Bitcoin

Hackers exploit Meta's AI to hack Instagram

By Kim03 | Kim Blog News | 4 hours ago


Hackers broke into Instagram profiles by asking Meta's support chatbot to change the registered email address. The flaw in the AI ​​assistant persisted even after the company announced a fix.

 

Next:

  1. Criminals took control of other people's profiles simply by asking Meta's customer service chatbot to change the registered email address.
  2. The flaw existed in the AI ​​assistant launched in March 2026, which was created to resolve account issues without human intervention.
  3. Even after Meta declared the problem fixed, new reports of intrusions surfaced the following day.

 

Last weekend, hacking an Instagram account became something anyone with access to Telegram and the willingness to type a few sentences could do. There were no viruses. There were no fake links. 

 

All you had to do was open Meta's support chat, state that you owned a profile, and request a change to your registered email address. Meta's support chatbot did the rest, without questioning, without checking, without hesitation.

The method was revealed by 404 Media and quickly spread through groups on the Telegram messaging app , where criminals not only shared the step-by-step instructions but also advertised stolen profiles for sale. 

Two cases drew particular attention: the Obama White House Instagram account, which was inactive and began displaying images generated by artificial intelligence without authorization, and the profile of Sergeant Major John Bentivegna , a high-ranking officer in the U.S. Space Force (USSF).

 

 

The AI ​​assistant skipped a basic step that any human agent would take.

The system exploited by the hackers is the AI ​​Support Assistant, a tool that Meta put into operation in March 2026 with the aim of conducting account recovery "from start to finish," eliminating the need for human intervention. In theory, an efficient solution. In practice, an open door.

The script followed by the hackers was straightforward: choose a profile with a short and valuable name, the so-called OG usernames , coveted on the black market for values ​​reaching thousands of dollars, connect to a VPN to simulate the victim's location, and initiate a conversation with Meta 's support chatbot claiming to be the account holder. The system then associated the criminal's email with the profile. Without asking for identification. Without a confirmation code. Without anything.

Any trained agent would have paused there and demanded some verification. The robot didn't pause. Two-factor authentication (2FA) protected some users , but those who hadn't activated this feature were vulnerable within minutes.

 

 

Sales of stolen profiles continued even after the announcement of a fix for Metacritic.

For years, a bustling parallel market has existed around OG usernames — short identifiers registered by early Instagram users, now treated as collectible assets. Until recently, obtaining them required real technical effort: targeted phishing, SIM swapping by bribing carrier employees, or hacking email accounts.

This loophole in Meta's support chatbot made all of that unnecessary. The ads on the Telegram channels included handles with proper names and country names , precisely the most sought-after in this niche. 

And TechCrunch reported that sales continued even after Andy Stone, a spokesperson for Meta, publicly stated on Monday that "the problem that occurred has already been fixed."

 

Meta sends notifications, but intrusions persist the day after the fix.

On Tuesday, new users reported losing access to their own accounts. Members of the same Telegram groups claimed that the exploit was still functioning—directly contradicting the company's statement. 

Stone told TechCrunch that Meta secured the affected accounts before launching the notification campaign, but declined to disclose the total number of compromised users.

Several victims reported receiving messages from Instagram warning of "suspicious activity" on their profile, with instructions to reset their password. Regarding the most emblematic case, Meta disputed that the Obama White House Instagram account was specifically compromised through this vulnerability, although it confirmed that the account was hacked by other means.

 

Incident reveals structural risk in delegating real authority to AI systems.

There is a tension that the technology sector has yet to resolve: how to give an artificial intelligence agent the power to act in the real world without replicating, along with efficiency, the safeguards that humans applied to the same process.

Meta built a chatbot capable of altering critical account data — and it did so without including the most basic filter that any customer service representative would apply before changing any record. 

When support was provided by a human, the process was frustratingly slow. But this slowness served a purpose: it forced those requesting help to prove their identity. By removing this friction without replacing the verification, the company transformed a security step into a blind spot.

This incident does not invalidate the use of AI in customer support . But it makes it clear that automating sensitive processes without addressing the authentication problem is simply trading a bottleneck for a vulnerability , and that no patch announcement can undo the damage caused while the vulnerability was present.

 

......................................................................

How do you rate this article?

4


Kim03
Kim03

I am a content producer. I also publish news content.


Kim Blog News
Kim Blog News

General news blog. Cryptocurrency news.

Publish0x

Send a $0.01 microtip in crypto to the author, and earn yourself as you read!

20% to author / 80% to me.
We pay the tips from our rewards pool.

Page not displaying correctly?