Full Breakdown
Meta AI Support Chatbot Exploit Enables Hijacking of High-Profile Instagram Accounts
6/2/2026, 8:32:58 PM
The Exploit in Action
Hackers initiated a password-reset flow for a target Instagram handle, spoofed the target’s geographic location with a VPN, and then opened a chat with Meta’s AI Support Assistant. By prompting the bot to “link my new email address” and supplying the victim’s username, the chatbot sent a verification code to the attacker-controlled email. After the code was entered, the bot displayed a “Reset Password” button, allowing the hacker to set a new password and lock the legitimate owner out. The method required no phishing, no malware, and bypassed two-factor authentication (2FA) when it was not enabled.
Background & Context
Meta rolled out the AI Support Assistant globally in March, marketing it as a “24/7” tool that could “reset passwords, set up 2FA, and resolve account problems” (product page tagline: “Solutions, not just suggestions”). The launch coincided with a broader AI-first reorganization that saw thousands of staff reassigned to AI projects and a reduction of over 8,000 employees.
Key Figures & Groups
- Meta – represented by Andy Stone, Vice President of Communications.
- Hackers – identified on Telegram and X by researchers such as ZachXBT and Dark Web Informer.
- Security analysts – Jane Manchun Wong (former Meta engineer), Jake Moore (ESET), Tom Van de Wiele (Hacker Minded), Tomas Stamulis (Surfshark), Marijus Briedis (NordVPN).
- Compromised accounts – the archived Barack Obama White House Instagram, Sephora’s brand page, Chief Master Sergeant John Bentivegna of the U.S. Space Force, and Wong’s personal account.
Timeline
- February 2026 – earliest reported activity of the vulnerability (Neowin).
- March 2026 – Meta expands AI support to all Facebook and Instagram accounts.
- Early June 2026 – videos and screenshots circulate on Telegram, X, Reddit; high-profile takeovers become public.
- May 29 2026 – Meta deploys an emergency patch.
- June 1 2026 – Andy Stone posts on X that the issue is resolved and impacted accounts are being secured.
Data & Statistics
- 404 Media and Neowin cite “thousands of accounts” compromised.
- Short, high-value handles such as “hey” and “jowo” were reported to be worth roughly $1 million collectively.
- Individual premium usernames have fetched “hundreds of thousands of dollars” on the gray market.
Why It Matters
The incident demonstrates how granting an AI system authority over credential changes creates a new attack surface. Hackers could monetize valuable handles quickly, and the breach raised doubts about the safety of AI-driven account recovery on any platform that handles sensitive data.
Official Statements & Responses
Meta’s Andy Stone wrote, “This issue has been resolved and we are securing impacted accounts.” The company confirmed that no back-end database was breached and that the vulnerability has been patched, but it did not disclose the total number of affected users.
Criticism & Opposition
Security experts warned that the bot lacked proper identity verification. Jake Moore (ESET) called the exploit “a reminder of the risks of outsourcing critical functions to AI.” Tom Van de Wiele labeled the rollout a “move fast and break things” mentality, while Marijus Briedis (NordVPN) argued that “account recovery should never rely on convenience alone.”
On-the-Ground Reports
Telegram videos show the exact prompt sequence; Reddit users reported being locked out and unable to reach a human support agent. The Obama White House page briefly displayed pro-Iran images, and Wong posted screenshots of password-reset attempts on X.
Conflicting Reports & Gaps
Sources differ on the scale of the breach (“thousands” vs “unknown”), the start date (February vs March), and whether 2FA would have blocked all attacks. Some outlets initially claimed world-leader accounts were compromised; Meta later labeled those claims “totally false.” The precise number of accounts patched remains undisclosed.
Verbatim Quotes
- “the Meta AI support is garbage and has lots of access perms which allowed you to reset passwords to any user without 2FA and did not verify who you are.” — ZachXBT, researcher
- “The password got changed without my knowledge and I was getting different password reset attempts throughout yesterday.” — Jane Manchun Wong, security researcher
- “This issue has been resolved and we are securing impacted accounts.” — Andy Stone, Meta spokesperson
- “AI chatbots create interesting new attack surface, and we’re likely going to see a lot more of these kinds of attacks,” — Ian Goldin, threat researcher, Lumen’s Black Lotus Labs
- “This is easily the biggest breach in Meta/Facebook history,” — Nikita Bier, X Head of Product
What’s Next
Meta is expected to tighten verification checks for AI-driven actions and to promote MFA adoption across Instagram. Industry observers are calling for clearer governance standards for AI systems that perform privileged operations, and security teams are monitoring for similar exploits on other platforms.
