By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Cybersecurity Beat
Search
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
    • Mission
    • Services
    • Contact
Reading: Account Hijackers Weaponized Meta AI Chatbot to Steal Instagram Handles
  • AI
  • Android
  • Authentication
  • Breaches
  • CASB
  • Compliance
  • Cryptography
  • Cyberinsurance
  • EDR
  • IAM
  • Malware
  • Phishing
  • Quantum
  • Ransomware
  • SecOps
  • SIEM
  • SOC
  • Threat Intelligence
  • Vulnerabilities
  • Zero Trust
Cybersecurity BeatCybersecurity Beat
Font ResizerAa
Search
  • News & Alerts
  • Articles
  • Spotlight
  • Features
  • Resources
Follow US
  • About CSB
  • Services
  • Contact
  • Privacy
  • Legal
©2026 CybersecurityBeat. All Rights Reserved.
News & Alerts

Account Hijackers Weaponized Meta AI Chatbot to Steal Instagram Handles

Threat actors manipulated Meta's AI assistant on Instagram to reset passwords and steal premium account handles, selling them on Telegram for large sums before the company deployed a patch.

CSBadmin
Last updated: June 1, 2026 11:03 pm
CSBadmin
2 Min Read
Share
SHARE

The AI Logic Flaw

A vulnerability in Meta’s AI powered account recovery assistant on Instagram enabled attackers to take over high value accounts without any traditional hacking or system intrusion. Security researchers ZachXBT and Dark Web Informer publicly disclosed that threat actors could manipulate the chatbot by simply requesting password reset codes to be sent to unauthorized recipients. The AI failed to enforce identity verification checks before processing the request, meaning anyone who knew a target’s username could initiate a takeover attempt.

Contents
The AI Logic FlawImpact on High Profile Accounts

The exploit did not involve a breach of Meta’s backend servers. Instead, the flaw existed in the AI logic layer, which lacked proper rate limiting and authentication mechanisms. Meta confirmed that no internal systems were compromised, but acknowledged the AI had insufficient controls around account recovery workflows.

Impact on High Profile Accounts

Attackers deliberately targeted premium, short handle Instagram accounts such as @hey and @jowo, which are known in underground markets for their high resale value. These coveted usernames, collectively valued at over $1 million, were quickly sold through private Telegram channels before Meta could intervene. Dark Web Informer tracked stolen account listings circulating in real time, highlighting how financially motivated actors exploit platform vulnerabilities for quick profit.

Meta patched the vulnerability shortly after reports surfaced. The company stated it fixed an issue allowing an external party to request password reset emails for some users, and assured that accounts remain secure. However, the incident underscores the growing risk of AI powered account recovery tools being weaponized when proper safeguards are absent.

Source: Cyber Security News

CSBadmin

The latest in cybersecurity news and updates.

TAGGED:Account TakeoverInstagramPassword Reset
Share This Article
Facebook Print
ByCSBadmin
Follow:
The latest in cybersecurity news and updates.
Previous Article Generative AI Tools Fuel GREYVIBE Cyberattacks Targeting Ukraine
Next Article Iran-Linked Cyberattackers Wipe IT and Backups at US Transit Agencies and GPS Firm

Trending

Estee Lauder data breach linked to Oracle E-Business Suite flaw
July 21, 2026
Iran-linked actors use AI to accelerate malware and phishing operations
July 20, 2026
Critical 7-zip vulnerability allows code execution via XZ archives
July 20, 2026
Hugging face says autonomous AI agent breached its infrastructure
July 20, 2026
Critical Nginx bug CVE-2026-42533 allows remote code execution via HTTP
July 20, 2026

Related Stories

CSBadmin

Anthropic’s Claude Mythos AI Uncovers Thousands of Critical Flaws in Key Software

CSBadmin

ClickLock macOS stealer kills apps every 210ms until victims give up password

CSBadmin

Microsoft’s Patch Tuesday Addresses DNS Memory Corruption and Netlogon Flaws

CSBadmin

Anthropic Disrupts AI-Powered Cybercrime Campaign That Targeted Healthcare and Government

csb-sized
  • About CSB
  • Services
  • Contact
  • Privacy
  • Legal

© 2026 Cybersecurity Beat. All rights reserved.

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?