Skip to content
AttackFeed by Joe Wagner | Cybersecurity News from Across the Internet

AttackFeed by Joe Wagner

Cybersecurity News from Across the Internet

  • Attack/News Feeds
  • Gov Alerts/ISAC Feeds
  • Vulnerability Alerts
  • Privacy/Governance Feeds
  • Fraud Feeds
  • iOS App
  • Android App
  • Home
  • Attack Feeds
  • Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts  – Krebs on Security
AttackFeed by Joe Wagner | Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts  - Krebs on Security

Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts  – Krebs on Security

Posted on June 1, 2026 By BrianKrebs No Comments on Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts  – Krebs on Security
Attack Feeds

The Instagram accounts for the Obama White House and the Chief Master Sergeant of the U.S. Space Force were briefly defaced with pro-Iranian images and messages over the weekend, after instructions began circulating on Telegram showing how to trick Meta’s “AI support assistant” bot into resetting account passwords.

AttackFeed by Joe Wagner | Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts  - Krebs on Security

A screenshot from a video released on Telegram claiming to show how Meta’s AI customer support bot could be tricked into resetting a target’s password.

On May 31, word began to spread on several Telegram instant message channels that Meta’s AI bot would happily add an email address to an existing account as part of the bot’s standard password reset flow.

A video released on Telegram by pro-Iran hackers claimed to document a remarkably simple exploit that appears to have involved using a VPN connection with an IP address that is in or near the target’s usual hometown, requesting a password reset for the account, and then choosing to chat with Meta’s AI support assistant. From there, the video shows the attacker told the bot to link the account in question to a new email address, after which the bot dutifully sent that address a one-time code that allowed a password reset.

The Telegram account that posted the video also linked to screenshots of pro-Iran images, videos and messages that defaced the hacked Instagram accounts, saying hackers had used the exploit to hijack a number of valuable (read: short) Instagram account names that allegedly have a resale value of more than a half million dollars.

Meta has not responded to requests for comment on the video’s claims, but the company reportedly did acknowledge the dormant Instagram account for the Obama White House was briefly compromised. The security blog thecybersecguru.com reports that Meta pushed an emergency patch over the weekend, and clarified that no back end database was breached.

“Instagram has notoriously poor human support infrastructure,” Cybersecguru wrote. “Recovering a locked account – especially a high-value one can take weeks of back-and-forth with an automated ticketing system. Meta’s solution was to deploy a conversational AI layer to handle common recovery workflows: relinking a lost email address, triggering a password reset, verifying account ownership. The assistant, presumably, was supposed to reduce friction for legitimate users stuck in account-access hell.”

Ian Goldin, a threat researcher at Lumen’s Black Lotus Labs, said we’re entering unchartered security territory as more large online platforms start allowing AI chatbots to handle sensitive account recovery requests. Just like human customer support employees can be social engineered into providing unauthorized access to someone’s account, AI bots are equally eager to help and vulnerable to persuasion and trickery, he said.

“AI chatbots create interesting new attack surface, and we’re likely going to see a lot more of these kinds of attacks,” Goldin said.

Securing your various online accounts means taking full advantage of the most secure form of multi-factor authentication (MFA) offered (such as a passkey or security key). In this case, even using the least robust form of MFA that Instagram offers — a one-time code sent via SMS — likely would have blocked the exploit: The hackers who released the video on Telegram said their exploit failed to work against any accounts that had MFA enabled.

  –

Read More  – Krebs on Security 

Post navigation

❮ Previous Post: RaccoonLine Publishes 2026 dVPN Buyer’s Guide for Privacy-Focused Users  – Hackread – Cybersecurity News, Data Breaches, AI and More
Next Post: USPS moving forward with mail-in ballot changes as courts weigh Trump’s election order   – CyberScoop ❯

You may also like

AttackFeed by Joe Wagner | Google moves post-quantum encryption timeline up to 2029  - CyberScoop
Attack Feeds
Google moves post-quantum encryption timeline up to 2029  – CyberScoop
March 25, 2026
AttackFeed by Joe Wagner | PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours of Disclosure  - The Hacker News
Attack Feeds
PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours of Disclosure  – The Hacker News
May 14, 2026
AttackFeed by Joe Wagner | Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices  - The Hacker News
Attack Feeds
Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices  – The Hacker News
May 31, 2026
AttackFeed by Joe Wagner | The missing cybersecurity leader in small business  - CyberScoop
Attack Feeds
The missing cybersecurity leader in small business  – CyberScoop
May 11, 2026

Leave a Reply Cancel reply

You must be logged in to post a comment.

  • Attack Feeds
  • Privacy/Governance Feed
  • Gov/ISAC Feeds
  • Alert Feeds
  • Privacy Policy
  • Wagner Cybersecurity

Copyright © 2026 AttackFeed by Joe Wagner.

Theme: Oceanly News Dark by ScriptsTown

We are using cookies for analytics purposes only.  We do not store, track or sell user information.

You can find out more about which cookies we are using or switch them off in .

AttackFeed by Joe Wagner
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.