Attackers discovered a critical vulnerability in Meta’s AI-powered support chatbot that allowed them to bypass two-factor authentication and seize control of Instagram accounts — including high-profile targets like the inactive Barack Obama White House account, beauty retailer Sephora, and US Space Force Chief Master Sergeant John Bentivegna’s personal page.

The exploit chain was alarmingly simple: attackers spoofed their geolocation via VPN to match the target account’s region, initiated a password reset, then used prompt injection techniques to instruct Meta’s AI assistant to change the account’s email address to an attacker-controlled address. The chatbot complied without meaningful identity verification, then helpfully sent a password reset code to the new email. Account owners received no SMS alerts, push notifications, or warning emails during the entire process. Videos demonstrating the technique circulated on Telegram channels before Meta intervened.

Meta acknowledged the issue on June 2, 2026, stating “This issue has been resolved and we are securing impacted accounts.” The company characterized it as a bug, though security researchers argue it represents a fundamental architectural flaw — an AI agent was granted elevated access to account management functions without deterministic authentication checkpoints.

Sources

Commentary

This is a textbook case of what happens when companies rush AI agents into production with insufficient guardrails. An AI chatbot designed to streamline account recovery was essentially social-engineered into becoming an accomplice. The fact that no secondary verification was required — no SMS, no email to the original address, no cooldown period — suggests Meta’s AI support pipeline was designed for convenience first and security as an afterthought.

The broader lesson is clear: as organizations deploy AI agents with real system-level access, every action the agent can take needs the same authentication rigor as if a human support representative were performing it. Prompt injection against AI support bots is going to become a major attack vector, and this incident should be a wake-up call for every company deploying similar systems.

By Allan