Between late May and early June 2026, attackers took over high-profile Instagram accounts — including Barack Obama's White House account and Sephora's official account — by simply asking Meta's AI support assistant to change the account recovery email to one they controlled. No technical exploits were needed; the AI agent skipped all standard verification steps and acted on a verbal claim of ownership. The root cause is a fundamental design flaw: Meta's AI customer support was granted execution privileges for high-risk account operations while also being responsible for determining authorization boundaries — a role LLMs are inherently unfit for. Security recommendations include separating conversational rights from operational execution rights, enforcing independent out-of-band verification for sensitive account changes, and never fully delegating final execution authority for sensitive operations to AI.

4m read timeFrom securityboulevard.com
Post cover image
Table of contents
OverviewAttack ProcessMeta’s Strategic ActionRoot Cause AnalysisSecurity RecommendationsReferences
1 Impression