Over the past weekend, high-profile Instagram accounts were taken over by people who did nothing cleverer than ask. Hackers opened a chat with Meta's AI support assistant, told it to link a new email address to an account they did not own, and the bot sent a one-time PIN to that address and offered a password reset. An Obama-era White House page, the account of a senior United States Space Force officer, and Sephora's profile all changed hands this way, according to reporting from 404 Media, TechCrunch and Krebs on Security. If your business lives on Instagram, Facebook or WhatsApp, the tool Meta built to help you recover a locked account is the same tool that just gave several away.
What happened, in plain terms
Late last year Meta rolled out an AI support assistant, and in March it pushed the assistant to all Facebook and Instagram accounts with real power behind it, including the ability to reset passwords and run account recovery. The product page sold it as "solutions, not just suggestions." Over the weekend, security researchers showed exactly what kind of solutions.
The method was almost insultingly simple. An attacker used a VPN to make their connection look like it was near the target's usual location, which kept Instagram's automated checks calm. They then opened the AI support chat and asked it to add their own email to the target's account. The bot added the address, sent it a one-time PIN, accepted the code typed back in, and presented a reset-password button. Once the password changed, the rightful owner was locked out, with no human at Meta to escalate to. Videos of the steps circulated on Telegram, where researchers said the trick had been doing the rounds since March. It is worth noting the backdrop: Meta cut several thousand support and engineering jobs in April. Nobody has tied the two events together directly, but moving critical account functions to a bot while thinning the people behind it is the setting this happened in.
Brian Krebs reported the one detail that matters most for the rest of us. The exploit failed against any account that had multi-factor authentication (MFA) switched on, even the weakest kind, a one-time PIN sent over SMS. Meta says the issue is resolved and that it is securing affected accounts. Krebs also noted the company appears to have removed the bot's ability to add email addresses rather than rethinking what an account-recovery bot should be allowed to touch at all.
Why this hits harder for SA business owners
For a lot of South African small businesses, Instagram and Facebook are the shop itself: the product photos, the customer messages, the orders, and years of followers built one post at a time, all sitting inside an account controlled by a company you cannot phone.
Durban has already seen how that ends. In 2024 the Independent on Saturday spoke to KZN business owners whose Instagram accounts were hijacked through phishing. Lauren, who runs WTF Vintage Furniture out of Durban North, lost an account with nearly 8,000 followers and was told she could buy it back. The owner of Stone Sloth candles had her profile defaced and turned into a billboard for a bitcoin scam. Several of them went months without their accounts, and the only thing that worked was finding a personal contact inside Meta, because the official support path led nowhere.
There is a second layer here, and it speaks straight to business owners. Across South Africa, companies are racing to put their own AI agents on WhatsApp and their websites to answer customers, chase payments and update records after hours. An AI agent that can take actions on an account is a new way in, and it answers to persuasion rather than a password. Whoever talks to it most convincingly wins. Under the Protection of Personal Information Act (POPIA), that exposure is the business owner's to carry. The Information Regulator has signalled tougher enforcement through 2026, the first corporate penalties have already landed, and small businesses tend to be the easiest targets because no one inside is watching the controls. Section 71 of POPIA already deals with decisions made by automated systems. A support bot that can sign an account over to a stranger is the kind of automated decision the Regulator is starting to ask hard questions about.
What to do this week
- Turn on multi-factor authentication everywhere. Every Instagram and Facebook login, your Meta Business Suite, and the email sitting behind them. An SMS code alone would have stopped this attack cold, and an authenticator app or a passkey is stronger and worth the 10 minutes.
- Secure the recovery email. The takeover ran through whatever inbox can reset the account. If that email has no MFA, your social accounts effectively have none either.
- Claim ownership in Meta Business Suite and review access. Check who holds admin rights, and remove former staff, old agencies, and that one freelancer from 2022. Fewer doors mean fewer locks to worry about.
- Put limits on any AI bot you run. If you use a chatbot for support, write down what it may never do without a human signing off: no password changes, no payment actions, no editing of account details. Log every conversation it has.
- Keep a recovery plan that does not rely on a bot. Hold a second admin login, save proof of ownership, and document a real contact path now, while you are calm, rather than at 11pm when the account is already gone.
Where Ubuntu Guard fits
We help KZN businesses lock down the accounts their revenue depends on, and set sensible rules for the AI tools they are starting to put in front of customers. If you want a second pair of eyes on your social, login, and recovery setup, that is the kind of thing we do. We work from a clean device, tell you exactly where the gaps are, and give you a plain-language report you can act on. We speak human, not tech jargon. You can read how we work at our cybersecurity assessment service.
Worried that one message to a support bot could hand over the accounts your business runs on? WhatsApp us and we will walk through your social and login security with you. Otherwise reach us at [email protected].
Cybersecurity Made Simple
Sources
- 404 Media, "Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked" by Jason Koebler, 1 June 2026.
- TechCrunch, "Hackers hijacked Instagram accounts by tricking Meta AI support chatbot into granting access", 1 June 2026.
- Krebs on Security, "Hackers Used Meta's AI Support Bot to Seize Instagram Accounts", June 2026.
- Gizmodo, "Hackers Tricked Meta AI Into Handing Out Access to Major Instagram Accounts", 1 June 2026.
- Engadget, "Meta's AI support chatbot made it ridiculously easy for hackers to take over Instagram accounts", 1 June 2026.
- Independent on Saturday (IOL), "Hackers hit small business", 2024.
- TechCentral, "How AI solutions are reshaping South African customer service", 17 March 2025.
- HRSpot, "How to Write a Workplace AI Use Policy (POPIA-Aligned)", 2026.
- Information Regulator (South Africa), enforcement guidance and POPIA Chapter 4 obligations, 2026.
- Protection of Personal Information Act 4 of 2013 (POPIA), Section 71 on automated decision making.
© 2026 Ubuntu Guard Cybersecurity | Durban, South Africa
ubuntuguard.co.za