03/06/2026
Meta's AI Customer Service Disaster: Instagram Accounts With a Single Chat
Meta is learning the hard cost of putting AI in charge of sensitive support. A flaw in its AI support assistant let attackers seize Instagram accounts, and the company has now patched it after a wave of takeovers.
Meta introduced the AI-powered support assistant in December to help users recover access to locked Facebook and Instagram accounts more quickly (Business Standard) — including password resets. Attackers found the gap fast. An attacker first switched on a VPN to appear in the target's region, which avoided Instagram's automatic location alarms, then opened Meta's AI Support Assistant and asked it to add a new email address to the victim's account. (Techish) The chatbot sent a verification code to the email address provided by the hacker; the hacker shared it back, the chatbot showed a "Reset Password" button, and the account was gone. (TechCrunch)
The core failure was simple. The AI chatbot treated the person it was talking to as the account owner without verifying their identity. (The Next Web) At no point did the hacker need to access the legitimate email address linked to the victim's account. (The Next Web)
The compromised accounts include the Instagram handle for the Obama-era White House, which appears to have been inactive since 2017, and the account of US Space Force Chief Master Sergeant John Bentivegna. (TechCrunch) Security researcher Jane Wong said her own account was also taken over — the password changed without her knowledge, with repeated reset attempts throughout the day. (TechCrunch)
The deeper problem is what comes next. Victims said they were left without any path to reach a live person for help recovering access. (Quartz)
Chatter about the flaw on Telegram dates back to March, around when Meta broadened the AI support rollout. (Quartz) Meta's Andy Stone confirmed a fix had been applied, saying the issue was resolved and impacted accounts were being secured, though it's unclear how many accounts were accessed before the patch. (Quartz)
One thing did blunt the attack: by most accounts the trick only worked on accounts that had no two-factor authentication. (Techish) So do this now — open your Instagram settings and confirm 2FA is switched on.
Cutting costs by handing AI authority over sensitive operations, without solid verification behind it, is a decision that eventually turns on the company making it. Can account security ever be fully automated, or is human oversight still essential? Curious where you land