Hackers Used Meta's AI Support Bot to Hijack Instagram Accounts / Jul 5, 2026
Some of the most guarded accounts on the internet turned out to share a very human weakness this year: an assistant that does what it is told. Hackers took over a string of high-profile Instagram accounts, reportedly including the Obama White House account, the top enlisted leader of the US Space Force, and Sephora, by simply asking Meta's AI support chatbot to change the email tied to the target account. Meta later said around twenty thousand accounts were affected.
What happened
Earlier in 2026, Meta rolled out AI-powered account support across Facebook and Instagram and gave the assistant real authority: resetting passwords and handling account recovery, "solutions, not just suggestions," as its product page put it. Attackers realized the bot would act on a confident request and turned that into a takeover method.
How the attack worked
The technique was almost embarrassingly simple. A hacker would open a chat with the support bot, give it the target's username and their own email, and ask it to link the new address to the account. The bot changed the recovery email, the attacker requested a reset code, and the account was theirs. Security researchers call this a confused deputy problem: a trusted system using its privileges on behalf of someone who should not have them. Worse, victims reported no way to escalate to a human.

How big it was
In a regulatory filing, Meta estimated about 20,225 Instagram accounts may have been affected. Investigators believe the first successful attacks date back to mid April, well before the company noticed at the end of May. High-value handles were flipped and sold on the gray market before an emergency fix went in.
Why it matters
This is the risk of handing security-critical functions to an AI assistant without hard verification. The model was helpful, and that was exactly the problem. When an agent can change recovery details, a persuasive message becomes an exploit, and social engineering that once needed a human target now works on a bot that never gets suspicious.
How to protect yourself
- Turn on two-factor authentication. In many cases it blocks a login even after a password reset.
- Be wary of services where the only support is an AI with no human path.
- If you build with agents, never let them perform high-privilege actions on request alone. Require real identity checks for anything that touches recovery, billing, or access.
Bottom line
Meta says it patched the flaw and will relaunch the tool once it is fixed. The lesson is bigger than one company: an AI that can take actions needs the same guardrails as any powerful account, or a friendly chatbot becomes the easiest door in.
Frequently asked questions
- How did hackers take over the Instagram accounts?
- They messaged Meta's AI support bot, gave it the target username and their own email, and asked it to link the new address. The bot changed the recovery email, which let them reset the password and take over the account.
- How many accounts were affected?
- Meta's regulatory filing estimated about 20,225 Instagram accounts, including several high-profile ones such as the Obama White House account, a top US Space Force account, and Sephora.
- How do I protect my account?
- Turn on two-factor authentication, which can block a login even after a password reset, and be cautious with services that offer only AI support and no path to a human.