The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMENEWSFEEDEVENTS
—STORIES—VERIFIED
BOOKMARKS
RSSSOURCESABOUTCORRECTIONS
STARTING SOONApple WWDC 2026IN 1HOpen coverage →
RSS
© 2026 The Circuitry
About UsContactCorrections
  • Home
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Fact-check summary

Multiple outlets including TechCrunch, Krebs on Security, 404 Media, BBC, The Guardian, and Reuters corroborate the Meta AI chatbot Instagram hack affecting ~20k accounts and high-profile targets.

Sourcing
3independent sources

via 9to5Mac

9to5Mac · track record
45Stories
100%Verified
1830d
All sources →
Markets
META···

Live quote · not investment advice

Home/Tech
VERIFIEDBy Xavier Rivera· ·2 min read

Hackers tricked Meta AI bot to hijack 20,000 Instagram accounts

Hackers tricked Meta’s AI support chatbot into resetting passwords and handing over around 20,000 Instagram accounts, including high-profile ones belonging to the Obama-era White House, U.S. Space Force, and Jane Wong. The prompt injection attack, active since February, enabled gray-market resale of valuable handles before Meta patched it on May 29.

Source:9to5Mac
Post
Hackers tricked Meta AI bot to hijack 20,000 Instagram accounts
TL;DRAI · 60 sec read

Hackers compromised 20,000 Instagram accounts by tricking Meta’s AI support chatbot with prompt injection. They used VPNs to add new emails and reset passwords without controlling originals. High-profile accounts were seized and resold. The chatbot skipped identity verification. Meta patched the flaw on May 29.

Hackers compromised around 20,000 Instagram accounts by tricking Meta’s AI-powered support chatbot into granting them access. The attack allowed them to change associated email addresses and reset passwords without ever controlling the victims’ legitimate emails. High-profile accounts including the Obama-era White House, the U.S. Space Force’s chief master sergeant John Bentivegna, and security researcher Jane Wong were among those taken over.

Attackers used VPNs and prompt injection on the support bot. The hackers employed a VPN to spoof the targets’ presumed locations and avoid triggering automated protections. They then opened a chat with Meta’s AI Support Assistant, requested to add a new email address, and provided a verification code sent by the bot to that new address. The chatbot subsequently displayed a “Reset Password” button, allowing the hackers to set a new password and seize control.
The attack allowed them to change associated email addresses and reset passwords without ever controlling the victims’ legitimate emails.

A video demonstrating the process circulated on X, and TechCrunch verified that the hacker’s public email mailbox received the verification code as shown. The exploit relied on the chatbot’s failure to verify the requester’s identity or require control of the original linked email. Researchers described it as a straightforward prompt injection attack that had reportedly been active since February.
POST FROM @DarkWebInformer· tweet embedded in the source article showing the exploit video in action
https://x.com/DarkWebInformer/status/2061253599758315527

Compromised accounts were resold on the gray market. Valuable Instagram accounts, including short handles @hey and @jowo, were targeted for resale. Their combined gray-market valuation was estimated above $1 million. Hackers held accounts briefly for clout, resale, or brand impersonation, with some posting pro-Iranian images and messages during the compromise.
The exploit relied on the chatbot’s failure to verify the requester’s identity or require control of the original linked email.

Prominent researchers such as Jane Manchun Wong reported their accounts hacked, with Wong stating her password was changed without her knowledge and she received multiple reset attempts. Pseudonymous researcher ZachXBT posted that the Meta AI support had excessive permissions allowing password resets without 2FA and without identity verification. Dark Web Informer similarly described the exploit and noted it had been patched.

Meta deployed an emergency patch and confirmed the scale. Instagram implemented the fix on May 29. Spokesperson Andy Stone stated on May 31 that the issue was resolved. Meta later revealed that around 20,000 accounts were compromised and outlined steps taken in response, though specific additional measures were not detailed in initial reports.
Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →

Reader-supported · Daily Brief

Daily brief at 7 AM ET. Top tech stories, every morning. Sourced and fact-checked.

HELP US IMPROVE

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
InstagramMetaSecurity
More from9to5Mac
  • Bloomberg details Apple’s 2025 AI shakeup ahead of iOS 27

    Tech · 1h
  • OpenAI Upgrades ChatGPT Memory, Extends to Free Users

    Tech · 3d
  • Anthropic Releases Claude Opus 4.8 Model

    Tech · 10d
More inTech
  • Bloomberg details Apple’s 2025 AI shakeup ahead of iOS 27

    Tech · 1h
  • Nvidia, LG Group form broad AI, robotics partnership

    Tech · 10h
  • Naver targets gigawatt-scale AI with Nvidia DSX

    Tech · 12h
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
SubscribeCircuitry Brief

Daily brief at 7 AM ET. Top tech stories, every morning.

MORE IN TECH

Bloomberg details Apple’s 2025 AI shakeup ahead of iOS 27

A Bloomberg report details the early 2025 executive meeting that triggered Apple’s AI strategy overhaul after Apple Intelligence underperformed and Siri faced delays. The changes, including new leadership assignments and a Google Gemini partnership, will debut in iOS 27 at WWDC today.

Nvidia, LG Group form broad AI, robotics partnership

Nvidia and LG Group announced a wide-ranging partnership on June 7 covering AI factory infrastructure, home robotics, autonomous driving components, and sovereign AI model development. The deal is one of the broadest single-company collaborations Nvidia has announced during Jensen Huang's South Korea visit.

Naver targets gigawatt-scale AI with Nvidia DSX

Naver will expand its AI infrastructure with Nvidia's DSX platform from an initial 55 megawatts toward gigawatt-scale at its GAK Sejong data center. The June 7 announcement accelerates South Korea's sovereign AI push and deepens ties between the internet company and the chipmaker.