Hackers exploited Meta's AI support bot to reset passwords and seize control of high-profile Instagram accounts, including those belonging to the Obama White House and the Chief Master Sergeant of the U.S. Space Force. The accounts were briefly defaced with pro-Iranian imagery and messaging over the weekend before being restored.

Attackers distributed detailed instructions on Telegram demonstrating how to manipulate Meta's automated support assistant into initiating password resets without proper verification. The technique bypassed standard security protocols by social engineering the chatbot, which failed to adequately validate account ownership before processing credential changes.

The compromise highlights a critical weakness in automated customer support systems. Meta's AI bot did not implement sufficient authentication barriers before granting access to sensitive account functions. This gap allowed threat actors to target accounts regardless of two-factor authentication or other secondary defenses, since they could reset the primary password entirely.

The vulnerability affected accounts with substantial reach and credibility. The Obama White House Instagram account commands millions of followers. Compromise of such profiles creates immediate risks for misinformation campaigns, credential theft targeting followers, and brand damage. The Space Force account's defacement underscores national security implications when government communication channels fall under adversarial control.

Meta responded by restricting access to the AI support bot's password reset function. The company disabled the feature pending a security review and implementation of stronger verification methods. However, the incident exposes how organizations increasingly rely on AI-driven automation without adequate safeguards for high-risk operations.

Organizations managing sensitive accounts should immediately review their support channel security. Password reset functions require multi-step human verification, not automated processing. Government and institutional accounts need additional protections including IP whitelisting, hardware security keys, and mandatory human review for any account access changes.

This breach demonstrates that AI automation in security contexts requires the same scrutiny as traditional systems. Speed and efficiency cannot override verification rigor.