In late May and early June 2026, Telegram groups used by security researchers and hackers began circulating videos showing a strikingly simple technique for stealing Instagram accounts: opening a chat with Meta's AI-powered support assistant and asking it, in plain language, to link a new email address to a target's account. According to Meta's own account, filed in a breach notification to the Maine Attorney General's office, this worked — and it worked on high-profile accounts, including the Obama White House's Instagram account (an archival account documenting the Obama administration), the account of John Bentivegna, the top enlisted leader in the U.S. Space Force with the title Chief Master Sergeant of the Space Force, and the cosmetics retailer Sephora's account.
What actually happened — and what didn't
It's important to be precise about the mechanism, because early coverage overstated it. This was not prompt injection, and the attackers did not forge two-factor authentication codes or trick the AI into "reasoning" its way around security. Meta's associate general counsel for incident response, Amber Hannah, explained the root cause plainly in the company's regulatory disclosure: the support tool "worked properly and functioned as intended; however due to a bug in a separate code path, the system did not properly verify that the email address provided by the individual requesting a password reset matched the email address associated with that user's Instagram account." In other words, when an attacker told the bot to send a password reset link to an email address the attacker controlled, a backend validation check that should have rejected the mismatched address failed to do so — and the system sent the reset link anyway. From there, anyone who received that link could log in and take over the account, but only if the account did not have two-factor authentication (2FA) turned on. Accounts protected by 2FA were not compromised through this route.
The scale of the breach
Meta told the Maine Attorney General that up to 20,225 accounts were potentially affected, though the company cautioned that the true number of accounts actually accessed by unauthorized parties could be lower, since some password resets in that count may have been performed by legitimate account owners. Meta says it discovered the vulnerability on May 31, 2026, then disabled the affected support tool, invalidated all password reset links the flawed process had generated, and forced a mandatory security checkpoint and password reset on every potentially affected account. The company said it could not rule out that attackers accessed profile information, email addresses, phone numbers, dates of birth, direct messages, and posts belonging to compromised users, and said it plans to notify affected users directly and recommend they enable 2FA.
Why this matters beyond one bug
Meta rolled out AI-driven account recovery — its "High Touch Support" tool — broadly across Facebook and Instagram earlier in 2026, explicitly marketing it as a way to deliver "solutions, not just suggestions" for account security and recovery. That framing is exactly what makes this incident notable: the flaw wasn't in the AI's judgment or in some adversarial prompt — it was an ordinary software bug that happened to sit behind an AI interface millions of people now use as their first, and often only, point of contact when locked out of an account. Separately, and unrelated to this specific incident, AI is also reshaping fraud on the defensive side: UK insurer Aviva reported in June 2026 that it identified a record £233 million in suspected fraudulent insurance claims across its brands in 2025 — more than 18,400 suspect claims — as both fraudsters and the company's own detection tools increasingly rely on AI-generated evidence and AI-assisted analytics, according to the company and reporting by The Guardian.
Our take
The lesson here isn't "AI chatbots can be manipulated into ignoring security rules" — that's not what occurred. The lesson is narrower and, in some ways, more mundane: any account-recovery workflow, AI-fronted or not, is only as safe as its weakest backend validation check, and putting a conversational interface in front of a sensitive process doesn't automatically add scrutiny — if anything, it can make a straightforward, plainly worded request look more legitimate to a system that isn't built to question it. The one control that reliably stopped the exploit cold was 2FA, which is also the most concrete, actionable takeaway for any reader: enabling it protects an account even when the recovery system behind it fails.
What to watch next
Watch for Meta's account of exactly how it fixed the validation bug before re-enabling the High Touch Support tool, and for any regulatory response beyond the Maine disclosure — several other state attorneys general are likely to have received similar notifications given the scale of the breach. It's also worth watching whether other platforms that have rushed AI agents into account-recovery and support roles undergo similar audits before, rather than after, a comparable incident.
💡 The Nexalytics Take
Hackers didn't trick Instagram's AI into breaking its own rules — they exploited a plain backend bug that failed to check whether a password-reset email address actually matched the account owner's. The AI interface just made the request easy to submit in natural language. The real safeguard that stopped this attack on protected accounts was two-factor authentication, not any judgment call by the bot.