Meta's AI Support Bot Handed Out Password Resets to Anyone Who Asked Nicely
A pro-Iran Telegram channel published a walkthrough showing how Instagram's conversational recovery assistant could be talked into linking attacker-controlled email addresses to target accounts. The Obama White House and a senior U.S. Space Force account were briefly defaced.

Over the weekend of May 31, the dormant Instagram account belonging to the Obama White House and the account of the Chief Master Sergeant of the U.S. Space Force were briefly defaced with pro-Iranian imagery. The entry point was not a zero-day. It was a chatbot.
Instructions circulating on Telegram laid out a four-step recipe: connect through a VPN exit node geolocated near the target's usual location, request a password reset on the target Instagram account, open a chat with Meta's AI support assistant, and ask the assistant to link a fresh email address to the account. The bot complied. It then sent a one-time code to the attacker-supplied address, and the reset went through.
A video posted to the Telegram channel walks through the exploit end to end. The same channel claimed the technique was used to seize short, high-value Instagram handles with a secondary-market value north of half a million dollars.
Meta has not publicly responded to questions about the video but reportedly confirmed the Obama White House account was briefly compromised. An emergency patch was pushed over the weekend. No backend database was breached — the failure sat entirely in the support-assistant logic that was supposed to reduce friction for users locked out of their accounts.
The exposed data category here is narrow but serious: account-recovery control. No PII dump, no record count to publish. What was leaked was effectively the authority to issue password resets, gated by a chatbot that treated persuasion as authorization.
This is the part worth sitting with. Conversational AI is being wired into the most sensitive workflow a platform operates, which is account takeover prevention. Human support agents have always been a social-engineering target. Bots are arguably worse: they're consistent, patient, and trained to be helpful.
Notably, the Telegram operators said the technique failed against any account with multi-factor authentication enabled, including SMS-based MFA. That's a low bar Instagram users can clear in under a minute.
Jurisdiction is murky. The FTC has standing interest in Meta's account-security representations under the 2020 consent order, and the Irish Data Protection Commission remains lead supervisory authority for Meta in the EU under GDPR. Neither has publicly opened an inquiry tied to this incident.
What affected users should do
- Turn on MFA on Instagram now. A passkey or hardware security key is strongest; an authenticator app is solid; SMS is the floor and, per the attackers themselves, still defeated this exploit.
- Review Settings → Accounts Center → Password and security → Where you're logged in and revoke unfamiliar sessions.
- Check the email addresses and phone numbers attached to your account under Personal details. Remove anything you don't recognize.
- If your account was reset without your action between May 30 and June 2, assume the recovery email was swapped and contact Meta support to restore the original.



