• JADEPUFFER: the first agentic ransomware

  • JADEPUFFER: the first agentic ransomware

  • External Attack Surface Management: reducing your external exposure

  • External Attack Surface Management: reducing your external exposure

  • Stay ahead of threats to your industry with real-time intelligence.

  • Stay ahead of threats to your industry with real-time intelligence.

  • Your executives are targets. Monitor your leadership's digital exposure.

  • Your executives are targets. Monitor your leadership's digital exposure.

The Instagram icon on a smartphone screen

Threat News

3 min read

Meta AI support flaw exposes immediate account takeover risk on Instagram

safe-e Intelligence Team

Cyber Threat Intelligence

No hacking required. All it took was a conversation with Meta’s AI assistant, asking to link a new email to the target account.

If your organization relies on Instagram for branding, communications, paid media, or executive presence, this alert requires immediate action.

You don’t need to know how to hack to hijack an Instagram account. In reported cases, all it took was a conversation with an AI support chatbot.

What happened

On June 1, 2026, multiple Instagram accounts were reported hijacked after attackers manipulated the Meta AI Support Assistant. Among the accounts cited in public sources: the Obama-era White House profile, Sephora’s corporate account, and a security researcher who reported seeing her own password changed without authorization.

The reported flow was straightforward:

  1. The attacker opened a conversation with Meta’s AI assistant.

  2. Asked, in natural language, to link a new email to the target account.

  3. The assistant sent the verification code to the attacker’s email.

  4. The attacker entered the code.

  5. The password reset option appeared.

Account hijacked. Without the victim’s password. Without access to the original email. Without relying on traditional phishing.

The critical issue isn’t that the AI responded incorrectly. It’s that the agent had permission to act on digital identity without proportional validation of who was making the request.

Why this is different

Traditional account takeover attacks depend on something already compromised: a leaked password, a hacked email, a SIM swap. In this case, the attack surface shifted to the conversation with the AI agent.

Technically, the case aligns with OWASP LLM06, Excessive Agency: when an AI agent is granted more permissions than necessary to operate safely. The chatbot began functioning as a conversational layer over privileged identity flows.

This pattern is not limited to social media. Any agent with write access to support, CRM, IAM, fraud prevention, HR, or SaaS operates under the same risk.

What is confirmed and what remains uncertain

Meta declared the issue resolved. On June 2, new posts on X/Twitter indicated the vector might still be functional "in some form." These reports alone do not confirm that the original vulnerability remains fully exploitable, but for defensive purposes the message is clear: critical accounts must be audited and monitored now.

One relevant data point, attributed to the attackers themselves according to KrebsOnSecurity: accounts with MFA enabled resisted the exploitation vector.

What to do now

  1. Enable strong MFA today. Prioritize passkeys or an authenticator app. SMS OTP is the minimum emergency fallback.

  2. Audit critical Meta accounts. Review recovery emails, active sessions, trusted devices, and Business Manager administrators. Remove personal or ungoverned corporate access.

  3. Review the last 90 days. Look for password reset attempts, email changes, unusual logins, or unauthorized changes to bio, links, and ads.

  4. Prepare a channel hijacking response plan. Define who contacts Meta, who preserves evidence, what to communicate if the account is used for fraud or phishing, and how to immediately pause paid campaigns.

  5. Pause paid campaigns, if necessary. A compromised account with active ads can amplify fraud or reputational damage.

The broader warning

Instagram was the visible target this time. But when an AI agent can reset passwords, modify customer data, or trigger sensitive APIs, it isn’t just a chatbot. It’s a privileged attack surface.

The correct evaluation of any conversational automation should not only ask "what does it answer?" It must also ask "what can it do, on behalf of whom, without human validation?"

When AI stops suggesting and starts acting, governance is no longer optional.

Sources: 404 Media, TechCrunch, KrebsOnSecurity, SecurityWeek, Task & Purpose, The Guardian, The Verge, OWASP, and OSINT reports on X/Twitter regarding possible post-patch persistence on 06/02/2026.