Meta AI Support Exploit Enables Instagram Account Takeovers

Hackers used Meta’s AI support chatbot to add attacker-controlled emails and reset Instagram passwords; Meta patched the flaw on May 29 and said it is securing impacted accounts.

Overview

A summary of the key points of this story verified across multiple sources.

1.

Meta said it resolved the issue and secured impacted accounts after an emergency patch on May 29.

2.

Hackers persuaded Meta’s AI support chatbot to add attacker-controlled emails and used verification codes to reset Instagram passwords while spoofing victims’ regions with VPNs, security researchers said.

3.

On May 31, researcher ZachXBT posted that the AI support allowed password resets without two-factor authentication by not verifying requesters.

4.

High-profile targets included the Obama-era White House account, Sephora, and the U.S. Space Force chief master sergeant, and one report said the exploit dated back to February and may have compromised thousands.

5.

Researchers are continuing to analyze the exploit’s mechanics while Meta investigates and secures accounts, and it remains unclear exactly how many users were impacted.

Written using shared reports from
5 sources
.
Report issue

Analysis

Compare how each side frames the story — including which facts they emphasize or leave out.

Center-leaning sources frame the incident as a preventable security failure and a sign of growing AI risk, highlighting high-profile account takeovers and Meta operational lapses. Editorial choices prioritize alarm through vivid examples and speculative links to broader AI threats while relying on sourced quotes for dramatic claims rather than definitive evidence.