Over the weekend, a troubling security flaw allowed hackers into several high-profile Instagram accounts. Users reported that their accounts were compromised via a clever trick on Meta’s own AI-powered support chatbot.
The hack involved spoofing a victim's location with a VPN and then asking the AI to add a new email address to the account. Once granted, the verification code was shared, leading to password reset attempts and ultimate takeover of the account.
Technical researcher Jane Wong revealed that her own Instagram account fell prey: “The password got changed without my knowledge and I was getting different password reset attempts throughout yesterday.”
A video circulating online demonstrated step-by-step how this exploit worked, highlighting the vulnerability in Meta’s security measures. The hack relied on the fact that it didn’t require control of the legitimate email address linked to the victim's account.
Meta has since addressed the issue, but the incident raises critical questions about AI and cybersecurity.







