The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Fact-check summary

Multiple outlets including TechCrunch, Krebs on Security, 404 Media, BBC, The Guardian, and Reuters corroborate the Meta AI chatbot Instagram hack affecting ~20k accounts and high-profile targets.

Sourcing
3independent sources

via 9to5Mac

9to5Mac · track record
79Stories
100%Verified
630d
All sources →
Markets
META···

Live quote · not investment advice

From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Home/Tech/Hackers tricked Meta AI bot to hijack 20,000 Instagram accounts
VERIFIEDBy Xavier Rivera· ·2 min read

Hackers tricked Meta AI bot to hijack 20,000 Instagram accounts

Hackers tricked Meta’s AI support chatbot into resetting passwords and handing over around 20,000 Instagram accounts, including high-profile ones belonging to the Obama-era White House, U.S. Space Force, and Jane Wong. The prompt injection attack, active since February, enabled gray-market resale of valuable handles before Meta patched it on May 29.

Source:9to5Mac
Post
Hackers tricked Meta AI bot to hijack 20,000 Instagram accounts
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
TL;DRAI · 60 sec read

Hackers compromised 20,000 Instagram accounts by tricking Meta’s AI support chatbot with prompt injection. They used VPNs to add new emails and reset passwords without controlling originals. High-profile accounts were seized and resold. The chatbot skipped identity verification. Meta patched the flaw on May 29.

Hackers compromised around 20,000 Instagram accounts by tricking Meta’s AI-powered support chatbot into granting them access. The attack allowed them to change associated email addresses and reset passwords without ever controlling the victims’ legitimate emails. High-profile accounts including the Obama-era White House, the U.S. Space Force’s chief master sergeant John Bentivegna, and security researcher Jane Wong were among those taken over.

Attackers used VPNs and prompt injection on the support bot. The hackers employed a VPN to spoof the targets’ presumed locations and avoid triggering automated protections. They then opened a chat with Meta’s AI Support Assistant, requested to add a new email address, and provided a verification code sent by the bot to that new address. The chatbot subsequently displayed a “Reset Password” button, allowing the hackers to set a new password and seize control.
The attack allowed them to change associated email addresses and reset passwords without ever controlling the victims’ legitimate emails.

A video demonstrating the process circulated on X, and TechCrunch verified that the hacker’s public email mailbox received the verification code as shown. The exploit relied on the chatbot’s failure to verify the requester’s identity or require control of the original linked email. Researchers described it as a straightforward prompt injection attack that had reportedly been active since February.
POST FROM @DarkWebInformer· tweet embedded in the source article showing the exploit video in action
https://x.com/DarkWebInformer/status/2061253599758315527

Compromised accounts were resold on the gray market. Valuable Instagram accounts, including short handles @hey and @jowo, were targeted for resale. Their combined gray-market valuation was estimated above $1 million. Hackers held accounts briefly for clout, resale, or brand impersonation, with some posting pro-Iranian images and messages during the compromise.
From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →

Prominent researchers such as Jane Manchun Wong reported their accounts hacked, with Wong stating her password was changed without her knowledge and she received multiple reset attempts. Pseudonymous researcher ZachXBT posted that the Meta AI support had excessive permissions allowing password resets without 2FA and without identity verification. Dark Web Informer similarly described the exploit and noted it had been patched.
The exploit relied on the chatbot’s failure to verify the requester’s identity or require control of the original linked email.
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Meta deployed an emergency patch and confirmed the scale. Instagram implemented the fix on May 29. Spokesperson Andy Stone stated on May 31 that the issue was resolved. Meta later revealed that around 20,000 accounts were compromised and outlined steps taken in response, though specific additional measures were not detailed in initial reports.
Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Morning Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning.

Two minutes, free forever. What's in The Brief →

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →
HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
InstagramMetaSecurity
More from9to5Mac
  • Bloomberg: Apple plans first touchscreen MacBook Pros for October 27

    Tech · 15h
  • Ring launches first smart lock with manual charging at $249

    Tech · 1d
  • Apple watchOS beta, screenless tracker plans, and CarPlay updates surface

    Tech · 15d
More inTech
  • GlobalFoundries signs $2B TSMC deal for US silicon interposers

    Tech · 9h
  • SpaceX agrees to buy 800 MHz spectrum for Starlink Mobile

    Tech · 12h
  • Anthropic Launches Cyber Mission to Secure Infrastructure and Open-Source Code

    Tech · 15h
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →

MORE IN THIS BEAT

All Tech →
  • Tech· 

    Microsoft discloses CVE-2026-83947 in Azure Event Grid

    Microsoft has disclosed CVE-2026-83947, a CVSS 7.7 HIGH spoofing vulnerability in Azure Event Grid caused by missing authorization. Microsoft says it has already fully mitigated the cloud-service flaw and customers have nothing to do.

  • Tech· 

    Critical CVE-2026-77900 Hits Microsoft Azure App Service for Linux

    A critical vulnerability CVE-2026-77900 affects Microsoft Azure App Service for Linux with a CVSS score of 9.8. The flaw allows an unauthenticated attacker to execute code over the network. Microsoft says it has already fully mitigated the flaw; no customer action is needed.

  • Tech· 

    Critical CVE-2026-88131 hits Microsoft Dataverse with remote code execution

    Microsoft Dataverse is affected by critical vulnerability CVE-2026-88131, which allows remote code execution. The flaw scores 9.8 on CVSS; Microsoft says it has already fully mitigated it and customers have nothing to patch.

  • Tech· 

    Critical CVE-2026-16823 hits IBM Security Verify Access

    IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 contain critical authentication bypass flaw CVE-2026-16823. The NVD rates it 9.1 and warns of remote exploitation without credentials.

  • Tech· 

    IBM patches nine Guardium Data Protection flaws

    IBM has released patches addressing nine vulnerabilities in Guardium Data Protection across versions 12.0 through 12.2.2. Two of the flaws are rated critical and could allow remote attackers to seize control of edge clusters or execute scripts in user browsers.