On June 2, 2026, foreign media outlets reported a significant security breach in Meta's proprietary AI customer service system. Cybercriminals capitalized on this vulnerability to reset Instagram account passwords and alter associated email addresses through interactions with the AI customer service, all without undergoing any form of identity verification, thus facilitating account theft. A series of high-profile organizations and public figures fell victim to this breach, including the official White House account from the Obama era, the personal account of the Chief Master Sergeant within the U.S. Space Force, and the official account of beauty retail behemoth Sephora. The hackers then proceeded to sell these compromised accounts via channels such as the dark web, engaging in illicit black and gray market transactions.
In response, Meta promptly issued a patch to address the vulnerability and commenced security enhancements for the affected accounts. However, numerous users whose accounts were stolen encountered hurdles in reclaiming their account rights. This incident has cast a spotlight on the AI transformation strategies employed by tech giants like Meta, with critics contending that in their zeal for full AI integration, they have neglected critical security risk management considerations.
