AI news story

Hackers duped Meta AI support chatbot to steal celebrity Instagram accounts

Pricey Instagram handles were stolen and resold before Meta patched the exploit.

  • LLMs
  • Source: Ars Technica
  • Published: 2026-06-01

Editor's take

Malicious actors exploited a vulnerability in Meta's AI-powered support chatbot, tricking it into divulging credentials that facilitated the theft and resale of high-value celebrity Instagram accounts. This incident highlights a critical blind spot in AI security, where the very tools designed to assist users can become vectors for sophisticated social engineering attacks. The affected accounts, some reportedly worth tens of thousands of dollars, underscore the tangible financial risks associated with poorly secured AI integrations.

The exploit's impact extends beyond individual account holders, raising concerns about the broader security posture of large-scale AI deployments in consumer-facing platforms. It suggests that even with substantial resources, companies like Meta are not immune to novel attack vectors that leverage AI's conversational capabilities. The speed at which these accounts were compromised and resold points to an organized criminal element exploiting emergent vulnerabilities.

Future scrutiny should focus on Meta's patching timeline and the specific conversational prompts or patterns that triggered the exploit. Understanding how the AI was "duped" is crucial for developing more robust defenses against similar AI-driven social engineering attempts across the industry, particularly as more platforms integrate AI into customer service and account management functions.