< Back to all clusters
[TECHNOLOGY] · United States · 2 sources

Meta's AI support bot used to hijack prominent Instagram accounts

Hackers exploited a prompt‑injection flaw in Meta’s AI‑driven support chatbot for Instagram, using VPNs and simple text commands to change the email address linked to a target account. The manipulated bot sent verification codes to the new address, allowing password resets and full control of the profile. The attack, active from March 2026, affected high‑profile accounts such as an inactive White House account from the Obama era, the beauty retailer Sephora and a senior officer of the U.S. Space Force. Stolen accounts were listed on Telegram marketplaces, with some usernames advertised for up to one million euros.

Meta confirmed the vulnerability and rolled out an emergency patch after media exposure, noting that accounts protected with multi‑factor authentication (MFA) resisted the exploit. Security researchers warned that the incident demonstrates how artificial‑intelligence tools can lower the barrier for sophisticated cyber‑attacks, prompting calls for stronger authentication, anomaly detection and human oversight in AI‑driven customer‑service functions.