Hackers trick Meta AI's support chatbot to steal celebrity Instagram accounts.

It has been revealed that hackers attempted to steal and resell celebrity Instagram accounts by deceiving Meta AI's support chatbot. The hackers succeeded in stealing celebrity accounts by simply asking the bot to change the email address associated with the account, while using a VPN to conceal their actual location.
Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked
https://www.404media.co/hackers-simply-asked-meta-ai-to-give-them-access-to-high-profile-instagram-accounts-it-worked/
People are using prompt injection to trick Meta's AI into handing over Instagram accounts - Neowin
https://www.neowin.net/news/people-are-using-prompt-injection-to-trick-metas-ai-into-handing-over-instagram-accounts/
Hackers duped Meta AI support chatbot to steal celebrity Instagram accounts - Ars Technica
https://arstechnica.com/ai/2026/06/meta-ai-support-chatbot-gave-hackers-access-to-notable-instagram-accounts/
According to technology media outlet 404 media, a video demonstrating an incredibly simple exploit is circulating in a Telegram group for hackers and security researchers. Using this exploit, hackers were able to take over Instagram accounts worth tens of millions of yen and resell them on the gray market before Meta applied an emergency patch on May 29, 2026.
The hacked Instagram accounts include the White House account of former President Barack Obama and the account of a Space Force Chief Sergeant . The compromised accounts temporarily posted pro-Iranian images and messages.
Obama White House IG HACKED
— RT (@RT_com) May 31, 2026
Iranian Gen Qasem Soleimani photos flood page — TMZ
'The White House is under Shiites' control' pic.twitter.com/5f8OXXYuec
The hacker used a VPN to pinpoint their location to the target Instagram account user's residence and initiated the password reset process. All they had to do was ask Meta AI's support chatbot to change the email address associated with the account. Technology media outlet Ars Technica described it as 'a very simple prompt injection attack.'
According to Neowin, this vulnerability has been exploited since February 2026, and hackers have reportedly compromised thousands of Instagram accounts. The vulnerability became widely known after several celebrities' Instagram accounts were compromised.
Renowned security researcher Jane Manchun Wong also posted that she had been a victim of account hijacking, stating, 'My Instagram account was also hacked. My password was changed without my knowledge, and I received various password reset attempts all day yesterday. I was also repeatedly logged out of the Instagram iOS app.'
Even my Instagram account got hacked
— Jane Manchun Wong (@wongmjane) June 1, 2026
The password got changed without my knowledge and I was getting different password reset attempts throughout yesterday. And I got repeatedly logged out from the IG iOS app
Quite concerning https://t.co/F6wjKYrlBo
Anonymous open-source intelligence researcher ZachXBT pointed out, 'Meta AI's support is rubbish; it has tons of access privileges, yet it can reset the password for any user's account without two-factor authentication , and it doesn't even verify who you are.'
It's likely because there was a massive Instagram / Meta exploit over the weekend that was just patched.
— ZachXBT (@zachxbt) June 1, 2026
Basically the Meta AI support is garbage and has lots of access perms which allowed you to reset passwords to any user without 2FA and did not verify who you are.
Telegram…
Dark Web Informer, also a security researcher, has posted about a similar vulnerability.
🚨 Instagram had an exploit that allowed you to use Meta AI to reset passwords to accounts with no MFA on them. The exploit was patched a short time ago. pic.twitter.com/PEUwLvmllj
— Dark Web Informer (@DarkWebInformer) June 1, 2026
According to security expert The CyberSec Guru , the hackers were targeting particularly valuable Instagram accounts, all of which had a combined valuation of over $1 million (approximately 160 million yen) on the gray market.
According to the security blog KrebsOnSecurity , this prompt injection attack was unsuccessful against accounts that had multi-factor authentication enabled.
Ars Technica noted, 'This attack highlights the broader risks faced by technology companies and other organizations rushing to deploy AI agents with high privileges that can modify, create, and delete critical data. Meta was scheduled to release its Meta AI Support Assistant in March 2026, promising to provide reliable 24/7 support for virtually any support issue at any time.'
Related Posts:







