Copy article

Hackers trick Meta AI into handing over Instagram accounts – including Barack Obama’s

ended 02. June 2026

Hackers were able to hijack and sell Instagram accounts by tricking the social media platform’s AI chatbot, Meta told the Metro.

Meta AI is a digital assistant integrated into Instagram as well as other Meta-owned platforms, like Facebook and WhatsApp.

But rather than use it to write captions or generate images, hackers have found a way to trick it into changing other people’s passwords, including Barack Obama's dormant White House Instagram account.

Among the first to document the vulnerability were cybercrime trackers ZachXBT, Dark Web Informer and impulsive.

Meta has now confirmed that the vulnerability has been patched.

  • How easy is it to trick an AI chatbot?
  • How dangerous is it that hackers can do this so easily?
  • What other thoughts do you have?

Responses this afternoon.

2 responses from the Newspage community

Copy all

Copy

The interesting part of this story is not that the AI was tricked. It is that a reported vulnerability suggests an AI-assisted process was able to influence a security-sensitive action. The question is not how clever the attackers were, but why that level of authority existed at all. Meta is correct that this was not a traditional data breach. But to the user, it makes little difference whether access comes through a database leak or a flawed recovery process. The account was still taken over. As AI moves into operational functions — support, identity verification, account recovery — it becomes part of the security perimeter. This is less a story about AI than about governance, permissions and oversight. The risk is not that AI makes mistakes. Human agents make mistakes every day. The risk is that AI lets those mistakes happen at machine scale. This wasn't a breach. It was a design decision that hadn't been stress-tested — and it won't be the last.
Copy

Humans are the weakest link in any authentication chain, and AI trained on human interaction patterns inherits that weakness by design. A system built to be helpful, to reduce friction, to resolve requests efficiently, is a system that has been optimised to say yes. The rule is to only give sufficient permission to get things done, and only superuser access when essential. This bot had far too many permissions granted, and that sealed its downfall.

The hacker didn't exploit code. They exploited the chatbot's inherent purpose: helpfulness.

You construct a plausible scenario, present yourself as someone with a legitimate need, and let the system's own compliance instincts do the work. The more helpful the system, the more exploitable it is through this method.

What makes AI chatbots specifically vulnerable is that they can't feel suspicion in the same way a human can, nor apply guardrails consistently over long a session. They can be 'worn down'. This solution just isn't good enough.