Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsStudyTraining
ProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Study
Training
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

1310+ Articles
157+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Hackers Used Meta's AI Support Bot to Seize Instagram Accounts
Hackers Used Meta's AI Support Bot to Seize Instagram Accounts
NEWS

Hackers Used Meta's AI Support Bot to Seize Instagram Accounts

Iran-linked hackers exploited Meta's AI support assistant to reset account credentials, briefly defacing the Instagram accounts of the Obama White House and the Chief Master Sergeant of the U.S. Space Force with pro-Iranian content.

Dylan H.

News Desk

June 1, 2026
5 min read

Overview

Iran-linked threat actors have discovered a method to manipulate Meta's AI support assistant into resetting account credentials, enabling unauthorized takeovers of high-profile Instagram accounts. The attacks briefly defaced the Instagram accounts of the Obama White House and the Chief Master Sergeant of the U.S. Space Force with pro-Iranian imagery and messaging.

Instructions for the technique began circulating on Telegram over the weekend, enabling a broader wave of copycats to replicate the attack method. The incident represents a novel abuse of AI-powered customer support systems to bypass traditional account security controls.


How the Attack Works

According to KrebsOnSecurity, attackers discovered that Meta's "AI support assistant" could be manipulated through carefully crafted social engineering prompts to initiate account recovery actions. The technique essentially:

  1. Engages Meta's AI support chatbot with a targeted account inquiry
  2. Uses prompt engineering techniques to guide the bot toward initiating a password or email reset
  3. Redirects account recovery communications to attacker-controlled contact information
  4. Gains full access to the target account after recovery flow completion

The exact prompt sequences were shared publicly on Telegram channels, significantly lowering the barrier for other attackers to replicate the method.


High-Profile Victims

AccountAffiliationContent Posted
Obama White HouseFormer U.S. President's official pagePro-Iranian imagery and messaging
Chief Master Sergeant, U.S. Space ForceU.S. military officialPro-Iranian imagery and messaging

Both accounts were temporarily defaced before being recovered and restored. The selection of high-visibility targets with ties to U.S. government and military suggests an influence operation component beyond pure account compromise.


The AI Support Bot Attack Surface

This incident highlights a critical and underexplored attack surface: AI-powered customer support chatbots. As companies deploy increasingly capable AI systems to handle customer service, these systems inherit the trust and access levels of the support processes they automate.

Key risks include:

  • Social engineering susceptibility: LLM-based chatbots can be manipulated through adversarial prompting techniques
  • Access to privileged actions: Support bots are often authorized to initiate account recovery, email changes, and other high-impact actions
  • Lack of human verification checkpoints: Automated systems may not apply the same skepticism a human support agent would
  • Rapid scalability: Unlike human agents, bot exploits can be replicated at machine speed once instructions are shared

Broader Implications for AI-Powered Support

The technique represents a category of attacks that will likely increase as AI support systems become more prevalent:

Traditional Social Engineering:
  Attacker → Human Support Agent → Account Recovery
  Risk: Human agent may verify identity, apply skepticism
 
AI Support Bot Attack:
  Attacker → AI Chatbot → Automated Account Recovery
  Risk: Bot follows programmed logic; adversarial prompts
        can manipulate reasoning toward attacker goals

Security researchers have long warned that deploying AI systems with access to sensitive account actions creates novel attack surfaces. This incident is the first widely documented case of AI support bot manipulation being used at scale against high-profile targets.


Meta's Response

Meta has not publicly detailed the specific vulnerability in its AI support system or confirmed the exact mechanism exploited. The company is expected to:

  • Disable or restrict the specific functionality that enabled account recovery via the AI bot
  • Add additional identity verification requirements before the AI can initiate sensitive account actions
  • Review prompt injection mitigations within the support bot system
  • Monitor for continued exploitation attempts using similar techniques

Given that the attack instructions circulated broadly on Telegram, Meta faces pressure to close the vulnerability quickly to prevent ongoing abuse by less sophisticated actors.


What Instagram Users Should Do

Secure High-Value Accounts Now

  1. Enable two-factor authentication (2FA) on your Instagram account

    • Settings → Security → Two-Factor Authentication
    • Use an authenticator app rather than SMS
  2. Review linked email and phone numbers

    • Ensure account recovery contacts are current and under your control
    • Remove any unrecognized recovery methods
  3. Use Instagram's "Login Activity" feature

    • Check for any suspicious login sessions or locations
    • Log out of all devices if anything appears unusual
  4. Enable login alerts

    • Settings → Security → Login Alerts
    • Receive notifications for any new device logins

For Organizations and Public Figures

Organizations managing high-profile social media accounts should:

  • Implement additional access controls beyond standard account security
  • Monitor accounts for unauthorized changes (profile images, bio, linked email)
  • Establish incident response procedures for rapid account recovery
  • Consider dedicated security keys (FIDO2/WebAuthn) for account 2FA

The Telegram Amplification Problem

The rapid spread of exploitation instructions via Telegram represents a recurring challenge in the modern threat landscape. Once a working technique is documented and shared:

  1. The attack is replicated by actors of varying sophistication
  2. Targeted victims expand beyond the initial high-profile cases
  3. Defenders must race to close the vulnerability before broad exploitation

This incident follows a pattern seen with ClickFix, device code phishing, and other attack techniques that spread virally through cybercriminal communication channels.


Key Takeaways

  1. AI support bots are a new social engineering attack surface — manipulation of LLM-based chatbots can enable unauthorized account actions
  2. High-profile U.S. government-linked accounts were defaced in an apparent Iran-linked influence operation
  3. Telegram amplified the technique to a broader attacker audience within hours
  4. Account recovery flows are the weak link — robust 2FA and recovery contact security are critical defenses
  5. Meta must add AI-specific security controls to prevent chatbots from being manipulated into executing sensitive account operations

Sources

  • KrebsOnSecurity — Hackers Used Meta's AI Support Bot to Seize Instagram Accounts
#Meta#Instagram#AI#Account Takeover#Iran#Social Engineering#Artificial Intelligence

Related Articles

Claude AI Artifacts Abused to Distribute macOS Infostealer

Threat actors are abusing publicly shared Claude AI artifacts and Google Ads to deliver the MacSync infostealer to macOS users through ClickFix social...

3 min read

Malicious Chrome Extension 'CL Suite' Steals Meta Business

Security researchers have uncovered a malicious Chrome extension called CL Suite that steals TOTP 2FA seeds, Meta Business Manager data, and analytics,...

3 min read

All Four Major Nation-State Adversaries Now Weaponizing

Google reports that APT groups from China, Russia, Iran, and North Korea are all actively using Gemini AI for cyber operations including target...

3 min read
Back to all News