Green matrix-style digital code streaming down a dark screen representing an AI security exploit
Photo via Unsplash

TL;DR: A flaw in Meta's AI support chatbot let anyone reset the password of any Instagram account that didn't have two-factor authentication enabled. The attackers didn't need to know the victim's email, phone number, or current password. They just had to ask the bot nicely. According to a data breach notification Meta filed with the Maine Attorney General on Friday, 20,225 accounts were compromised between April 17 and early June 2026. The high-profile victims included the dormant Obama White House account and the account of U.S. Space Force Chief Master Sergeant John Bentivegna. Meta disabled the chatbot and removed the vulnerable code path, but the 7-week attack window is what the company is now being forced to explain.

How the Attack Worked

TechCrunch's Lorenzo Franceschi-Bicchierai published the first report on June 1 after watching a video posted on X showing the full attack chain. The hacker used a VPN to spoof the target's presumed location, sidestepping Instagram's automated location-based protections. Then they opened a chat with Meta's AI Support Assistant and simply asked the bot to add a new email address to the victim's account [1].

The chatbot complied. It sent a verification code to the email address the hacker controlled. The hacker shared that code back with the bot. The bot then surfaced a "Reset Password" button. The hacker clicked it. Account hijacked [1][2].

At no point did the chatbot verify that the email address being added actually belonged to the account holder. It also didn't check the verification code against the email on file for the account. The bot trusted the request because the requester asked politely.

Meta's official explanation, in the breach notice: "The tool itself worked properly and functioned as intended; however due to a bug in a separate code path, the system did not properly verify that the email address provided by the individual requesting a password reset matched the email address associated with that user's Instagram account" [3].

Translation: the chatbot worked exactly as designed. The verification step (the one that was supposed to make this attack impossible) had a bug. So the system did what the chatbot told it to do, even when the chatbot was being lied to.

Seven Weeks. 20,225 Accounts. Two Failed Fixes.

According to the Maine filing, the attack window started April 17, 2026. It didn't close until early June [3].

The public timeline:

  • April 17: Earliest compromised accounts, per Maine AG filing.
  • Late May: Victims start complaining on Reddit and X. Security researcher Jane Wong says her account was taken over. Wong: "The password got changed without my knowledge and I was getting different password reset attempts throughout yesterday. Quite concerning" [1].
  • May 31 / June 1: TechCrunch publishes the exploit. 404 Media's Jason Koebler and Emanuel Maiberg confirm the same chatbot flaw on their podcast. Compromised accounts include the dormant Obama-era White House handle and the U.S. Space Force's chief master sergeant [1][2].
  • June 1 (Monday): Meta spokesperson Andy Stone tells reporters "the issue that did happen has already been fixed" [1].
  • June 2 (Tuesday): More Instagram users report hijacks. Telegram channels advertise freshly hijacked short handles for sale. The fix didn't stick [1].
  • June 3 (Wednesday): Instagram starts sending password-reset notifications to users it believes were targeted. 404 Media publishes its podcast on the exploit [2].
  • June 5 (Friday): Meta files the breach notification with the Maine Attorney General. 20,225 accounts confirmed compromised. Meta disables the AI chatbot and removes the vulnerable code path [3].

Seven weeks. Meta's "fix" took 24 hours to be bypassed. The real fix only happened after reporters and a state attorney general got involved.

Who Got Hit

The attackers weren't subtle about who they targeted. TechCrunch saw examples of "OG handles" (short usernames with common forenames or country names) that had been hijacked and listed for sale in a gray market where these accounts change hands for hundreds or thousands of dollars [1].

The high-profile confirmed victims:

  • The dormant Obama White House account: inactive since 2017, hijacked. (Meta disputed this in its breach notice, but the account clearly changed hands; screenshots circulated widely.) [1]
  • U.S. Space Force Chief Master Sergeant John Bentivegna: the highest-ranking enlisted member of the U.S. Space Force. Compromised. Not a great look for a military branch that exists to defend U.S. communications infrastructure [1].
  • Jane Wong: independent security researcher, well known in the reverse-engineering community. Account hijacked, password changed without her knowledge [1].

Then there are the 20,222 regular users. Meta's Maine filing confirms they lost access to "contact information, dates of birth, and profile information, as well as the ability to access the person's posts, direct messages, and account activity" [3]. Direct messages. For an app that handles the personal conversations of nearly two billion people, that's a significant data exposure.

Meta says it is "unaware" of what, if any, personal data the attackers actually read [3]. That is a non-denial. Attackers don't usually announce what they did with the accounts they stole.

The "Move Fast" Pattern

This is the third major Meta security or privacy failure in three months. The pattern is the same every time.

First, Meta ships a feature built on a chatbot, an AI model, or another system that makes decisions about real users. Second, the system has a flaw that a competent attacker (or, in this case, a person willing to ask a chatbot a polite question) can exploit. Third, Meta fixes it after the damage is done and after the press catches it.

June 2026 is the same pattern as April 2026, when Meta's Model Capability Initiative was caught installing keystroke-tracking software on U.S. employees' work computers without consent [4]. It's the same pattern as June 2025, when the ACLU and 75 civil society groups warned that Meta was planning to put facial recognition in Ray-Ban smart glasses, with internal documents showing Meta planned the launch "during a dynamic political environment" to minimize civil society pushback [5][6].

EFF Threat Lab summarized the philosophy in June 2025: "Move Fast, Surveil Things" [5]. The June 2026 chatbot disaster fits the pattern perfectly. Meta shipped an AI system to handle account recovery, the system had a verification bug, attackers asked it to do bad things, it did them, and 20,225 people lost their accounts.

Meta is meanwhile laying off thousands of employees while rewarding top executives with stock incentives, and "continues to double-down on AI" [3]. The trust-and-safety teams that would normally catch a verification gap like this one are the teams being cut.

What Meta Did (and Didn't) Do

As of the Maine filing, Meta has:

  • Disabled the AI support chatbot entirely
  • Removed the code path that allowed the chatbot to initiate password resets
  • Notified all 20,225 affected users by email
  • Told affected users to "reset their passwords and re-authenticate through secure, verified channels" [3]
  • Started reviewing other chatbots across Meta's platforms to look for similar vulnerabilities [3]

What Meta hasn't done, as of this writing: filed a public incident report, explained why the verification check was missing in the first place, said whether the affected accounts have been restored to their original owners, or disclosed whether the OG-handle gray market absorbed any of the stolen accounts. The company also has not said how many of the 20,225 users actually had 2FA disabled when the attack happened, which would tell us how many of the 2 billion Instagram users were always one polite chatbot conversation away from losing their account.

The attackers had seven weeks. The Telegram channels advertising hijacked handles are still online. There's no way to un-takeover 20,225 accounts and the direct messages they contained.

What You Can Do

You are one chatbot conversation away from losing your Instagram account. The fix is two minutes of settings work.

  • Turn on two-factor authentication. Now. Open Instagram, go to Settings → Accounts Center → Password and security → Two-factor authentication. Use an authenticator app, not SMS. SMS-based 2FA is better than nothing, but SIM-swap attacks are real and SIM swaps are cheap. Authy, Google Authenticator, or 1Password all work [7].
  • Check your authorized logins. Settings → Accounts Center → Password and security → Where you're logged in. If you see a device or location you don't recognize, log it out and change your password immediately.
  • Check your account email. Settings → Accounts Center → Personal details → Contact info. Make sure the email address on file is one you control. If a hacker added their own email first, the password reset route to your account is theirs.
  • Remove unused third-party app access. Settings → Website permissions → Apps and websites. Revoke anything you don't actively use. Each connected app is another attack surface for the next Meta security failure.
  • Use a unique password for Instagram. If your Instagram password is the same as your email, your bank, or anything else, change it now. A password manager (Bitwarden, 1Password, KeePass) generates and stores unique passwords for every account. Reusing passwords means one breach is every breach.
  • Watch your DMs for the next two weeks. If your account was compromised, attackers may have used it to send phishing links to your contacts. Tell people you trust to ignore anything suspicious from your account until you confirm you've regained control.
  • Consider whether you need Instagram at all. A platform that lets any attacker take over an account with one chatbot prompt is not protecting you. Your posts, your DMs, your contact list, and your identity are all stored in an app with a known verification flaw. That's not a privacy policy. That's a liability.

Sources