Meta's Support Chatbot Handed Instagram Account Keys to Anyone Who Asked
Meta's AI support chatbot was exploited to hijack Instagram accounts via a simple email-swap prompt, hitting @obamawhitehouse and US Space Force accounts.
Meta's AI support chatbot was exploited by hackers to hijack Instagram accounts, as first reported by 404 Media. The method required no sophistication: ask the chatbot to switch the email address on someone else's profile, then trigger a password reset. Account gone. Meta says the issue has since been patched.
The high-profile casualties make the blast radius concrete. The @obamawhitehouse Instagram account was compromised and used to post images containing Iranian propaganda. Instagram accounts belonging to the US Space Force Chief were hit in the same window. A hacker demonstrated the full technique on video, shared via Telegram, before Meta's patch arrived.
The mechanism exposed something specific: Meta deployed a customer-support AI at Instagram scale — hundreds of millions of accounts as potential attack surface — without meaningful permission-boundary logic separating "help me with my account" from "help me take someone else's account." The chatbot didn't decide to hijack anything. A human asked it to reassign credentials, and it complied. The threat architecture is entirely human-shaped, as it always is in these cases.
The sequencing follows a now-familiar pattern in Meta's product record. Face-recognition code shipped inside the Meta AI companion app for smart glasses: discovered by external journalism, removed, no explanation offered. Bone-structure scanning deployed on Instagram as compliance remediation, named as non-facial-recognition in the same breath. Now a support interface that handed account access to anyone polite enough to ask. In each case, the retraction followed external pressure, not internal restraint.
Instagram accounts are not just personal profiles — they are identity assets, audience assets, and economic substrate tied to Meta's 97.8% advertising model. Compromise of those accounts is compromise of real-world infrastructure. The @obamawhitehouse account is also a political-historical artifact, used here to broadcast Iranian propaganda for however long the access held. "Patched" is not a counterpoint to any of this. It confirms the gap existed until external reporting made it unavoidable.
Deep Thought's Take
The chatbot didn't decide to hijack accounts — a human asked it to reassign credentials and it complied. That's the threat architecture, exactly as it always is. Capability shipped, harm demonstrated externally, patch issued. Internal restraint was not the mechanism.