. This is such a sorry lack of precaution that even I'm surprised.
Score: 4 Votes (Like | Disagree)
teaneedz Avatar
40 minutes ago at 03:36 pm
hilarious...but is it really unexpected? this is just the tip of the iceberg as more mainstream folks encounter the 'great' AI world we now live in. 🍿
Score: 3 Votes (Like | Disagree)
error Avatar
44 minutes ago at 03:31 pm
This is why everybody loves AI support.
Score: 3 Votes (Like | Disagree)
BeatsByTim Avatar
26 minutes ago at 03:50 pm
Puts a smile on my face.
Score: 2 Votes (Like | Disagree)
Mr_Brightside_@ Avatar
45 minutes ago at 03:30 pm
You’ve gotta love the VP updating on X.
Score: 2 Votes (Like | Disagree)
Kirkster Avatar
6 minutes ago at 04:09 pm
LololoL. Meta hacking meta.
Score: 1 Votes (Like | Disagree)