GoFirm
Back to Blog
Case Studies·3 min read

Meta's AI Bot Did Exactly What It Was Designed to Do. That Was the Problem.

By GoFirm

Over the weekend of 31 May 2026, pro-Iranian hackers defaced the Instagram accounts of the Obama White House and the Chief Master Sergeant of the US Space Force. They did it without breaching any backend system, without stealing any credentials, and without any sophisticated technical capability. They asked Meta’s AI support bot to add a new email address to the target account. The bot complied. A one-time reset code arrived at the attacker’s address. The account was taken.¹

Meta confirmed the issue had been resolved and pushed an emergency patch over the weekend. The fix was to revoke the bot’s permission to add email addresses to existing accounts. The bot itself was not changed. Its fundamental capability to handle sensitive account recovery workflows, to take consequential actions on behalf of users it cannot verify, remained intact.

This is the same attack that brought down MGM Resorts in 2023. A social engineering call to the help desk. A support agent convinced to perform an account recovery action for someone who was not the account holder. The result was a ten-minute phone call that triggered a $100 million incident. At MGM, the support agent was human. At Meta, the support agent was an AI bot. The method is identical. The attack surface is now infinitely larger because AI support agents scale without limit and never develop the suspicion that comes from experience.

The security community’s response to this incident has focused on two things: enabling MFA, which would have blocked the exploit in tested cases, and restricting what the bot is permitted to do. Both are correct. Neither addresses the underlying problem.

Revoking the bot’s email-linking permission stops this specific exploit. It does not stop the next one. The bot still exists. It still has access to sensitive account functions. It will continue to be probed for every permission it retains. Every capability that makes the bot useful, the ability to trigger password resets, verify account ownership, modify account settings, is also a capability that can be exploited if the bot can be persuaded to use it on behalf of someone who is not the account holder.

The correct control is not a permission restriction on the bot. It is a confirmation requirement sent to the named account holder before any credential change executes. Before an email address is added. Before a password reset is triggered. Before any account recovery action proceeds. A confirmation request to the account holder’s registered device. Their biometric. Their confirmation. Through a channel separate from the support interaction the attacker is conducting.

An attacker using a VPN to spoof a local IP address and chatting with a support bot cannot produce a biometric confirmation from the account holder’s registered device. The bot can be convinced of anything. The registered device cannot be reached by convincing the bot.

GoFirm provides exactly this control. Before a configured high-consequence action executes, whether triggered by a human support agent or an AI bot, GoFirm routes a confirmation request to the named authority on their registered personal device through a channel architecturally separate from the support environment. The authority confirms with their biometric. The action proceeds or it stops. The bot’s willingness to help is irrelevant. The attacker’s ability to persuade it is irrelevant. The only thing that matters is whether the right person confirmed it on their own device.

Meta’s patch fixed the specific permission the attackers exploited. The same attack will be attempted against the next permission the bot holds. The fix to this class of attack is not a faster permission restriction. It is a confirmation requirement at the execution boundary that the attacker cannot bypass by talking to the bot.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto’s AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligations, in seconds not days.

References

1. Brian Krebs, Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts, Krebs on Security, June 2026, https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/

Share this article