The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Fact-check summary

Multiple outlets including TechCrunch, Krebs on Security, 404 Media, BBC, The Guardian, and Reuters corroborate the Meta AI chatbot Instagram hack affecting ~20k accounts and high-profile targets.

Sourcing
3independent sources

via 9to5Mac

9to5Mac · track record
67Stories
100%Verified
1330d
All sources →
Markets
META···

Live quote · not investment advice

Home/Tech/Hackers tricked Meta AI bot to hijack 20,000 Instagram accounts
VERIFIEDBy Xavier Rivera· ·2 min read

Hackers tricked Meta AI bot to hijack 20,000 Instagram accounts

Hackers tricked Meta’s AI support chatbot into resetting passwords and handing over around 20,000 Instagram accounts, including high-profile ones belonging to the Obama-era White House, U.S. Space Force, and Jane Wong. The prompt injection attack, active since February, enabled gray-market resale of valuable handles before Meta patched it on May 29.

Source:9to5Mac
Post
Hackers tricked Meta AI bot to hijack 20,000 Instagram accounts
TL;DRAI · 60 sec read

Hackers compromised 20,000 Instagram accounts by tricking Meta’s AI support chatbot with prompt injection. They used VPNs to add new emails and reset passwords without controlling originals. High-profile accounts were seized and resold. The chatbot skipped identity verification. Meta patched the flaw on May 29.

Hackers compromised around 20,000 Instagram accounts by tricking Meta’s AI-powered support chatbot into granting them access. The attack allowed them to change associated email addresses and reset passwords without ever controlling the victims’ legitimate emails. High-profile accounts including the Obama-era White House, the U.S. Space Force’s chief master sergeant John Bentivegna, and security researcher Jane Wong were among those taken over.

Attackers used VPNs and prompt injection on the support bot. The hackers employed a VPN to spoof the targets’ presumed locations and avoid triggering automated protections. They then opened a chat with Meta’s AI Support Assistant, requested to add a new email address, and provided a verification code sent by the bot to that new address. The chatbot subsequently displayed a “Reset Password” button, allowing the hackers to set a new password and seize control.
The attack allowed them to change associated email addresses and reset passwords without ever controlling the victims’ legitimate emails.

A video demonstrating the process circulated on X, and TechCrunch verified that the hacker’s public email mailbox received the verification code as shown. The exploit relied on the chatbot’s failure to verify the requester’s identity or require control of the original linked email. Researchers described it as a straightforward prompt injection attack that had reportedly been active since February.
POST FROM @DarkWebInformer· tweet embedded in the source article showing the exploit video in action
https://x.com/DarkWebInformer/status/2061253599758315527

Compromised accounts were resold on the gray market. Valuable Instagram accounts, including short handles @hey and @jowo, were targeted for resale. Their combined gray-market valuation was estimated above $1 million. Hackers held accounts briefly for clout, resale, or brand impersonation, with some posting pro-Iranian images and messages during the compromise.
From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →

Prominent researchers such as Jane Manchun Wong reported their accounts hacked, with Wong stating her password was changed without her knowledge and she received multiple reset attempts. Pseudonymous researcher ZachXBT posted that the Meta AI support had excessive permissions allowing password resets without 2FA and without identity verification. Dark Web Informer similarly described the exploit and noted it had been patched.
The exploit relied on the chatbot’s failure to verify the requester’s identity or require control of the original linked email.
Meta deployed an emergency patch and confirmed the scale. Instagram implemented the fix on May 29. Spokesperson Andy Stone stated on May 31 that the issue was resolved. Meta later revealed that around 20,000 accounts were compromised and outlined steps taken in response, though specific additional measures were not detailed in initial reports.
Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →

Reader-supported · The Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning. Two minutes, free forever.

HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
InstagramMetaSecurity
More from9to5Mac
  • Apple tests AI for Genius Bar, sends letters to ex-staff at OpenAI

    Tech · 8h
  • Apple to launch Upgrade leasing program on July 28

    Tech · 9h
  • iOS 27 public beta lands with Siri AI

    Tech · 5d
More inTech
  • lmdeploy's OpenAI API Server Exposed to SSRF via Redirects

    Tech · 4h
  • Apple tests AI for Genius Bar, sends letters to ex-staff at OpenAI

    Tech · 8h
  • SolarWinds Serv-U Hit by Critical IDOR Flaw CVE-2026-28302

    Tech · 8h
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
SubscribeCircuitry Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning. Free forever.

MORE IN TECH

lmdeploy's OpenAI API Server Exposed to SSRF via Redirects

lmdeploy's OpenAI-compatible API server is affected by an SSRF flaw (CVE-2026-63764, CVSS 9.3) that lets unauthenticated attackers reach internal services and cloud metadata endpoints. The issue stems from following HTTP 302 redirects without re-checking each hop against the URL safety guard and was added to the NVD on July 21, 2026.

Apple tests AI for Genius Bar, sends letters to ex-staff at OpenAI

A July 21, 2026 recap highlights Apple's testing of an AI note-taking system for Genius Bar use, scrapped Intel Mac Pro plans, legal letters to ex-employees at OpenAI, and up to 11% iPhone price hikes in Japan. These stories reflect ongoing AI development, hardware strategy shifts, talent retention efforts, and market pricing dynamics.

SolarWinds Serv-U Hit by Critical IDOR Flaw CVE-2026-28302

SolarWinds Serv-U is affected by an IDOR vulnerability rated CVSS 9.1 that can lead to privilege escalation and remote code execution as root when group administrator access is available. The flaw, published July 21 2026, carries lower impact on Windows and is addressed in the Serv-U 2026-3 release.