Over the weekend, the Instagram profiles associated with the Obama administration and the Chief Master Sergeant of the U.S. Space Force faced a temporary breach, displaying pro-Iranian content, following a wave of instructions shared on Telegram that outlined a method to manipulate Meta’s AI support assistant into resetting account passwords.
On May 31, a series of messages circulated across various Telegram channels, revealing that Meta’s AI bot was programmed to add a new email address during its standard password reset procedure.
A video shared by pro-Iranian hackers on Telegram showcased a surprisingly straightforward method that seemed to involve using a VPN with an IP address matching or near the target's home location. The process included requesting a password reset, then interacting with Meta’s AI support assistant. The video depicted how the attacker instructed the bot to link the account to a new email, prompting the bot to send a one-time verification code for the password reset.
Alongside the video, the Telegram account provided screenshots of pro-Iranian imagery and messages that defaced the hacked Instagram accounts, claiming that this exploit had facilitated the takeover of numerous high-value Instagram usernames, potentially worth over half a million dollars on the resale market.
While Meta has yet to respond to inquiries about these claims, Andy Stone from Meta announced on Twitter/X that the issue had been addressed and that they were working to secure the compromised accounts. The cybersecurity blog thecybersecguru.com reported that Meta implemented an emergency fix over the weekend, reassuring users that no backend databases had been accessed.
The blog pointed out that Instagram has a reputation for having a subpar human support system, making the recovery of a locked account, especially a valuable one, an arduous process that could involve weeks of interaction with an automated ticketing system. Meta's strategy included introducing a conversational AI layer to streamline common recovery tasks like re-establishing lost email addresses and verifying account ownership. This assistant was presumably intended to help users navigating the often frustrating experience of account access issues.
Threat researcher Ian Goldin from Lumen’s Black Lotus Labs noted that we are venturing into new security challenges as major online platforms increasingly lean on AI chatbots for sensitive account recovery tasks. He cautioned that just as human support staff can be manipulated into granting unauthorized access, AI bots are also prone to deception and manipulation.
“AI chatbots introduce a novel attack vector, and we can expect to see more incidents of this nature,” Goldin stated.
To safeguard your online accounts, it’s crucial to utilize the most secure forms of multi-factor authentication (MFA) available, such as passkeys or security keys. Even the most basic MFA, like receiving a one-time code via SMS, could have thwarted this particular exploit, as the hackers noted their methods were ineffective on accounts with MFA activated.



