Back to Feed
Identity & AccessJun 2, 2026

Meta AI Hands Over High-Profile Instagram Accounts to Hackers

Meta AI account recovery assistant exploited via confused deputy flaw to compromise high-profile Instagram accounts.

Summary

Threat actors compromised multiple high-profile Instagram accounts by exploiting a confused deputy vulnerability in Meta's AI-powered account recovery assistant. The attackers bypassed fraud detection using VPNs, submitted AI-modified selfies to defeat identity verification, and used the chatbot to link new email addresses and reset passwords. Meta has since patched the issue, but hundreds of accounts were reportedly compromised and sold on the dark web.

Full text

Threat actors compromised multiple high-profile Instagram accounts last week by simply asking Meta’s AI-powered account recovery assistant to hand them over. The attackers exploited a logic flaw in the AI assistant, a classic ‘confused deputy’ issue, to have their own email addresses linked to the targeted accounts and take them over. Confused deputy weaknesses have been known to security researchers for decades and involve tricking a deputy that has elevated privileges into performing specific actions on the attacker’s behalf. In this case, the Meta AI assistant had API access to account management systems, being deployed to help users re-link email addresses, reset passwords, and verify they are the owners of specific accounts. Due to the logic flaw, hackers were able to simply ask the chatbot to link a targeted account to a new email address, under the pretense that they had been hacked or that they had lost access to the previously linked email address. To bypass Meta’s fraud detection protections, they used VPNs to appear as if they were in the target’s geographic location.Advertisement. Scroll to continue reading. The AI assistant happily linked the new email address and then sent a code that allowed the attackers to reset the password for the targeted account, locking the rightful owner out. In the event that the chatbot asked for a selfie to verify account ownership, the attackers reportedly modified victims’ photos using AI tools and submitted the altered images. Inexplicably, the attack also bypassed two-factor authentication (2FA) protections for the targeted accounts, and some victims say they were never notified of the password reset attempts. Hundreds of high-profile accounts were reportedly compromised and immediately sold on the dark web. Some miscreants were seen sharing videos and instructions on how the account takeover is performed. Using the trick, the hackers gained access to the Obama White House handle and to the accounts of Sephora and John Bentivegna, the Chief Master Sergeant of the Space Force. Instagram parent company Meta has resolved the issue, and the exploit no longer works, but it’s unclear how many accounts might have been affected. SecurityWeek has emailed the company for a statement and will update this article if it responds. “This is a great illustration of why AI agent authorization is the harder, and more critical, problem than authentication. Meta’s bot verified nothing about who was asking; it just helpfully did what it was told to do, up to and including sending the attacker a confirmation code to make sure the new email address was valid. The industry is pretty focused on keeping AI from saying bad things. That’s fine, as long as we don’t completely overlook whether AI should be allowed to do what it’s trying to do,” FusionAuth senior director Dan Moore commented. Related: As the Pentagon Pushes for Battlefield AI, Some Military Leaders Urge Caution Related: Researcher Discovers 4th WhatsApp View Once Bypass; Meta Won’t Patch Related: McDonald’s Chatbot Recruitment Platform Exposed 64 Million Job Applications Related: Pro-Iranian Hacking Group Claims Credit for Hack of FBI Director Kash Patel’s Personal Account Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire 19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root AccessRecent Palo Alto Networks Vulnerability Exploited for WeeksExploit Code Published for Critical Flowise RCE VulnerabilityCharter Communications Data Breach Could Impact Nearly 5 MillionMokN Raises $15 Million for Phish-Back PlatformGogs Zero-Day Exposes Servers to Remote Code ExecutionChrome 148 Update Patches 151 VulnerabilitiesGeordie Raises $30 Million for AI Security and Governance Platform Latest News Oracle WebLogic Vulnerability Exploited in the WildSupply Chain Attack Hits 32 Red Hat NPM PackagesDashlane Brute-Force Attack Leads to Limited Encrypted Vault DownloadsOracle’s First Monthly Patches Resolve 77 VulnerabilitiesWP Maps Pro Vulnerability Exploited to Take Over WordPress SitesDutch Police Dismantle Massive 17-Million-Device BotnetCritical Windows Netlogon Vulnerability in Attackers’ CrosshairsDragos Acquires xIoT Security Firm Phosphorus Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Threat Detection and Incident Response Summit On-Demand Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization. Register Webinar: Third-Party Risk in Practice June 4, 2026 Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice. Register People on the MoveRapid7 announced that Wael Mohamed will assume the role of Chief Executive Officer, replacing current Chief Executive Officer Corey Thomas, who will become Executive Chairman of the Board.Anurag Jain has been appointed Senior Vice President of Engineering at CodeHunter.CTERA has appointed Tal Sarfaty as Senior Vice President of Cybersecurity.More People On The MoveExpert Insights Raising the Cybersecurity Stakes: Ante up for the Agentic Era CISOs are now facing machine-speed attacks and asking, “How do I agent?” The industry must provide remediation at scale. (Nadir Izrael) Caught Off Guard: Securing AI After It Hits Production As enterprises rush AI projects into production, security teams are increasingly being forced into reactive mode. (Joshua Goldfarb) Cyber Resilience is the New Business Continuity Plan The organizations best prepared to face disruption are those that align security, continuity and risk management around what the business cannot afford to lose. (Steve Durbin) Enhancing Data Center Security Without Sacrificing Performance For AI data centers, where the stakes are the highest and performance constraints are the tightest, security and performance are no longer a zero-sum game. (Nadir Izrael) Is the SOC Obsolete, and We Just Haven’t Admitted It Yet? Many AI-first enterprises have already embraced sovereign architectures for general AI initiatives; cybersecurity—and the SOC—should be next. (Danelle Au) Flipboard Reddit Whatsapp Whatsapp Email

Entities

Meta (vendor)Meta AI account recovery assistant (product)Instagram (product)confused deputy attack (technology)