Instagram has begun alerting users targeted in a widespread hacking campaign where cyber criminals hijacked accounts simply by asking Meta’s AI support chatbot to hand over access.
Over the weekend, malicious actors exploited Meta’s automated AI support system to seize control of several high-profile Instagram accounts. Concurrently, a large number of people complained on social media that their profiles had been compromised, with many of the targeted accounts holding highly coveted, short usernames.
These rare handles, often featuring common first names or country names, are highly sought after and frequently resold as collectibles in a grey market for “OG handles”. Other notable targets in this wave of attacks included the dormant Obama White House account (a claim Meta has disputed) and the profile of John Bentivegna, the Chief Master Sergeant of the US Space Force.
How Hackers Tricked Meta’s Automated Assistant
The simplicity of these breaches raises serious questions about Meta’s security protocols. Rather than deploying sophisticated exploits, the perpetrators merely convinced Meta’s AI chatbot that they were the legitimate owners of the targeted accounts.
By instructing the AI assistant to link the target account to an email address under their control, the hackers bypassed security checks entirely. The chatbot complied, enabling the attackers to reset passwords, take full control, and lock out the original owners, all without any human intervention from Meta staff.

Is the Exploit Truly Resolved?
On Monday, Meta spokesperson Andy Stone said that “the issue that did happen has already been fixed.”
However, on Tuesday, additional Instagram users reported that their accounts had been compromised. Discussions monitored within a Telegram channel dedicated to publicising this specific exploit showed members claiming they could still abuse the chatbot. At the time of writing, these individuals were actively advertising stolen handles for sale, though it remains difficult to verify if every compromised account stemmed from this exact vulnerability.
Meta’s Security Response and User Notifications
In a subsequent post on X, Stone stated: “Some people may receive password reset notifications and some may be asked security questions when they try and log into their accounts.”
Stone confirmed that Meta secured the affected accounts on Monday and initiated password reset protocols. Meta has declined to share the exact number of users impacted by this security failure.
A growing number of users have publicly shared the warning emails received from Instagram. The notifications state that the platform “detected some suspicious activity that suggests your Instagram may have been compromised,” confirming that protective measures had been applied and prompting users to reset their credentials.

The Shift from Complex Exploits to Conversational Prompts
As 404 Media noted, Meta announced in March that it was deploying AI systems to automate customer support functions. The company stated the AI assistant was designed to “resolve account issues from start to finish,” including the capability to “reset your password securely.” This transition eliminated human oversight from highly critical administrative actions.
For years, there has been a flourishing market for stolen “OG” usernames. Historically, acquiring these handles demanded sophisticated vectors, including SIM-swapping, phishing campaigns, or bribing telecommunications insiders. In this latest campaign, however, the security barrier was reduced to a simple conversation, and Meta’s automated assistant complied without verification.
