Close Menu
Semi-CurrentSemi-Current
  • News
  • Reviews
  • Guides
  • About
Facebook X (Twitter) Instagram
Semi-CurrentSemi-Current
  • News
  • Reviews
  • Guides
  • About
Facebook X (Twitter) Instagram
Semi-CurrentSemi-Current
Home » Meta patches an Instagram flaw that let its own AI hand over accounts
AI & Software

Meta patches an Instagram flaw that let its own AI hand over accounts

Turns out "just ask the chatbot" was a valid password-reset method?
David GonzalesBy David Gonzales3 June 20262 Mins Read
Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
Meta AI with instagram on screen
Share
Facebook Twitter LinkedIn Pinterest Email
  • Meta patched a flaw in its AI support assistant that let attackers reset an Instagram account’s password by spoofing the victim’s location and asking the bot to add a new email.
  • Over the weekend, attackers used it to hijack high-profile accounts — including an Obama-era White House handle and the US Space Force’s top enlisted leader — and deface them with pro-Iran propaganda.
  • Meta says the issue is fixed and accounts are being secured; the flaw stemmed from giving a support chatbot the power to change account details.

Meta has fixed a flaw in its AI support assistant that let attackers take over Instagram accounts without a password. “We fixed an issue that allowed an external party to request password reset emails for some Instagram users,” Meta spokesperson Andy Stone said, adding there was “no breach” of Meta’s systems.

The method, as reported and not disputed by Meta: spoof the target’s location over a VPN, ask the Meta AI Support Assistant to add a new email to the account, and let the bot send a password-reset code to the attacker’s address.

The exploit worked because the assistant could change account contact details with no real check on who was asking. Over the weekend it was used in the wild — not by researchers filing a disclosure, but by attackers hitting live accounts. The hijacked handles included an Obama-era White House Instagram, US Space Force senior enlisted advisor John Bentivegna, the email app @hey, and Sephora — several of them defaced with imagery praising Qassem Soleimani. A group calling itself Handala Hack Team claimed responsibility. Stone said the issue “has been resolved and we are securing impacted accounts.”

This particular flaw sits in a broader pattern: companies are giving customer-support AI real account powers and treating the conversation itself as the security check. Philippine banks, telcos, and e-commerce apps have spent the past year replacing human support with chatbots built on the same architecture this attack exploited.

Meta attributed the takeovers to the support assistant’s account-change permissions rather than to any breach of its systems. That leaves open what other account actions the same assistant can take, and under what checks — the part Meta hasn’t detailed.

AI Cybersecurity Hacks Instagram Meta Meta AI Social media
Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
David Gonzales
  • Website
  • Facebook
  • X (Twitter)
  • Instagram

Founder and Editor-in-Chief at SemiCurrent.com

Related Posts

Industry & Business 3 June 2026

Anthropic files confidentially for an IPO, beating OpenAI to the gate

Computing 3 June 2026

Nvidia’s RTX Spark brings a Blackwell GPU and on-device AI to laptops

Industry & Business 3 June 2026

Ayala ties up with Japanese conglomerates for first ‘intelligent city’ in Philippines

Desktop 4 December 2025

Micron to kill off Crucial-branded consumer memory business in 2026

Leave A Reply Cancel Reply

Recent Posts

  • Acer Nitro 16 debuts AMD’s Ryzen 9 9955HX3D, a first for its gaming laptops
  • Acer’s Predator Helios 18 AI tops out at an RTX 5090 and 256GB of RAM
  • Asus ROG Strix SCAR 18 debuts an 18-inch 4K 240Hz mini-LED display, 320W of power
  • AMD’s budget-friendly Ryzen 7 7700X3D extends AM5 support through 2029
  • Honor 600 draws Philippine crowds on sale day, with a Mercedes on the line

Recent Comments

No comments to show.
New Comments

    Archives

    • June 2026
    • December 2025

    Categories

    • AI & Software
    • Computing
    • Desktop
    • Gadgets
    • Gaming
    • Industry & Business
    • Mobile
    Facebook Instagram X (Twitter)
    © 2026 Semi-Current · The latest in tech, more or less · Words and Design by David Gonzales

    Type above and press Enter to search. Press Esc to cancel.