Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124
Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124

You may have heard that some prominent Instagram accounts were hacked over the weekend. White House Account of Barack Obama He was arguably the largest among them.
What you may not have heard is that the hackers didn’t have to try very hard: Meta’s customer support chatbot essentially handed over the accounts.
according to 404 mediathe hackers simply had to ask Meta’s AI support chatbot to change the email address associated with the targeted account. The hackers then tricked the bot into initiating a password reset without requiring identity verification. The AI then sent an access code to the hacker’s email address, which the hacker copied into the chat. This prompted the AI to display a “Reset Password” button, which was then used to modify the password and take control of the account.
There’s even a step-by-step adjustment Video of the process On X. The hacker used a VPN to make it appear they were in the target’s location, and the AI quickly responded to the request. At no time did the hacker need the user’s email address or original password.
Instagram had an exploit that allowed you to use Meta AI to reset passwords for accounts that didn’t have MFA on them. The exploit was patched a short time ago.pic.twitter.com/PEUwLvmllj
– Dark Web Informer (@DarkWebInformer) June 1, 2026
The security breach hit accounts, including cosmetics retailer Sephora and US Space Force Master Sergeant John Bentevna. It is unclear how many accounts were affected in total, but many users reported being hacked Reddit and X over the weekend, including security researcher Jane Wong.
“My password was changed without my knowledge, and I was receiving various attempts to reset the password all yesterday,” Jane said He said on X. “And I’ve been repeatedly logged out of the (Instagram) iOS app. It’s very disturbing.”
The problem is almost entirely due to Meta customer support which is now run by AI. Tech giant Make the switch Back in March, saying it would enable “24/7 help for account issues like updating your password and settings for your profile.”
But with an AI chatbot handling the entire process, humans were unable to intervene when suspicious activity started. This allowed hackers to carry out a social engineering style attack and execute it multiple times before anyone noticed.
per Cybersecurity Newssecurity researchers ZachXBT and Dark Web Informer were the first to publicly reveal this exploit, but not before several high-profile accounts were stolen. Dark Web Informer tracked the sale of many of these high-profile accounts in real time. Some of these accounts were bundled together with an asking price of $1 million.
Instagram spokesperson Andy Stone said in a statement Share on X The exploit has since been fixed. 404 Media reports that Meta is in the middle of “locking down affected accounts.”
Meta has not yet responded to a request for comment.
The social engineering exploit had one major drawback: it did not work on accounts with multi-factor authentication. These accounts either already have the code in the authenticator app of choice or received it via text message. Without MFA set up, the one-time reset code appears to be sent to an email address of your choice, allowing hackers to obtain it.
The best way to protect yourself is to enable multi-factor authentication, available on all Meta platforms. He – she It won’t protect you 100% of the timebut it is much better than the password itself, and would have been completely protected against this particular exploit.
There are other things you can do Enhance account securityincluding using passkeys where available and a private email address to make your account credentials more difficult to find.