It has been revealed that Meta's AI customer support chatbot was exploited to hijack Instagram accounts. According to foreign media reports, hackers used Meta's AI support tools to take control of targeted accounts by changing the email addresses linked to them and requesting password resets.
The tool in question is an AI-assisted system introduced by Meta to make account recovery faster and easier. Meta introduced an AI assistant to resolve Facebook and Instagram account issues on its official blog in December 2025. At the time, Meta explained that it would not only provide answers when users experienced account problems but would also be able to directly handle certain requests.
This vulnerability spread through videos and screenshots distributed on platforms such as Telegram. It is reported that hackers requested an AI chatbot to change the email address of a specific Instagram account, received a verification code via the new email, and then reset the password. Some reports stated that the attackers used a VPN to make it appear as if they were accessing the account from a location similar to that of the target account owner.
Meta stated that the issue has been resolved. Andy Stone, Meta’s Vice President of Communications, said, “This issue has been resolved, and we are protecting the affected accounts.” However, Meta did not disclose specifically how many accounts were affected or which verification procedures the AI support tool failed to pass.
This incident illustrates the problems that arise when applying AI to high-risk account recovery procedures. Account recovery is an area where user convenience and security directly conflict. Making the recovery process faster makes it easier for legitimate users to receive assistance, but if verification procedures are weak, the door can be opened to attackers at the same speed.
This case is particularly noteworthy because it demonstrates that even accounts with two-factor authentication enabled may not be safe. If an attacker can change the account's email address itself, there is a possibility that they can bypass existing security measures and gain control of the password reset process. If account recovery tools are not strong enough to verify the actual account owner, AI can become an automated bypass route rather than a security measure.
Around the same time as this vulnerability, there were also reports of several prominent Instagram accounts being hacked, including the Obama White House Archives, Sephora, and accounts of high-ranking U.S. Space Force officials. However, it has not been officially confirmed whether all of these accounts were compromised in the same manner.
Meta is attempting to automate customer support and account recovery using AI. However, functions such as changing account ownership, email addresses, and password resets require much higher security standards than simple consultations. This incident demonstrates the risk that just as AI support tools quickly resolve user issues, they can also rapidly process requests from attackers.
More and Sources