The Instagram accounts for the Obama White House and the Chief Master Sergeant of the U.S. Space Force were briefly defaced with pro-Iranian images and messages over the weekend, after instructions began circulating on Telegram showing how to trick Meta’s AI support assistant bot into resetting account passwords.

On May 31, word began to spread on several Telegram channels that Meta’s AI bot would readily add an email address to an existing account as part of the bot’s standard password reset flow.
A video released on Telegram by pro-Iran hackers claimed to document a remarkably simple exploit that appears to have involved using a VPN connection with an IP address in or near the target’s usual hometown, requesting a password reset for the account, and then choosing to chat with Meta’s AI support assistant. From there, the video shows the attacker instructing the bot to link the account to a new email address, after which the bot sent that address a one-time code that allowed a password reset.
The Telegram account that posted the video also linked to screenshots of pro-Iran images, videos, and messages that defaced the hacked Instagram accounts, claiming hackers had used the exploit to hijack a number of valuable — read: short — Instagram account names with an alleged resale value of more than half a million dollars.
Meta has not responded to requests for comment on the video’s claims, but Meta’s Andy Stone said on Twitter/X that the issue had been resolved and that they were securing impacted accounts. The security blog thecybersecguru.com reports that Meta pushed an emergency patch over the weekend and clarified that no back-end database was breached.
“Instagram has notoriously poor human support infrastructure,” Cybersecguru wrote. “Recovering a locked account — especially a high-value one — can take weeks of back-and-forth with an automated ticketing system. Meta’s solution was to deploy a conversational AI layer to handle common recovery workflows: relinking a lost email address, triggering a password reset, verifying account ownership. The assistant, presumably, was supposed to reduce friction for legitimate users stuck in account-access hell.”
Ian Goldin, a threat researcher at Lumen’s Black Lotus Labs, said we’re entering uncharted security territory as more large online platforms allow AI chatbots to handle sensitive account recovery requests. Just as human customer support employees can be social-engineered into providing unauthorized account access, AI bots are equally eager to help and vulnerable to persuasion and trickery, he said.
“AI chatbots create interesting new attack surface, and we’re likely going to see a lot more of these kinds of attacks,” Goldin said.
Securing your online accounts means taking full advantage of the most secure form of multi-factor authentication (MFA) available, such as a passkey or hardware security key. In this case, even the least robust form of MFA that Instagram offers — a one-time code sent via SMS — likely would have blocked the exploit: the hackers who released the video on Telegram stated that their method failed against every account that had MFA enabled.