Observed Signal · Jun 1, 2026 · Security Incident · Source: techcrunch · Impact: 4/5 · Sentiment: Negative
Hackers Used Meta AI Chatbot to Hijack Instagram Accounts
Instagram patched a security flaw that let attackers hijack accounts by tricking Meta’s AI-powered support chatbot into adding an attacker-controlled email and initiating a password reset. Reddit and X users reported multiple compromises over the weekend, including the dormant Obama-era White House Instagram handle, the account of U.S. Space Force chief master sergeant John Bentinvegna, and security researcher Jane Wong. A published video showed attackers using a VPN to spoof location, having the chatbot send a verification code to the attacker’s email, then using the bot’s interface to reset the password. TechCrunch verified the attacker email in the video received the verification code. Instagram spokesperson Andy Stone said the issue was fixed; Meta did not provide additional comment to TechCrunch.
A security vulnerability in a major social platform’s AI support chatbot enabled account takeovers, posing risks to user and creator account integrity and trust on a walled-garden platform used widely for advertising and influencer activity.
Track Meta Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Instagram fixed a vulnerability that allowed account takeovers via Meta’s AI support chatbot.
- Attackers allegedly tricked the Meta AI Support Assistant into adding an attacker-controlled email, receiving a verification code, and enabling a password reset.
- Compromised accounts reported included the Obama-era White House Instagram handle, U.S. Space Force chief master sergeant John Bentinvegna, and researcher Jane Wong.
- Attackers reportedly used a VPN to spoof the victims’ locations to avoid triggering automated protections.
- TechCrunch verified that the hacker email shown in a public video received the verification code; Instagram spokesperson Andy Stone confirmed the issue was fixed on June 1, 2026.
Connected Companies & Entities
3 Entities mappedOntology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Hackers Used Meta's AI Support to Hijack Instagram Accounts
In March 2026 Meta rolled out an AI-powered support feature on Facebook and Instagram to assist with account issues such as password resets. Security researchers report that attackers exploited the AI support chatbot by requesting an email change for targeted accounts; the chatbot sent a verification code to the attacker, who then completed a password reset and gained full access. The method circulated in Telegram groups since late March 2026 and was used to take over several high-profile profiles, including Barack Obama and a Chief Master Sergeant from the U.S. Space Force. Attackers reportedly used VPN-based location spoofing to avoid detection. Meta told 404Media it has fixed the vulnerability and is helping affected users regain access.
Instagram Alerts Victims After Meta AI Chatbot Hacks
A widespread campaign exploited Meta’s AI support chatbot to take over Instagram accounts by convincing the bot to link targets to attacker-controlled emails, allowing password resets. Meta said it fixed the issue but continued reports and Telegram discussions suggested the technique persisted and that some hacked short “OG” handles were being resold. Meta secured affected accounts, began sending password-reset emails and notifications to people it determined were targeted, and declined to disclose how many users were impacted. Reported targets included high-profile and dormant accounts; TechCrunch and other outlets documented examples and social complaints. The incident raises concerns about automated account-recovery tooling and the risks of delegating critical support actions to conversational AI systems.
Instagram password-reset emails spark phishing fears
Over the weekend, millions of Instagram users received password-reset emails they did not initiate, prompting security experts to warn of potential phishing and fraud. Malwarebytes highlighted a purported dataset tied to around 17.5 million Instagram accounts that was offered for sale on the dark web, reporting that it could include usernames, email addresses, phone numbers, and some physical addresses. Instagram acknowledged the issue but denied a data breach or unauthorized access to accounts, saying users can ignore the emails and that passwords were not automatically changed. Security researchers caution that even without a breach, circulating data can fuel phishing attempts. Instagram advised a cautious approach and recommended steps to protect accounts: enable two-factor authentication, review logged-in devices in the Meta Accounts Center, consider changing passwords, and avoid clicking links in suspicious emails. Some observers noted the possibility that older datasets are resurfacing rather than a fresh incident.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
