Meta's AI Support Bot Had Admin Access to Every Instagram Account. Hackers Just Asked.
What happened
When Meta deployed its AI customer support assistant across Facebook and Instagram in early 2026, the company handed the system something it had never given a bot before at this scale: real administrative authority over user accounts. The chatbot could modify email addresses, trigger password resets, and effectively transfer account ownership. That capability, routed through a conversational interface that anyone could prompt, became the mechanism for the largest account-takeover campaign the platform had seen.
Starting April 17, 2026, attackers found that the High Touch Support chatbot would re-link any Instagram account to a new email address on request. No confirmation from the original account holder was required. A VPN was enough to mimic the victim's general location, satisfying the only automated check the system ran before sending a one-time verification code to the attacker's inbox. From there, a standard password reset locked out the original owner. Meta patched the flaw around May 29, but the window had been open for six weeks.
The breach surfaced publicly over the weekend of May 31 when a wave of high-profile hijackings became visible. The former Obama White House account was taken over, along with those of U.S. Space Force Chief Master Sergeant John Bentivegna, retailer Sephora, and security researcher Jane Manchun Wong. Some accounts were defaced with pro-Iranian messages; others appeared for sale on messaging platforms. When Meta filed a breach notification with the Maine Attorney General's office on June 5, the confirmed count was 20,225 affected accounts.
The root cause was not a malfunction. The chatbot did what it was designed to do: act on support requests. The problem was that Meta granted it elevated privileges to execute sensitive account changes without any out-of-band check against the account's original owner. The system's own assessment of whether a request was legitimate was the only gate. Human agents, who might have caught inconsistencies, had been largely replaced by the automated system, leaving affected users few options for rapid recovery once the takeovers began.
Maine's breach-notification law is what forced disclosure. Without that requirement, the full count might have stayed internal indefinitely. That is the accountability gap this incident exposes: a provable record of what a system did, which requests it acted on, under what authority, and when, would have made the scope of the breach visible in real time rather than weeks after the fact. Any deployment that grants an AI system administrative authority over identity should carry that kind of record as a baseline requirement, not as an afterthought prompted by a state filing.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.