Meta AI Support Exploit Hijacks Obama White House Instagram Account

Meta AI Support Exploit Hijacks Obama White House Instagram Account

Instagran app icon on smartphone.

Source: Brett Jordan/Unsplash

Écrit par
Liz Ticong
Liz Ticong
Jun 2, 2026
2 minute read
eWeek Le contenu et les recommandations de produits sont indépendants de la rédaction. Nous pouvons gagner de l'argent lorsque vous cliquez sur des liens vers nos partenaires. En savoir plus

Instagram account takeovers are often associated with stolen passwords, phishing links, or compromised email accounts. The latest breach ran through Meta’s own support system.

Hackers used Meta’s AI support assistant to carry out a series of Instagram account takeovers, including one targeting the archived Obama White House account, according to reports. High-profile targets gave the breach a wider impact, but the risk sits in the account-recovery process itself.

A recovery feature became the route into the account.

How the reset flow was abused

The X walkthrough showed a takeover beginning in an unexpected place, inside a support chat. Instead of stealing the victim’s password, the attacker appeared to use a VPN near the target’s presumed location, then asked Meta’s AI Support Assistant to add a new email address to the Instagram account.

From there, the recovery flow did the rest. A verification code was sent to the attacker’s inbox, fed back into the chat, and the bot surfaced the option to reset the password.

The original email account never had to be compromised. TechCrunch verified that the public inbox shown in the video received the verification code, while KrebsOnSecurity reported that similar instructions had circulated on Telegram.

Meta later said the issue had been fixed. “This issue has been resolved and we are securing impacted accounts,” company spokesperson Andy Stone wrote on X. 

Big-name account takeovers exposed the scale of the risk

Aside from the archived Obama White House account, Sephora, and the US Space Force Chief Master Sgt. John Bentivegna was reportedly among the affected accounts. Security researcher Jane Manchun Wong also said her Instagram account was taken over after a series of password reset attempts.

Some hijacked accounts were briefly defaced with pro-Iranian images and messages. Other targets appeared to be valuable short Instagram handles, the kind often chased in account-theft markets because they can be resold for large sums.

Recognizable public accounts, security professionals, consumer brands, and prized usernames were all pulled into the same breach, showing how the recovery weakness could affect very different types of Instagram users.

Advertisement

AI support bots are becoming security targets 

Account controls such as recovery details, identity checks, and password reset flows make AI support tools attractive to attackers.

Ian Goldin, a threat researcher at Lumen’s Black Lotus Labs, told KrebsOnSecurity that large platforms are entering “unchartered security territory” as AI chatbots take on sensitive recovery requests. “AI chatbots create interesting new attack surface, and we’re likely going to see a lot more of these kinds of attacks,” Goldin said.

Human help desks have long been vulnerable to social engineering. AI support automates that problem, giving attackers a system they can probe until the recovery flow gives way.

Permiso researchers found a prompt-injection flaw that can make ChatGPT summaries display phishing links and QR codes.

Liz Ticong

Liz Ticong is a tech industry expert with hands-on experience in AI, software testing, and product analysis. Specializing in AI news, software reviews, and buyer’s guides, she rigorously tests and experiments with the latest AI and tech tools to provide in-depth, practical insights. As a contributor to eWeek and TechRepublic, she simplifies complex topics, helping readers make well-informed decisions.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Propriété de TechnologyAdvice. © 2026 TechnologyAdvice. Tous droits réservés

Divulgation publicitaire : Certains des produits qui apparaissent sur ce site proviennent d'entreprises dont TechnologyAdvice reçoit une compensation. Cette compensation peut influencer la façon dont les produits apparaissent sur ce site, notamment l'ordre dans lequel ils apparaissent. TechnologyAdvice n'inclut pas toutes les entreprises ou tous les types de produits disponibles sur le marché.