Summary
- In December 2025, Meta introduced an artificial intelligence (AI) support assistant designed to make the account recovery process faster and easier.
- According to a report, hackers have been using the same AI support assistant to gain unauthorized access to multiple Instagram accounts.
- Security researchers claim that the AI tool made account takeovers surprisingly simple even for accounts protected with two-factor authentication (2FA).
In December 2025, Meta introduced an artificial intelligence (AI) support assistant designed to make the account recovery process faster and easier. The AI assistant was created to help Facebook and Instagram users recover locked accounts. However, it now appears that Meta may have made the process a little too easy.
According to a report, hackers have been using the same AI support assistant to gain unauthorized access to multiple Instagram accounts. Security researchers claim that the AI tool made account takeovers surprisingly simple even for accounts protected with two-factor authentication (2FA).
The issue was first highlighted by several security researchers on X (formerly Twitter). They reported that details of the hacking method along with screenshots and videos were circulating on Telegram.
According to those materials, hackers would simply instruct the AI support chatbot to change the email address linked to a target account and then submit a password reset request.
Meta has since begun fixing the issue although it remains unclear how many accounts were compromised before the vulnerability was discovered. The report noted that Telegram users had been discussing the security flaw since March.
Meta spokesperson Andy Stone stated that the issue has now been resolved and that the company is scanning for affected accounts. However, Meta has not explained how such a significant security weakness made its way into the AI tool.
Reports suggest that hackers discovered the chatbot relied partly on a user’s physical location when enabling support features. To exploit this, attackers reportedly used VPN services to make their location appear similar to that of the target user.
While the exact number of affected accounts remains unknown, reports indicate that several high-profile accounts were compromised including the White House Instagram account associated with former U.S. President Barack Obama.
We welcome your contributions! Submit your blogs, opinion pieces, press releases, news story pitches, and news features to opinion@minutemirror.com.pk and minutemirrormail@gmail.com

