A recently disclosed security incident exposed significant weaknesses in AI-driven account recovery systems after attackers manipulated an automated support assistant to seize control of Instagram accounts. The flaw allowed threat actors to convince the AI-powered support tool to make account changes that should have required stronger identity verification, ultimately enabling unauthorized access to victim accounts. The attack relied on a logic flaw within the automated recovery workflow rather than malware or traditional credential theft. Attackers reportedly used VPN services to appear geographically close to their targets and then interacted directly with the support chatbot. By requesting that a new email address be associated with a victim’s account, the attackers were able to receive verification codes intended to validate account ownership. Once the new email address was accepted, they initiated password resets and gained full control of the accounts.
Several prominent accounts were compromised during the campaign, including those belonging to well-known organizations, government-affiliated entities, researchers, and public figures. In some cases, hijacked accounts were used to publish unauthorized content, while highly desirable usernames were reportedly transferred or sold through underground channels. Security researchers noted that valuable short-handle accounts were particularly attractive targets because of their significant resale value. Investigators found that the automated system failed to adequately verify account ownership before approving sensitive changes. Reports indicate that some of the platform’s normal security protections, including two-factor authentication and identity verification checks, were either bypassed or rendered ineffective through the flawed workflow. The incident demonstrated how AI systems entrusted with privileged account management functions can become high-value attack surfaces when security controls are not rigorously enforced.
Following public disclosure and widespread abuse of the technique, the affected platform implemented a fix and began securing impacted accounts. The event has renewed concerns within the cybersecurity community regarding the increasing use of AI for sensitive customer support operations. Experts argue that account recovery and identity verification processes require stronger safeguards, robust authentication mechanisms, and human oversight to prevent automated systems from being manipulated into performing actions that compromise user security.