Industry

Meta AI Chatbot Bug Allowed Hacking of 34,000 Instagram Accounts

A flaw in Meta's AI-powered customer service chatbot enabled hackers to reset passwords for roughly 34,000 Instagram accounts, including the dormant account of former President Barack Obama. About 20,000 accounts were breached, exposing personal data such as email addresses and phone numbers. Meta says it has fixed the bug and secured affected accounts.

Neura News

Neura News

Neura Market Editorial

June 9, 20264 min read
Meta AI Chatbot Bug Allowed Hacking of 34,000 Instagram Accounts

A bug in Meta's artificial intelligence customer service tool left more than 34,000 Instagram accounts vulnerable to takeover, with roughly 20,000 accounts actually breached by hackers, according to internal company documents reviewed by The New York Times.

The flaw allowed anyone to use an AI-powered chatbot designed for customer support to reset passwords for Instagram accounts. The hacker simply asked the chatbot to change a password, and the system complied without verifying the requester's identity. Meta said it has since fixed the vulnerability and secured the affected accounts.

High-Profile Accounts Targeted

Among the accounts compromised was the official Instagram account of former President Barack Obama, which had been dormant since he left the White House in 2017. In late May, the account suddenly began posting unusual content, including messages deriding President Trump and claiming the White House was "under Shiite control." The posts were not authorized by Obama's office.

Hackers also took over the account of SimpliSafe, a home security monitoring company, and the Instagram account of a senior official in President Trump's Space Force department. In the Space Force official's case, attackers posted pro-Iran messages comparing the war in Iran to U.S. involvement in Vietnam during the 1960s.

Scale of the Breach

Of the 34,000 accounts affected, about 20,000 were breached, meaning hackers gained access to the account holders' email addresses, phone numbers, birth dates, and other personal data. Internal documents show that more than 3,500 of the affected accounts had their user names changed by the attackers.

Meta stated that it could not determine exactly what information was viewed or stolen by the attackers. The company said it has notified affected users and restored access to compromised accounts.

The vulnerability was first reported by 404 Media earlier this month. The New York Times obtained internal Meta documents that detailed the scope of the breach.

The #1 Newsletter in AI

Stay ahead of the AI curve

The most important updates, news, and content — delivered weekly.

No spam. Unsubscribe anytime.

Broader Implications for AI Security

The incident highlights a growing concern as companies deploy AI chatbots for customer service and other sensitive functions. Meta has been integrating AI tools across its platforms, including Instagram and Facebook, to automate tasks such as password resets and account recovery. Security experts have warned that such systems can be exploited if not properly designed with verification safeguards.

Meta, the parent company of Instagram, has faced previous security incidents, but this is one of the first major breaches linked directly to an AI-powered tool. The company has not disclosed whether it will change its approach to AI-based customer service in the wake of the incident.

The bug was discovered in March, meaning it existed for several months before Meta patched it. Hackers exploited it to target a wide range of accounts, from high-profile political figures to businesses. The Obama account, which had not posted in nearly a decade, was likely chosen for its visibility and potential for disinformation.

Meta's Response

In a statement, Meta said: "We have fixed this bug and secured the affected accounts. We are working with law enforcement and have taken steps to prevent this from happening again." The company did not provide details on how the fix was implemented or whether any attackers have been identified.

The breach underscores the risks of relying on AI systems for critical account management functions without robust authentication checks. As AI chatbots become more common in customer service, companies will need to balance convenience with security.

Related on Neura Market

More from Neura News

General

Open-weight AI mirrors Kubernetes ecosystem shift

Tobi Knaup, co-founder of Mesosphere, draws parallels between the rise of Kubernetes and the current trajectory of open-weight AI models. He argues that open-weight models are becoming a neutral substrate for innovation, attracting a global ecosystem of developers, startups, and enterprises. The piece warns against US restrictions on Chinese open-weight models, advocating instead for American leadership through open releases, procurement strategies, and standards.

Jul 25·7 min read
General

Open-weight AI mirrors Kubernetes rise, US warned on bans

The author, a Mesosphere co-founder, draws parallels between the rise of Kubernetes and the current open-weight AI ecosystem. He argues that open-weight models are becoming a neutral platform for innovation, and warns that US restrictions on Chinese open-weight models could isolate American developers from a global ecosystem. The piece urges the US to compete by releasing frontier models, using procurement to create demand, building the stack, and setting standards rather than imposing bans.

Jul 25·7 min read
Industry

Power line failure reveals AI data center grid risks and solutions

A fallen power line near Washington, DC caused over 3 gigawatts of data center load to vanish from the PJM grid in seconds, spiking voltage across the region. The event, which made lights flicker from Northern Virginia to Chicago, highlights a growing problem as AI data centers become larger and more concentrated. Experts warn that without better coordination or technology like ON.Energy's battery-backed uninterruptible power supply, such disruptions will become more frequent and severe.

Jul 25·5 min read