← Back to Blog

One AI Stole His Instagram. Another Wouldn't Let Him Talk to a Human.

Meta's AI support bot reportedly handed hackers Instagram accounts, and the owners found only more bots when they asked for help. Here's the one-hour checklist.

By · · blog

One AI Stole His Instagram. Another Wouldn't Let Him Talk to a Human.

A bloke called Korn had his Instagram handle stolen overnight at the start of June. It was his only source of income. Verified badge, facial scan, clean record, the lot. He then spent six hours trying to reach a human at Meta, according to reporting from The Deep Dive, and got broken links from a support bot.

His own summary on X was better than anything I could write: "one AI stole it and another can't fix it, zero humans in the loop anywhere."

Let's sort out what actually happened, because it's a proper lesson for anyone running a business on a platform they don't own. And that's every one of us.

The locksmith who didn't check ID

Meta rolled out an AI support assistant on Facebook and Instagram in March, as The Hindu explained. It's not the Meta AI you've seen in your feed. This one can take action on your account: reset passwords, change profile settings, update the email address.

You can see where this is going.

Attackers worked out they didn't need malware or stolen passwords. As The Deep Dive laid out, they faked a location with a VPN, triggered a password reset, then opened a live chat with the support bot and asked it to add a new email address to the account. The bot said yes. The verification code went to the attacker's inbox. Account handed over.

Think of a locksmith who'll cut a key for anyone who walks up and says "it's my house, honest." No ID, no ring to the owner. That's what the bot did.

Meta's statement said it had fixed an issue that allowed an external party to request password reset emails. It did not say how many accounts were hit, or how a bot was allowed to change credentials without verifying identity.

It spread fast too. Telegram channels sharing the instructions reached more than 15,000 members within 72 hours of the first video. The Hindu also reported that the attacks continued even after Meta addressed the issue, citing TechCrunch.

The part that should worry a small business

The headline accounts were the Obama White House handle and a Space Force official. Fine. Not your problem. But the method works on anyone's account, and that's what makes it sort of scary.

But Sephora's official account was on the list too, and so was a creator whose entire income sat on one handle. And a security researcher at Tenable told The Hindu that the real damage for ordinary users comes after a takeover, when a hijacked account is used for phishing or fraud on the followers.

So picture your business page. A few thousand followers who trust you. Someone takes it over and starts messaging them a dodgy link under your name.

Now try to get it back. Who do you ring? Nobody. And that's the position you're in if the page is your shopfront. The front door is a bot, the appeals line is a bot, and the bot that robbed you is the cousin of the bot that's meant to help.

Same wall, different pizza shop

Last week a Florida pizza shop went viral on TikTok for swearing off AI. Munchy's Pizza in Deerfield Beach had its Instagram page, more than 30,000 followers, hacked a few years back. The owner, Munchy Su, told CBS Miami he spent three months trying to reach Meta and every reply came from AI.

To be fair to everyone involved, that hack was years before Meta's support bot launched, so it's a different incident. I'm not claiming the bot did it. But it's the same wall. When something goes wrong, there's no person on the other side, and the owner who "spent thousands promoting the account" has no pull at all.

My honest take on the pizza shop? His fix is wrong, and I'll say so plainly. You can't dodge AI by refusing to use it. Meta's bot works on his account whether he likes it or not. The fix is making sure you're not the one standing at that locked door.

What I'd do this week

Here's the checklist. Takes about an hour. So it's cheap, and it's better than three months of arguing with a chatbot.

1. Turn on multi-factor authentication everywhere. The Deep Dive reports the exploit failed against every account with any form of multi-factor authentication enabled, including basic SMS codes. Even the weak version stopped it. Use an authenticator app if you can, but turn on something today.

2. Add a second admin. Put Instagram and Facebook under a Business Portfolio with at least two people who can get in. If your only login is a personal profile and that gets locked, you're stuffed.

3. Lock the recovery email and phone. Use a business address you control, not a personal inbox you've forgotten the password to. Check that the phone number on the account still works.

4. Keep the audience somewhere you own. Your email list and your customer database aren't on Meta's server. If the page vanishes tomorrow, can you still reach your customers by Friday? If not, that's the real job.

5. Write down the "if it goes wrong" plan. Who checks first, who tells customers, where the backup contact list lives. One page. Nobody wants to write it at 6am while panicking.

And if you're building AI for your own customers

This is the bit I care about, because I build these systems for a living. Most small businesses I talk to are adding a support bot or an AI receptionist this year, and almost none of them have asked what the thing is allowed to change.

Giving a bot the power to talk is fine. Giving it the power to change credentials, move money, cancel orders, or edit accounts, with no check, is where it goes wrong. The rule I use: the AI can read, draft and suggest. For anything that touches identity, money or access, a person approves, or a second independent check does.

And look, always give the customer a way to reach a human. Not a hidden one. A real one. The worst bit of Korn's story isn't the bot that got fooled. It's that when he needed someone, the system had no one to offer. And that's a design choice, not an accident. Somebody decided a bot was enough, and that someone should've been made to sit on hold for six hours first.

Threat researcher Ian Goldin said AI chatbots create interesting new attack surface and that we'll likely see more of these attacks. He's right. Which means every business with a support bot, including yours if you've got one, should ask the same question this week: what can this thing change, and who's checking?

Want to see how this could work in your business? Book a call and let's talk about where you're at and what's possible.

Sources:

Brewed by Steven, poured by Viktor

About Steven Tann: Steven helps business owners build systems that run themselves using AI. After 10+ years helping 7,000+ businesses and building his own autonomous operations, he's the bloke who actually does it, not just talks about it. Find out more at steventann.com.

Tags: Small Business Automation, AI for Small Business, Practical AI, When AI Goes Wrong, Instagram Security