Key Takeaways
- Hackers accessed Meta’s AI support chatbot and forced email changes on over 200 Instagram accounts, including several celebrity profiles.
- The vulnerability allowed attackers to bypass two‑factor authentication by manipulating the email‑reset flow.
- Indian users are advised to re‑verify their Instagram email addresses; the fix rolls out globally on June 5, 2026.
- Meta confirmed the issue is patched, but recommends enabling login alerts and using authentication apps instead of SMS OTPs.
Alright, let’s break this down. A few weeks ago a handful of security researchers posted screenshots of a conversation with Meta’s AI‑powered support bot. The bot, meant to help with routine account issues, was apparently tricked into confirming a request to change the email tied to an Instagram account. Once the email was swapped, the hacker could reset the password and take over the profile.
What actually happened?
The attackers started a chat with Meta’s “Meta Support” bot on the Facebook Help Center. By feeding the bot a very specific sequence of prompts – basically asking it to “verify my email change request” – the bot responded with a confirmation code that the hackers could capture. Using that code, they completed the email‑change flow on Instagram.
Because Instagram’s password‑reset relies on the email address, once the email was under the attacker’s control they could request a password reset link, set a new password, and lock the original owner out. In many cases the victims also had two‑factor authentication (2FA) enabled, but it was SMS‑based. The attackers simply intercepted the OTP by hijacking the newly‑added email, which sent the OTP to the attacker’s inbox.
Numbers and scope
- More than 200 Instagram accounts were reported compromised, including public figures, brands, and some Indian influencers.
- At least 15 accounts belonged to Indian users with verified badges.
- The exploit was active from early March 2026 until Meta rolled out a patch on June 5, 2026.
- Meta’s internal logs show the AI bot processed roughly 12,000 email‑change requests per day during the window.
Why did the AI bot become the weak link?
Meta introduced the AI chatbot to reduce wait times for routine queries. It uses a large language model trained on internal support documents. Unfortunately, the model was not hardened against “prompt injection” – a technique where an attacker crafts inputs that steer the model to reveal or perform unintended actions.
In this case, the hackers discovered that by asking the bot to "repeat the verification step for changing my email" the bot would output the exact code it sent to the user’s current email address. The bot didn’t check whether the requester was the legitimate account owner.
What does this mean for Indian Instagram users?
India is the second‑largest market for Instagram, with over 380 million monthly active users. A breach like this can lead to brand impersonation, fraud, and loss of follower trust – especially for businesses that rely on Instagram for sales (think of fashion boutiques, food delivery partners, and regional influencers).
Most Indian users still rely on SMS OTPs for 2FA, which is less secure than authenticator apps (Google Authenticator, Authy, etc.). If the email is compromised, the SMS OTP can be intercepted via SIM‑swap or social engineering, making the whole chain vulnerable.
Meta’s response
Meta released a statement on June 3, 2026, confirming the vulnerability and saying they have "implemented stricter verification checks" for the AI chatbot. The fix includes:
- Blocking the bot from disclosing verification codes.
- Adding a mandatory “account ownership” check that requires a recent login on the device.
- Prompting users to confirm email changes via a push notification on the Instagram app, not just via email.
The company also rolled out a forced re‑verification for all accounts that changed their email in the last three months. Users received a notification to review their security settings.
What should you do right now?
- Check your email address. Open Instagram, go to Settings → Account → Personal Information, and verify the email listed.
- Enable login alerts. Turn on “Login Activity” notifications so you get an alert every time a new device logs in.
- Switch to an authenticator app. Go to Settings → Security → Two‑Factor Authentication and select “Authentication App”.
- Review connected apps. Revoke any third‑party apps you don’t recognize.
- Update your password. Use a unique, long passphrase – avoid dictionary words.
Our take – TamilTech‑ஓட கருத்து
Meta’s AI chatbot was supposed to be a convenience, but it turned into an attack surface. The incident highlights two big lessons for Indian users:
- Never rely solely on email‑based verification, especially when you’re using a platform that offers stronger options.
- AI‑driven support tools need rigorous security testing before they go live – prompt injection is a real threat.
Overall, the fix looks solid, but the damage is already done for those high‑profile accounts. If you run a business on Instagram, treat this as a wake‑up call and tighten every security layer you can.
What’s next?
Meta is expected to roll out a broader AI‑security framework across Facebook, WhatsApp, and the new Threads app. Keep an eye on updates – the next wave might target the same AI‑chat flow for account recovery on those platforms.
Stay safe, keep your recovery options updated, and don’t let a friendly bot become your worst enemy.



Comments (0)
Be the first to comment!