Instagram users locked out after Meta AI abused to steal accounts
Attackers reportedly abused Meta’s AI support and selfie checks to take over Instagram accounts, then trapped victims in chatbot-only recovery loops.
Intelligence analysis by GPT-5.4 Mini

Multiple Instagram users say their accounts were hijacked after attackers fooled Meta’s AI support flow into treating them as the rightful owner. Victims report being unable to recover access because support appears to rely on automated loops rather than human help.
It is like a house with a super-smart front door robot that lets the wrong person in because they wear a fake badge. Then the real owner gets stuck talking to another robot that keeps saying “try again” instead of opening the door.
Analysis
What happened
BleepingComputer reports that multiple Instagram users suddenly lost access to their accounts after attackers allegedly used Meta’s AI-powered support and recovery tools against them. Among the reported victims were accounts tied to the Obama White House team, app researcher Jane Manchun Wong, and the handles @hey and @korn.
How the takeover allegedly worked
According to the article, the attacker starts by triggering the “forgot password” flow and then uses Meta’s own verification steps to appear legitimate. When Instagram asks for a selfie, the attacker reportedly takes a photo from the target’s account, runs it through an AI video generator to make it look like an animated selfie, and submits it for verification. The article says this can trick Meta’s AI into accepting the submission and changing the account email address.
The reported outcome is especially concerning because the method is said to bypass 2FA protections. Once the email address is changed, the attacker can start a password reset and receive the code needed to complete the takeover.
Why victims are stuck
The article says impacted users then run into a recovery process that can loop through chatbots and broken links without reaching a human agent. One affected user quoted in the piece said they spent hours trying to get human support and received repeated failures from Meta’s support AI.
What is confirmed and what is not
BleepingComputer says Meta has not issued a public press release about the incident, but company vice president of communications Andy Stone replied to one affected user that the issue had been resolved and impacted accounts were being secured. The article also notes that claims about rare single-letter usernames such as @e and @f could not be independently verified.
The broader lesson is clear: if account recovery can be fooled, then the security controls around it need stronger identity checks and a real human escalation path.
Key points
- Attackers allegedly used Meta’s AI support flow to gain control of Instagram accounts.
- The reported method used a selfie verification step with an AI-generated video to mimic a real person.
- Victims said 2FA did not stop the takeover and recovery was stuck in chatbot loops.
- Meta had not published a full public response, though a company executive said the issue was resolved and impacted accounts were being secured.
- BleepingComputer could not independently verify claims about some rare single-letter usernames.
If Meta tightens its recovery checks, the same AI tools could become safer and faster for real account owners. A clearer path to human support would also help victims recover accounts before attackers can lock them down further.
If the reported weakness is real and remains easy to abuse, attackers could keep stealing high-value accounts at scale. A chatbot-only recovery process could leave victims unable to prove ownership quickly enough to regain access.



