Breaking news

Instagram Secures Platform After AI Chatbot Exploit Leads To Account Hijackings

Instagram Patches Security Vulnerability

Instagram has fixed a security flaw that allowed hackers to take control of user accounts by exploiting Meta’s AI-powered support chatbot. The vulnerability reportedly enabled attackers to add unauthorized email addresses to accounts and reset passwords without access to the legitimate account owner’s email.

Exploit Mechanics Detailed

Reports of account hijackings surfaced over the weekend through posts on Reddit and warnings shared on X. Among the accounts reportedly affected were the Obama-era White House account and the account of U.S. Space Force Chief Master Sergeant John Bentivegna, raising concerns about the potential scope of the vulnerability.

How The Attack Unfolded

Security researcher Jane Wong said her account was compromised after her password was changed without her knowledge. In a post on X, Wong described receiving repeated password reset notifications before losing access to her account. A widely shared demonstration of the exploit showed how an attacker could use a VPN, interact with Meta’s AI Support Assistant and submit an alternative email address. After receiving a verification code, the attacker could reset the password and gain control of the account without accessing the owner’s original email.

Industry Reactions And The Path Forward

Instagram spokesperson Andy Stone confirmed that the vulnerability has been fixed, although Meta has not disclosed how many accounts may have been affected. The incident highlights the security challenges that can emerge as technology companies expand the use of AI-powered support tools and automated account management systems.

Ongoing Security Challenges

The breach has renewed scrutiny of how AI-driven customer support systems handle account recovery and identity verification requests. While the flaw was addressed quickly, the incident demonstrates how automated support processes can become targets for abuse when security controls fail to account for unexpected forms of manipulation.

Cyberattacks On Governments, Infrastructure And Businesses Shape 2026

Cybersecurity has become an increasingly prominent issue in 2026 as cyber incidents continue to affect governments, businesses and critical infrastructure worldwide. Recent attacks have targeted sectors ranging from healthcare and education to energy and public administration, highlighting the growing impact of cyber threats on economic activity and national security.

Questions Remain Over DOGE’s Access To Social Security Data

More than a year after individuals linked to the Elon Musk-led Department of Government Efficiency (DOGE) gained access to systems at the Social Security Administration, questions remain about how sensitive data was handled. Court proceedings are ongoing following allegations that a copy of the Social Security database was transferred to an external server, potentially exposing personal information belonging to millions of Americans.

According to legal filings, the Social Security Administration has acknowledged uncertainty regarding the contents of the server. Lawmakers have warned that, if confirmed, the incident could rank among the largest data breaches involving government records in U.S. history.

Hackers Increasingly Target Water Systems And Energy Grids

Cyberattacks targeting critical infrastructure have continued across Europe, including incidents affecting energy networks and water systems. Authorities in Poland, Sweden and Norway have reported attacks linked to groups believed to be acting in support of Russian interests. At the same time, tensions in the Middle East have heightened concerns about cyber threats to critical infrastructure, particularly privately operated utilities with limited cybersecurity resources.

Iranian Government Hackers Target Stryker

In March, Iranian hackers reportedly carried out a cyberattack against medical technology company Stryker, wiping thousands of employee devices. The incident, attributed to a group linked to Iranian intelligence, disrupted operations and affected the company’s first-quarter financial performance.

Instructure Among Shinyhunters’ Disruptive Hacking Campaigns

The hacking group ShinyHunters has continued to rely on voice phishing techniques to gain access to corporate networks. One of the most prominent incidents involved education technology company Instructure, whose Canvas learning management platform was breached.

The attack exposed personal information belonging to more than 30 million users and disrupted academic schedules during examination periods. Other reported victims include Charter, Carnival and organisations operating in the finance and public sectors.

Supply Chain Attacks Continue To Target Technology Companies

Software supply chains have remained a major target for cybercriminals. Security researchers have linked a series of attacks to compromises involving tools and platforms used by software developers, including Aqua Security’s Trivy, Bitwarden and Checkmarx. Such incidents can have wider consequences across the technology industry because compromised software updates may provide attackers with access to credentials and internal systems.

FBI Reports Major Cyber Incident

The Federal Bureau of Investigation was compelled to declare a “major cyber incident” in April after one of its surveillance systems was breached by actors believed to be linked to Chinese intelligence. This breach, which reportedly exposed the phone numbers of individuals under surveillance, has raised serious concerns about national security and the integrity of federal surveillance operations.

Hasbro Faces Operational Disruptions Following Cyberattack

Toy manufacturer Hasbro experienced weeks of operational disruption after detecting a cyberattack in late March. The company reported website outages and other operational challenges before confirming in May that the attackers had been removed from affected systems. Regulatory filing delays and other business impacts are expected to continue in the near term.

Millions Of Identity Documents Exposed

Several data exposure incidents reported during the year affected systems used for identity verification and customer onboarding. Cases involving a hotel check-in platform, a money transfer service, a prison communications provider and a UK visa portal exposed passports, driver’s licences and other identification documents belonging to more than two million people. The incidents have raised concerns about the security of personal information collected as part of identity verification requirements.

Growing Focus On Cybersecurity

The incidents reported throughout 2026 demonstrate the increasing impact of cyber threats across both public and private sectors. As organisations continue investing in digital infrastructure and artificial intelligence, cybersecurity remains a central concern for governments, businesses and critical service providers.

Aretilaw firm
eCredo
The Future Forbes Realty Global Properties
Uol

Become a Speaker

Become a Speaker

Become a Partner

Subscribe for our weekly newsletter