Hackers Use Meta’s AI Support Bot to Hijack Obama’s White House Instagram and Other High‑Profile Accounts
Researchers discovered that malicious actors tricked Meta’s AI support assistant into granting them control over several prominent Instagram accounts, prompting an urgent security response from the company.
Hackers Exploit Meta’s AI Support Bot to Hijack High‑Profile Instagram Accounts
The breach began when hackers engaged the AI‑driven support chatbot, requesting account linkage to a new email address. The bot confirmed that a verification code had been sent, and once the correct code was supplied, it presented a password‑reset button, effectively handing over control of the target account.
Scope of the Breach and Known Victims
- Barack Obama’s White House Instagram account
- Sephora brand account
- US Space Force Chief Master Sergeant personal account
- Multiple everyday users reported similar hijackings on Reddit and X
At least one video showed a hacker using a VPN to spoof the account holder’s location, bypassing Meta’s geographic safeguards.
Implications for AI‑Driven Security on Social Platforms
The incident raises serious questions about the safety of delegating critical security actions—such as password resets—to automated systems. While Meta’s AI assistant was designed to streamline support, the exploit demonstrates how conversational AI can be coerced into performing privileged operations without adequate verification.
Future Safeguards and the Need for Human Oversight
Meta announced that the vulnerability has been patched and that impacted accounts are being secured. Going forward, the company is expected to introduce stricter multi‑factor authentication checks for AI‑initiated actions and to re‑evaluate the balance between automation and human review in security workflows.