A Instagram hacking via Meta AI allowed hackers to take control of high-profile accounts, including the White House's, by simply tricking the platform's support chatbot.
A technique accessible to anyone
On June 1, 2026, numerous users began reporting on X and Reddit the compromise of their Instagram accounts. The attack vector identified by security researchers is as surprising as it is alarming: the support chatbot integrated into Meta AI, designed to help users solve their problems, was turned against them with disconcerting ease.
The procedure exploited required no particular technical skill. Hackers first initiated a standard password reset procedure, then selected "Meta AI Support Assistant" as the contact channel. They then simply asked the chatbot to associate a new email address with a target account, providing only the victim's username (@usernameusername). Without any prior identity verification, the bot executed the request and sent a confirmation code to the email address provided by the attacker. This code then allowed them to set a new password and simultaneously log out the legitimate owner from all their devices.
TechCrunch was able to verify that the attacker's public inbox, visible in a demonstration video posted on X by the Dark Web Informer account on June 1, 2026, had indeed received the verification code sent by Instagram. The flaw lay in a glaring blind spot: at no point in the process did the attacker need to access the legitimate email address associated with the targeted account. To bypass Instagram's automatic geographic protections, hackers also used a VPN to simulate a location close to that of their target.
Prominent figures among the victims
The incident quickly took on symbolic significance due to the profiles targeted. Among the compromised accounts were the Instagram handle of the Obama-era White House, inactive since 2017, and the account of Chief Master Sergeant John Bentivegna of the U.S. Space Force, according to information published by TechCrunch. Security researcher Jane Manchun Wong herself confirmed that her account had been taken over by unknown individuals.
"The password was changed without my knowledge and I received several password reset attempts throughout yesterday," stated Jane Manchun Wong in an X post. ("The password got changed without my knowledge and I was getting different password reset attempts throughout yesterday.")
According to several testimonies published online, the targeted accounts shared a common characteristic: short, rare, or high-value usernames, prized on underground markets where they can be resold at high prices. The selection of victims therefore does not appear to have been random.
Two-factor authentication, the only effective shield
A crucial point emerges from the analysis of this incident: the flaw only operated on accounts lacking two-factor authentication. Dark Web Informer explicitly stated this in their X post accompanied by the demonstration video: the exploit allowed password resets only on accounts without multi-factor authentication enabled. This clarification significantly changes the interpretation of the affair.
The two-factor authentication on Instagram Thus, it constitutes the first line of defense against this type of social engineering attack. On accounts protected by this measure, even if an attacker managed to associate a fraudulent email address via the chatbot, they would be blocked by the need to validate a second factor, via an authentication app or SMS, which only the legitimate owner can provide. This is a concrete reminder of the fundamental usefulness of this protection, too often neglected by users who keep the default security settings.
A structural problem for support chatbots
This episode illustrates a vulnerability that goes beyond a simple software bug. The large language models that power support chatbots do not, by nature, have an identity verification mechanism. They process text requests, evaluate their plausibility, and respond accordingly. A sufficiently plausible formulation, in the correct format, can therefore lead them to execute sensitive actions without any human control in the loop.
This architecture raises a fundamental question for all companies that have integrated AI agents into their customer support processes: what is the granularity of permissions granted to these systems? In Meta's case, the Meta AI Support Assistant apparently had the ability to modify account information without prior authentication of the requesting user. This level of delegation proved incompatible with the security requirements of a platform used by billions of people worldwide.
Meta closes the gap and focuses on child protection
Meta's reaction was swift. Andy Stone, an Instagram spokesperson, confirmed the fix deployed in an X post published on June 2, 2026. The exact number of compromised accounts was not disclosed, and the company did not respond to TechCrunch's request for comment at the time of publication.
In a very different context, Meta also announced on June 2, 2026, in an official press release, the global rollout of new content settings for teen accounts on Instagram, Facebook, and Messenger. This system, called "13+ content setting" and inspired by film classification criteria and parental feedback, is enabled by default for minors. The platform also states it is testing a feature to limit the repeated exposure of young users to certain types of content that could affect their mental health, such as posts about nutrition or anxiety management, when viewed in large quantities. According to Meta, nine out of ten teens who have access to this setting have kept it since its launch in October 2025 in the United States, the United Kingdom, Australia, and Canada.
For any Instagram user, the lesson from this episode is immediate: enabling two-factor authentication in the account's security settings remains the simplest and most effective measure to protect against this type of attack, regardless of its sophistication. In an ecosystem where tools meant to help can become vectors of intrusion, relying on a verification factor independent of the chatbot is no longer an option.


No comments yet — start the discussion!