惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

月光博客
月光博客
人人都是产品经理
人人都是产品经理
Hugging Face - Blog
Hugging Face - Blog
有赞技术团队
有赞技术团队
阮一峰的网络日志
阮一峰的网络日志
罗磊的独立博客
博客园_首页
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
大猫的无限游戏
大猫的无限游戏
博客园 - 司徒正美
S
SegmentFault 最新的问题
Jina AI
Jina AI
美团技术团队
酷 壳 – CoolShell
酷 壳 – CoolShell
小众软件
小众软件
WordPress大学
WordPress大学
爱范儿
爱范儿
博客园 - Franky
量子位
V
V2EX
Apple Machine Learning Research
Apple Machine Learning Research
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
雷峰网
雷峰网

Consumer Insights

The ransomware negotiator who was working for the other side After years on the run, alleged Ryuk ransomware operator pleads guilty INTERPOL crackdown shows scammers shifting to social media Meta lets strangers remix your public Instagram photos with AI—here’s how to opt out Invited to a "job interview" with Netflix or OpenAI? Beware! Your Google password could be at risk Two arrested over credit card phishing - as the Netherlands is named Europe's worst for payment fraud India pauses WhatsApp username feature over security concerns Alleged teen ransomware hustler faces US charges after arrest in Finland WhatsApp usernames explained: how to reserve yours and stay safe Scammers race to cash in on Venezuelan earthquake disaster USB drives carrying China-linked malware infected Japanese military networks for nearly a year WhatsApp tests new safety prompt before you chat with strangers Social media is worth celebrating. It's also worth protecting. Polish police dismantle SIM-swap gang accused of crypto theft Operation Endgame deals fresh blow to StealC and Amadey malware networks Hacker hijacks Brazil's national alert system, sending "misanthropy" to millions of phones Cybercrime now rivals traditional crime across parts of Asia Apple's Hide My Email tweak leaves privacy fans fuming Americans lost $3.5 billion to imposter scams last year — and the scams are getting harder to spot Scammers have killed the physical Steam Gift cards Crypto investment scam sends couriers to collect victims' cash, FBI warns Maine forced to take down data breach portal after fake notices filed with authorities Privacy own-goal: World Cup blunder leaks Lionel Messi's passport details Why schools remain one of cybercriminals' favourite targets WhatsApp detects new spyware activity from Israel’s NSO Group despite court order Got a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5 Europol cracks down on illegal streaming globally FBI Warns Fans About FIFA Scams Ahead of 2026 World Cup Virtual knife, real lawsuit: Counter-Strike skin dispute ends in court As Deepfakes Spread, YouTube Makes AI Labels Harder to Miss
Hackers didn't hack Instagram; they just asked Meta AI
Silviu STAHIE · 2026-06-03 · via Consumer Insights

Hackers have reportedly found a way to exploit Meta’s AI-powered assistant to take control of high-profile Instagram accounts, including those linked to public figures, government organizations, and holders of valuable usernames.

According to online reports, attackers persuaded the chatbot to change account recovery email addresses, allowing them to reset passwords and take control of targeted accounts before Meta patched the vulnerability.

Key takeaways

  • Attackers allegedly abused Meta’s AI support chatbot to change recovery email addresses on Instagram accounts.
  • High-profile accounts, including government-affiliated and celebrity-related profiles, were reportedly compromised.
  • Meta says it has fixed the vulnerability and is securing affected accounts.
  • Multi-factor authentication (MFA) reportedly prevented many takeovers.

What happened?

Meta’s AI support assistant allegedly became an unexpected entry point for account takeovers after attackers discovered they could persuade the chatbot to modify account recovery information.

According to 404 Media, hackers used the AI-powered support system to change the email addresses associated with targeted Instagram accounts. After they gained control of the accounts, they could initiate password resets and access the victim’s account.

The vulnerability reportedly remained active for months until several high-profile account compromises attracted widespread attention. Meta subsequently implemented an emergency fix and stated that the issue had been resolved.

The reported attack chain was surprisingly simple. Attackers would use a VPN to look like they were in the same geographic region as the target account and start an Instagram password recovery process.

They then escalated the discussion to Meta’s AI support chatbot and requested to change the account’s email address. Following the regular password reset process, the attackers would gain control of the account.

The attack did not rely on sophisticated malware, zero-day exploits or technical vulnerabilities in Instagram itself. Instead, attackers manipulated the AI system to perform sensitive account recovery actions.

Which accounts were affected?

Reports linked the exploit to several high-profile account compromises. According to published accounts, affected profiles included the Barack Obama White House Instagram account, The Chief Master Sergeant of the Space Force account, and many “OG” Instagram usernames.

Security researchers also reported that attackers targeted rare, highly desirable usernames that can command significant prices on underground markets.

How users can protect their accounts

Although Meta has reportedly fixed the vulnerability, users should still follow account security best practices.

  • Enable multi-factor authentication

The exploit generally failed against accounts protected by MFA, including SMS-based authentication.

  • Use a unique password

Avoid using the same password across multiple services. Password reuse remains one of the most common causes of account compromise.

  • Review account recovery options

Verify that your recovery email address and phone number remain accurate and accessible.

  • Monitor login alerts

Most major platforms provide notifications when new devices log in or account settings change.

  • Watch for suspicious activity

Unexpected password reset emails, login notifications, or profile changes may indicate that someone is attempting to access your account.

 Don't let hackers take over your Instagram account

Bitdefender Security for Creators helps protect creators, influencers, and social media users from the tactics commonly used in account takeover attacks, including phishing attempts, malicious links, fake collaboration offers, and credential theft. It also provides security monitoring designed to help you spot risks before attackers can exploit them.

Whether you're managing a growing audience or simply want to keep your Instagram account secure, taking proactive steps today can help prevent the frustration, financial losses, and reputation damage that often follow a compromise.

Learn more about Bitdefender Security for Creators and strengthen the security of your online presence before attackers get a chance.

FAQ

What happened?

Hackers reportedly exploited Meta's AI support chatbot to change recovery email addresses on Instagram accounts and gain control of them.

Did Meta fix the issue?

Yes. Meta said it patched the vulnerability and is securing affected accounts.

Why does this matter?

The incident shows how AI systems with elevated privileges can become attack targets if they can perform sensitive account-management tasks.

Would multi-factor authentication have helped?

Yes. Researchers reported that MFA prevented many takeover attempts from succeeding.

How can users protect their accounts?

Enable multi-factor authentication, use a strong unique password, and regularly review account recovery settings.