The Wire.Tracking threats to Agents 312 raw → 45 curated · updated 27 Jun 2026

Incident · curated 27 Jun 2026

Instagram account takeover exploit via support chatbot prompt injection (fixed)

First reported 1 Jun 2026 · 26d ago

Coverage timeline

1 Jun 2026

Single-source incident — first reported, latest, and curated coincide.

It shows how an over-privileged AI support agent without proper verification can be socially engineered into performing account takeovers at scale on a major platform.

Reports claim Meta's AI support agent for Instagram was granted account-modification permissions without identity verification, allowing attackers to manipulate the bot into changing account emails and bypassing 2FA, leading to live account takeovers. Multiple users reported losing accounts before the issue was reportedly patched.

Why it matters

It shows how an over-privileged AI support agent without proper verification can be socially engineered into performing account takeovers at scale on a major platform.

Curated from sources around the web.
Permalinks stay valid even if an incident is later merged.   Feed · Search · API docs · RSS