When AI becomes a risk: how Meta’s support chatbot enabled the hijacking of Instagram accounts

For years, major tech platforms have promoted AI-powered automation as a way to reduce costs, speed up processes, and improve the user experience. However, an incident recently confirmed by Meta has exposed one of the biggest risks of delegating critical security functions to AI-based systems: the ability to execute sensitive actions without adequately validating the identity of the requester.

In late May and early June 2026, various security researchers, journalists, and users began reporting a series of Instagram account hijackings that initially appeared to be conventional attacks. However, the reality turned out to be far more concerning when the attackers were not exploiting a traditional technical vulnerability, stealing credentials through phishing, or compromising Meta’s servers. Instead, they were using the company’s own AI-powered support assistant to gain access to other people’s accounts.

The origin of the problem

Meta had deployed an AI-based support assistant capable of performing certain actions related to account management, including access recovery processes and password resets. The intention was to streamline user support and reduce the need for human intervention.

The problem lay in the fact that the system apparently had sufficient privileges to modify information associated with an account and execute access recovery flows, but without implementing robust authentication controls before performing such actions.

According to investigations published by various specialized media outlets, the attackers discovered that they could convince the chatbot to associate an email address controlled by them with an Instagram account that did not belong to them. Once that association was made, the system itself sent verification codes to the attacker’s email and subsequently allowed them to initiate a password reset.

In practical terms, the AI acted as if it automatically assumed that the person it was conversing with was the legitimate owner of the account.

How the attack worked

The reports agree on a relatively simple sequence:

Technical flow of the attack

Most concerning is that the process did not require prior access to the victim’s legitimate email or the exploitation of malware or complex vulnerabilities. In many cases, a carefully crafted conversation with the automated assistant was enough.

What type of attack was applied here?

Most of the social media posts have described this incident as a case of “Prompt Injection.” Although technically the term has become popular for describing attacks that manipulate the behavior of language models through specially designed instructions, several experts believe the main problem here was more serious: a design flaw in the authorization controls.

The AI was not only manipulated through natural language; it also had sufficient privileges to execute critical changes to real accounts.

From a security perspective, the incident can be interpreted as a combination of:

  • Lack of strong identity validation.
  • Insufficient authorization controls.
  • Excess privileges granted to the AI assistant.
  • Excessive reliance on decisions made by a generative model.
  • Absence of deterministic verifications before executing sensitive actions.

The affected accounts

The attacks were not limited to ordinary users. Various reports indicate that high-profile accounts with significant commercial or media value were compromised.

Among the most notable are:

  • The former White House account corresponding to the Obama administration (@obamawhitehouse).
  • The account of the Chief Master Sergeant of the United States Space Force.
  • Accounts associated with Sephora.
  • Various users with extremely valuable usernames within the Instagram underground market.
  • Security researcher Jane Manchun Wong, who publicly confirmed being affected.

Account recovery abuse

In some cases, the hijacked accounts were used to publish political propaganda and AI-generated images before being recovered.

Meta has not publicly disclosed the exact number of affected accounts. The company confirmed the existence of the problem and stated that the vulnerability had been fixed, but did not provide details about the actual scope of the incident.

This lack of transparency has generated criticism among researchers and cybersecurity specialists, especially because the attacks appeared to have been occurring for weeks or even months before the problem was publicly addressed.

What this incident reveals about AI security

Beyond Instagram, this case represents a warning for the entire tech industry.

Over the past two years, numerous organizations have begun integrating AI assistants with permissions to manage accounts, approve requests, make administrative changes, process transactions, and manage digital identities. The problem is that language models were not originally designed as authentication mechanisms or access control systems. They are excellent at interpreting human language, but can be extremely vulnerable when given operational privileges without external validation mechanisms.

Real risk of AI with elevated privileges

In computer security, there is a fundamental principle: authentication should never depend on a conversation. Critical decisions must be backed by deterministic controls, cryptographic verifications, multi-factor authentication, and mechanisms independent of the model’s reasoning.

The Meta incident demonstrates that an AI-based assistant can inadvertently become an intermediary to execute actions that would normally be protected by multiple layers of security.

Meta’s response

Meta confirmed that the problem was fixed and stated that there was no breach of its internal systems. According to the company, the incident was limited to a failure in the account recovery flow managed by the AI assistant. It also indicated that it was working to secure the affected accounts.

However, for many experts, the discussion no longer revolves solely around whether or not there was a traditional breach, but around the fact that an automated system with elevated privileges could be persuaded to perform actions that should never have depended on a natural language conversation.

Lesson learned

Conclusion

The Instagram incident was not the result of a sophisticated vulnerability or an advanced malware campaign. It was the consequence of a deeper problem: granting an artificial intelligence the ability to execute critical actions without sufficiently strict identity controls.

The lesson for the industry is clear. AI can speed up support processes, automate tasks, and improve the user experience, but when granted privileges to modify accounts, reset passwords, or manage digital identities, it must operate under independent and verifiable security mechanisms. Otherwise, a simple conversation can become an access path to compromise millions of accounts.

Additional information: