Ad

Hackers exploited a vulnerability in Meta's AI-powered support chatbot to take over several high-profile Instagram accounts. The issue, now fixed by Meta, allowed attackers to manipulate the chatbot into sending password reset codes to email addresses they controlled. This enabled unauthorized access without needing the account owners' inboxes or phones.
The vulnerability came to light over the weekend after accounts such as the Obama-era White House handle, beauty retailer Sephora, and US Space Force Chief Master Sergeant John Bentivegna were compromised. Security researchers ZachXBT and Dark Web Informer first reported the issue, revealing that threat actors had discovered a way to exploit Instagram's Meta AI assistant. This tool is designed to help users recover access to their accounts.
Reports on platforms like Reddit, X, and Telegram described multiple account takeovers. Attackers did not use advanced malware or phishing tactics. Instead, they targeted the AI-powered Support Assistant, which is meant to help with account recovery.
Attackers began by using a VPN to appear as if they were logging in from the same region as the targeted account. This helped them avoid Instagram's automated security checks. They then accessed Instagram's login page, selected the "Forgot Password" option, and initiated a conversation with the Meta AI Support Assistant using the "Get Support" feature.
Through carefully crafted prompts, hackers convinced the chatbot to add a new email address to the victim's account. Once the chatbot accepted the request, it sent a verification code to the attacker-controlled email address. After entering this code, the attackers could reset the account password, gaining control without needing access to the victim's actual email or phone.
In some cases, attackers simply instructed the chatbot to send password reset codes directly to their own email addresses. If successful, they could use the code to complete the takeover process.
TechCrunch independently verified part of the attack. The publication confirmed that a public email address shown in demonstration videos did receive a verification code from Instagram. However, the exploit did not always succeed on the first attempt, and attackers sometimes had to repeat the process before the chatbot complied.
The incident raised concerns about the effectiveness of two-factor authentication (2FA). Some users reported that 2FA-protected accounts remained secure, while others lost access despite having additional security measures enabled. The exact interaction between the vulnerability and Instagram's authentication systems remains unclear.
Meta spokesperson Andy Stone confirmed on Monday that the vulnerability had been resolved. The company is actively working to secure affected accounts but has not disclosed how many users were impacted. Some users have reported ongoing issues regaining access to their accounts even after the fix.
Ad

Vivo X500 Ultra Leak Suggests 10x Periscope Telephoto Camera Upgrade
A new leak suggests the vivo X500 Ultra may feature a 10x periscope telephoto camera, surpassing previous models. The X500 series is also expected to support new teleconverters and vlog cameras, reflecting increased competition.
02-Jun-2026 06:30 AM

Amazon Music Unlimited Launches in India With 100 Million Songs and New Free Tier
Amazon has launched Music Unlimited in India, offering over 100 million songs and podcasts with HD, Ultra HD, and Spatial Audio. Prime members pay Rs 99 per month, while a free ad-supported tier will launch soon.
02-Jun-2026 02:30 AM

Realme Teases Launch of P4R 5G Smartphone in India
Realme has started teasing the launch of its P4R 5G smartphone in India, confirming 5G support and hinting at a large battery. The device targets young users and more details are expected soon.
01-Jun-2026 11:30 PM

Meta AI Exploit Led to High-Profile Instagram Account Takeovers, Now Fixed
Hackers exploited a vulnerability in Meta's AI-powered support chatbot to take over high-profile Instagram accounts. Meta has fixed the issue and is working to secure affected accounts, but some users still report access problems.
01-Jun-2026 08:30 PM

Google to Open First Physical Store Outside US in Tokyo This Summer
Google will open its first physical retail store outside the US in Tokyo, Japan this summer, offering Pixel, Nest, and Fitbit devices, on-site repairs, and serving as a pick-up point for online orders.
01-Jun-2026 08:30 PM

Anthropic Files Confidential IPO, Eyes $1 Trillion Valuation Amid AI Industry Surge
Anthropic has confidentially filed for a US IPO, potentially targeting a valuation above $1 trillion. The move follows its recent lead over OpenAI in private valuation and signals growing competition in the AI industry.
01-Jun-2026 07:30 PM
Ad
Ad












Ad
Ad