• Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
Blog - Creative Collaboration
No Result
View All Result
Home Gadgets

Hackers asked Meta’s AI chatbot to hand over Instagram accounts, and it did

June 3, 2026
Share on FacebookShare on Twitter

TL;DR

Hackers hijacked high-profile Instagram accounts by asking Meta’s AI support chatbot to change account email addresses without identity verification. Meta says the flaw is fixed, but attacks reportedly continued after the company’s announcement.

No phishing link. No malware. No SIM swap. Hackers took over high-profile Instagram accounts over the weekend by doing something disarmingly simple: they asked Meta’s AI customer support chatbot to change the email address on someone else’s account. The bot complied without verifying the requester’s identity, and the attacker then reset the password and locked out the rightful owner.

The technique, which was first reported by 404 Media, spread through Telegram channels where hackers shared the method and began advertising stolen handles for sale. Among the compromised accounts were the dormant Obama White House Instagram profile, which was used to post unauthorised AI-generated images, and the account of US Space Force chief master sergeant John Bentivegna.

Meta spokesperson Andy Stone said on Monday that “the issue that did happen has already been fixed.” But on Tuesday, more Instagram users reported losing access to their accounts, and members of the same Telegram channels claimed the exploit still worked, according to TechCrunch.

How the attack worked

The method exploited a flaw in Meta’s AI Support Assistant, which the company rolled out in March 2026 with the ability to “resolve account issues from start to finish,” including resetting passwords. The chatbot was designed to replace human support agents for routine account recovery tasks.

The 💜 of EU tech

The latest rumblings from the EU tech scene, a story from our wise ol’ founder Boris, and some questionable AI art. It’s free, every week, in your inbox. Sign up now!

An attacker would identify a target account, typically a short “OG” username worth thousands on underground markets. They would use a VPN to spoof the target’s presumed location, open a chat with the AI support bot, and simply claim to be the account owner. The bot would then link the attacker’s email address to the target account without asking for any proof of ownership.

A human support agent would have verified the caller’s identity before making such a change. The chatbot did not. Two-factor authentication may have blocked some takeovers, but accounts without it enabled were vulnerable to compromise in minutes.

A grey market for stolen handles

For years, a flourishing underground market has existed for so-called OG usernames, the short, desirable handles claimed by Instagram’s earliest users. Previous methods of stealing them required technical sophistication: phishing the victim, bribing telecom insiders to perform SIM swaps, or compromising email accounts.

This attack lowered the barrier to entry dramatically. The hackers who shared the technique on Telegram were advertising apparently stolen handles for sale, including common forenames and country names that function as collectibles in this grey market. TechCrunch reported that the sales continued even after Meta’s announced fix.

Meta scrambles to notify victims

Meta has been sending password reset emails and security notifications to users whose accounts were targeted. Several victims reported receiving messages from Instagram warning that the company had “detected some suspicious activity that suggests your Instagram may have been compromised,” along with instructions to reset their passwords.

Stone told TechCrunch that Meta secured affected accounts on Monday before beginning its notification campaign. He declined to say how many users were compromised. Meta also disputed that the Obama White House account was taken over using this specific method, though it confirmed the account was hacked.

The cost of automating trust

The incident exposes a fundamental tension in deploying AI agents with real-world authority. Meta built its support chatbot to perform actions that previously required a human in the loop, but it shipped that capability without the verification checks that human agents would have applied as a matter of course.

It is a pattern the industry has seen before. When Instagram account recovery was handled by humans, the process was slow and often frustrating, but it at least required the requester to prove they were who they claimed to be. Automating that process without preserving the identity-verification step turned a bottleneck into a vulnerability.

The broader lesson is not that AI should never handle sensitive account operations, but that authentication remains a problem no chatbot can shortcut. Meta gave its AI the power to hand over the keys. The hackers simply walked up and asked for them.

Next Post

CoD Season 4 Patch Notes Detail SG-12 Nerf, Anti-Cheat Updates, And More

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

No Result
View All Result

Recent Posts

  • Amazon Music Unlimited free trial: Get 4 months for free ahead of Prime Day
  • Barcelona-Catalunya GP 2026 livestream: How to watch F1 for free
  • US government forces Anthropic to pull its advanced AI models
  • The best robot vacuums of 2026 so far after testing 10+ at home
  • 42 state AGs probe OpenAI days after IPO filing

Recent Comments

    No Result
    View All Result

    Categories

    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi
    • Home
    • Shop
    • Privacy Policy
    • Terms and Conditions

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    No Result
    View All Result
    • Home
    • Blog
    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    Get more stuff like this
    in your inbox

    Subscribe to our mailing list and get interesting stuff and updates to your email inbox.

    Thank you for subscribing.

    Something went wrong.

    We respect your privacy and take protecting it seriously