Get all your news in one place.
100's of premium titles.
One app.
Start reading
International Business Times UK
International Business Times UK
Vinay Patel

A Single Chatbot Request Was All It Took to Hijack the Obama White House Instagram Account [VIDEO]

A terrifying new security breach has revealed that hackers successfully hijacked prominent Instagram profiles, including Sephora and the Obama White House, using nothing more than Meta's own AI support assistant (Credit: Mourizal Zativa on Unsplash)

Meta acknowledged on Monday that intruders successfully breached prominent Instagram pages by exploiting its AI-powered support chatbot, noting that a fix was deployed once security experts flagged the vulnerability.

High-Profile Targets Compromised

These revelations emerged alongside a wave of breaches hitting prominent Instagram profiles. Among those compromised were Sephora, the Chief Master Sergeant of Space Force, and the Barack Obama White House page (@obamawhitehouse).

Similar attacks seemingly hit the wider public during the weekend, with numerous individuals taking to Reddit to report compromised Instagram profiles, while others on X raised the alarm over identical account takeovers.

'The password got changed without my knowledge and I was getting different password reset attempts throughout yesterday,' Security researcher Jane Wong said her Instagram account was hijacked. 'Quite concerning.'

How the Simple Exploit Worked

A demonstration uploaded to X laid out the exact method used to breach Instagram profiles. To bypass the platform's automated security triggers, the intruder reportedly relied on a VPN to fake the geographic location of their intended targets.

Next, the hacker initiated a conversation with the Meta AI Support Assistant, requesting that a new email address be linked to the victim's profile. Footage shows the bot dispatching a security pin to the newly provided address; once the thief fed this code back into the chat, the assistant generated a 'Reset Password' prompt. By simply inputting a new password, the attacker successfully locked the owner out of their account.

Bypassing Original Account Security

TechCrunch successfully confirmed the exploit after checking the intruder's public inbox, which was visible in the footage, and verifying that the security code had indeed arrived. Crucially, the exploit succeeded because the intruder never actually needed to gain control of the genuine email inbox associated with the victim's Instagram profile.

Responding to Wong and other affected posters, Instagram spokesperson Andy Stone confirmed on Monday that the vulnerability had been resolved.

In a separate post, he noted that 'This issue has been resolved, and we are securing impacted accounts.' However, the exact number of individuals who had their profiles compromised during the security lapse remains unknown.

Growing Fears Over AI Safety

This security failure fuels growing anxiety surrounding the dependability of artificial intelligence when trusted to manage critical safety protocols like account credentials.

Having rapidly restructured its workforce around artificial intelligence and aggressively expanded automated features across its platforms, Meta rolled out this support assistant globally on Facebook and Instagram earlier this year. Promotional materials for the tool highlighted that the assistant can 'take action for you on a growing set of requests directly within Facebook and in the future, on Instagram.'

The Future of Tech Moderation

The assistant was designed to handle tasks ranging from resetting passwords to flagging scams, impersonation profiles, and inappropriate content. 'The Meta AI support assistant is a major step in our work to deliver stronger support on our apps,' reads a March press release from Meta.

As Meta continues to push automated tools into core moderation roles, this incident serves as a stark reminder of the risks involved. Relying on automation to protect user data clearly backfires when systems cannot distinguish between a legitimate owner and a clever intruder, leaving tech giants with a difficult balancing act ahead.

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.