Several Instagram accounts, including those of the Obama White House and the Chief Master Sergeant of the U.S. Space Force, were compromised over the weekend as pro-Iranian messages appeared on the platforms. This incident followed the circulation of instructions on Telegram, detailing a method to deceive Meta's AI support assistant into resetting account passwords.
On May 31, alerts began spreading through Telegram channels about a vulnerability in Meta's AI bot, which could allegedly facilitate the addition of an email address to existing accounts during password resets. A video from pro-Iran hackers demonstrated a method involving a VPN to mask the attacker's location, followed by requests to the AI assistant to change the email linked to the account.
According to reports, this exploit enabled the hijacking of several high-value Instagram usernames, with potential resale values exceeding $500,000. Meta's Andy Stone announced that the issue had been addressed and stated they were taking steps to secure the affected accounts. Following the incident, an emergency patch was implemented by Meta, clarifying that no backend database was compromised.