Hackers hijacked Instagram accounts by asking Meta’s own AI chatbot to reset the password

https://media.thenextweb.com/2026/06/hackers-tricked-meta-ai-chatbot-instagram-account-hijack.avif

TL;DR

Hackers tricked Meta’s AI support chatbot into adding their email to victims’ Instagram accounts and resetting passwords. No victim email access needed.

Hackers hijacked Instagram accounts over the weekend by tricking Meta’s own AI-powered support chatbot into granting them access. The attack required no access to the victim’s email, no phishing link, and no malware. The hacker simply asked the chatbot to add a new email address to someone else’s account.

A video posted on X showed the step-by-step process. The hacker used a VPN to spoof the target’s presumed location, avoiding Instagram’s automated account protections. They then opened a chat with Meta AI Support Assistant and asked the bot to add a new email address to the target’s account.

The chatbot sent a verification code to the hacker’s email address. The hacker shared the code back with the chatbot. The bot then displayed a “Reset Password” button....

Copyright of this story solely belongs to thenextweb.com. To see the full text click HERE