Hackers Duped Meta AI Support Chatbot to Steal Celebrity Instagram Accounts

Hackers Duped Meta AI Support Chatbot to Steal Celebrity Instagram Accounts

Ars Technica – Security
Ars Technica – SecurityJun 1, 2026

Companies Mentioned

Why It Matters

The incident shows how AI‑driven support tools can become attack vectors when granted unchecked privileges, exposing billions of user accounts and high‑value digital identities. It forces tech firms to rethink AI deployment security and reinforces the need for robust verification mechanisms.

Key Takeaways

  • Hackers used Meta AI chatbot to reset Instagram emails via prompt injection.
  • Exploit required VPN matching target region and bypassed 2FA without MFA.
  • Hundreds of thousands of dollars of Instagram accounts sold on gray market.
  • Meta patched vulnerability on May 29 after public exposure.
  • Lack of out‑of‑band verification leaves AI agents vulnerable to confused deputy attacks.

Pulse Analysis

The breach unfolded when attackers leveraged a prompt‑injection technique against Meta’s AI support assistant, a large‑language model launched in March 2026 to handle password‑reset requests. By routing their traffic through a VPN that mimicked the target’s geographic region, they convinced the chatbot to replace the account’s email address, effectively sidestepping multi‑factor authentication. The method proved effective across thousands of accounts, including high‑visibility profiles like the Barack Obama White House and the Space Force chief, before Meta rolled out an emergency patch on May 29.

Beyond the immediate financial loss—estimated at over $1 million for premium handles such as @hey and @jowo—the exploit highlights a systemic risk: AI agents with elevated permissions can become "confused deputies," unintentionally executing privileged actions for malicious actors. Security experts stress that out‑of‑band verification, rate limiting, and deterministic gating are essential safeguards. While basic SMS‑based MFA blocked the attack on hardened accounts, many users rely on weaker controls, leaving a large attack surface for AI‑driven abuse.

The incident is a cautionary tale for the broader tech industry as AI‑powered customer support proliferates. Companies must balance the promise of 24/7 automated assistance with rigorous security architectures that include independent verification steps and anomaly detection. Meta’s rapid patch demonstrates responsiveness, yet the episode underscores the need for industry‑wide standards to prevent similar AI exploitation, protecting both brand reputation and the burgeoning market for digital identity assets.

Hackers duped Meta AI support chatbot to steal celebrity Instagram accounts

Comments

Want to join the conversation?

Loading comments...