Illustration of an Instagram security breach linked to the Meta AI assistant

Instagram Security Breach: How Meta AI Facilitated the Hacking of 20,000 Accounts

October 4, 2026 Off by Password Revelator

A critical vulnerability, exploited via Meta's support chatbot, allowed attackers to hijack thousands of Instagram profiles without any technical skills. A look back at a major security blunder.

This article will also interest you: OpenAI AI agents accused of cyberattack: an unprecedented complaint filed in California

During the weekend of May 31, a disconcertingly simple hacking method shook Instagram users. Forget malware or complex phishing: just chat with Meta's artificial intelligence to take over an account.

A gaping flaw in the Meta AI assistant

The attack did not require access to the victim's email address or complex passwords. The modus operandi, revealed by numerous reports on Reddit and X (formerly Twitter), was based on psychological manipulation of Meta's conversational assistant.

The hacker proceeded in three simple steps:

  1. Identity masking: The attacker used a VPN to simulate the same geographic location as his target, thus bypassing automatic detections.
  2. Social engineering: He would initiate a conversation with Meta AI Support and simply request that a new email address be added to the targeted account.
  3. Takeover: The chatbot generated a verification code sent to the new address. Once the code was validated, the attacker simply had to click a reset button to lock the rightful owner out of their own account.

High-profile victims and 20,225 compromised accounts

The scale of the incident is massive. According to a legal notice filed by Meta with the State of Maine, 20,225 users were affected by this vulnerability.

Among the compromised targets, there are prestigious entities, which underlines the indiscriminate nature of the attack:

  • The archived White House account during the Obama administration.
  • The Sephora account.
  • Chief Master Sergeant John Bentivegna of the United States Space Force.

Cybersecurity researcher Jane Manchun Wong, herself a victim, testified on social media: “My password was changed without my knowledge and I received several reset attempts throughout the day. This is quite worrying."

Why was such a flaw possible?

This situation results from a strategic decision by Meta taken in March 2026. The company had chosen to delegate the most sensitive functions of account management to its AI, such as resetting passwords or modifying identifiers.

The fundamental problem was the lack of robust identity verification. Meta AI processed modification requests without ever ensuring that the interlocutor was the legitimate owner of the account. This automation, supposed to streamline the user experience, has become the ideal entry point for hackers.

Meta reaction and correction

Faced with the viralization of reports, Meta reacted quickly. On Monday, June 1, Instagram spokesperson Andy Stone confirmed that the vulnerability had been closed. However, the company did not disclose exactly how long the vulnerability remained active before it was patched.

AI, a new major attack vector

This incident highlights a growing challenge for tech giants: the security of conversational assistants. By integrating AI into critical functions like customer support or account management, businesses are creating new blind spots.

The flexibility of chatbots, capable of interpreting ambiguous requests to help the user, becomes a major weakness when exploited by malicious actors. This case serves as a reminder that automation, without strict safeguards, can transform a support tool into a massive hacking weapon.