惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 聂微东
Y
Y Combinator Blog
WordPress大学
WordPress大学
L
LangChain Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
A
About on SuperTechFans
小众软件
小众软件
有赞技术团队
有赞技术团队
S
SegmentFault 最新的问题
宝玉的分享
宝玉的分享
Recent Announcements
Recent Announcements
GbyAI
GbyAI
I
InfoQ
The GitHub Blog
The GitHub Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
酷 壳 – CoolShell
酷 壳 – CoolShell
罗磊的独立博客
C
Check Point Blog
V
V2EX
Apple Machine Learning Research
Apple Machine Learning Research
月光博客
月光博客
量子位
雷峰网
雷峰网
Hugging Face - Blog
Hugging Face - Blog

Hackread – Cybersecurity News, Data Breaches, AI and More

Operation Endgame Disrupts StealC, Amadey and SocGholish Malware Networks New GhostShell Hacking Group Targets Ukraine’s Drone Defense Sector Fake npm Packages Impersonate PostCSS Tool to Steal Chrome Passwords Best Crypto Payment Solutions for E-Commerce Businesses Internet Society Foundation Opens Global Call for Common Good Cyber Fund to Strengthen Cybersecurity LastPass Confirms Customer Data Breach After Klue OAuth Token Theft ‘Cordyceps’ CI/CD Flaw Exposes Microsoft, Google, Apache Repos to Pipeline Hijacking The Rise of AI-Powered Academic Fraud: Beyond Traditional Plagiarism New CryptoBandits Malware Uses USB Drives and Tor to Steal Crypto The Evolution of iGaming Fraud: What Security Teams Should Expect in 2027 2 Scattered Spider-Linked Hackers Plead Guilty Over £39M TfL Cyberattack Beats Studio Buds Flaw Could Let Nearby Attackers Eavesdrop on Users Texas Parks and Wildlife Data Breach Affects Over 3M License Customers Threat Hunting Beyond Alerts: Finding the Activity Detection Misses Scammers Use Fake GitHub Stars, VirusTotal Reviews to Spread Crypto Clipper Salesforce Disables Klue Integration After OAuth Token Theft Hits Customer Data MDR Provider Comparison: Time to Discover and Respond to Threats Meteor 3.0 Migration Helped Rocket.Chat Move Off End-of-Life Node.js Runtime Gcore Helps Ucom Safeguard Public Live Broadcast Infrastructure During Armenia’s Parliamentary Elections Nintendo America Employee Data Exposed After Shadowbyt3$ Targets TinyPulse eFAQ Publishes Investigation Into Alleged Scam Activity and Coordinated Reputation Attacks FIFA World Cup 2026: Hackers Target Football Fans With Fake Tickets Sites MacBook Neo vs Windows Laptops for Cybersecurity Tasks Operation Endgame Disrupts SocGholish Malware Infrastructure What Businesses Should Know Before Migrating Their CMS DragonForce Ransomware Abused Microsoft Teams to Hide Malware Activity Agentjacking: Researchers Show How One Fake Bug Report Can Hijack AI Coding Agents FortiBleed Attack Exposes Fortinet Firewall Credentials in 194 Countries SpyCloud Report Finds Phishing Attacks Surge as Employee Data Is Exposed at 86% of Fortune 100 Companies 152 Chrome Live Wallpaper Extensions Hid Ad Tracking and Fake Search Clicks
Hackers Abused Meta’s AI Support Bot to Hijack Major Inst...
Deeba Ahmed · 2026-06-02 · via Hackread – Cybersecurity News, Data Breaches, AI and More

Instagram has fixed a security problem that let hackers hijack several famous accounts by tricking Instagram’s parent company, Meta’s new artificial intelligence helper, called the Meta AI support assistant.

This incident happened over the weekend and was brought to light when several users on social media platforms like X and Reddit complained of losing control of their Instagram accounts with proof.

The profiles impacted included well-known beauty brand Sephora, a high-ranking US Space Force chief master sergeant John Bentivegna, and security researcher Jane Wong.

Hackers also took over the archived Barack Obama White House account, which has over two million followers, and posted fake pictures and pro-Iranian messages. “The White House is under Shiites’ control,” one of the messages read.

Instagram Fixes Major Security Issue After Hackers Trick Meta AI Support Chatbot

How the Scammers Fooled the Bot

In March, Meta started testing the Meta AI support assistant for Facebook and Instagram. It was supposed to help with things like resetting passwords without a human needing to get involved. But hackers quickly found a major security flaw in the way the AI was programmed to think; it was a logic flaw that forced the AI to trust data in the wrong order.

Exploitation started with using a VPN to hide where their computer really was. They picked a location close to the person they wanted to hack. This made sure Instagram’s security systems didn’t flag anything strange.

Then, they started a chat with the AI assistant. They gave it the username they wanted to take over and asked it to add a new email address to that account. Due to the logic flaw, the bot sent a security verification code to the hacker’s email. When the hacker typed this code back into the chat, the bot gave them a button to change the password. The system even accepted fake selfie videos made by AI tools to bypass identity checks.

The real owners of these accounts didn’t get any warnings, texts, or emails about these changes at all, and even worse, this trick also bypassed two-factor authentication, which usually asks for an extra step to prove it’s you before making big changes.

Watch the full saga of Instagram accounts being compromised one after another, as shared by International Cyber Digest, a cybersecurity news feed on X, formerly Twitter.

Calls for Better Support

Step-by-step videos showing the hacking trick quickly became viral in blackhat hacking groups on Telegram. Security experts following the issue said that valuable short handles like “hey” and “jowo” (collectively valued at around $1 million) were stolen and sold for money.

People who lost control of their accounts complained about being unable to talk to a real Meta representative and get a human worker involved. On Monday, Meta spokesperson Andy Stone posted on social media that the company had fixed the problem and was working to secure the affected accounts again.

Instagram Fixes Major Security Issue After Hackers Trick Meta AI Support Chatbot