Meta AI support bot allowed hackers access to Instagram accounts just by simply asking, say researchers

NEW YORK, June 2 β Meta is facing scrutiny after security researchers found that its AIβpowered support chatbot could be manipulated to grant unauthorised access to Instagram accounts.
Futurism reported that multiple users and cybersecurity researchers demonstrated how Metaβs automated support agent β designed to help with account recovery β could be tricked into handing over access links simply by claiming to be the account owner. In several documented cases, the bot allegedly provided passwordβreset or loginβrecovery URLs without verifying the requesterβs identity.
According to the report, the vulnerability allowed attackers to bypass standard security checks, including twoβfactor authentication, by exploiting the chatbotβs willingness to accept unverified claims. Screenshots shared by researchers showed the bot responding with recovery links after minimal prompting.
Meta told Futurism that it had taken action to address the issue, but did not specify what changes were made. The company also said it had not found evidence of βwidespread abuse,β though researchers quoted in the article argued that the flaw was significant and easily exploitable.
Cybersecurity analysts warned that the incident highlights broader risks in deploying AI systems for sensitive support functions without robust verification safeguards. Some experts said the case underscores how AIβdriven customer service tools can unintentionally create new attack surfaces if not properly secured.
The report noted that several affected Instagram users have since regained control of their accounts.