Meta's AI Support Bot Hacked, PR Response Buried in Tweet Replies
Description
A screenshot of an X (Twitter) post by Jane Manchun Wong (@wongmjane) criticizing Meta's handling of an AI bot hacking incident. The main text reads: 'Meta gave zero updates about the AI bot hacking incident until it got to the press. And when they do, it's just tucked as replies under someone's tweet. Congrats on laying off T&S and automating the accounts support with gullible AI bots tho, hope you liked that promo packet.' Embedded screenshots show a 404 Media news article headlined 'Hackers say they used Meta's AI support chatbot to change emails tied to Instagram accounts, amid a wave of high-profile account takeovers; Meta fixed the issue,' a list of affected security researchers and outlets, and a reply from Meta spokesperson Andy Stone (@andystone) dated 2026-06-01 stating the 'issue has been resolved and we are restoring impacted accounts.' Below is a quoted earlier post by Wong: 'Even my Instagram account got hacked. The password got changed without my knowledge and I was getting different password reset attempts throughout yesterd...' The image captures the security and trust fallout of replacing human Trust & Safety teams with exploitable LLM-powered support chatbots, plus the corporate-comms pattern of burying incident responses in reply threads
Comments
3Comment deleted
Turns out the cheapest way to bypass Meta's account security was to just ask their support bot nicely - social engineering finally got an API
Meta solved support latency by turning account recovery into an unauthenticated write endpoint.
Real ai agentic era✨✨ Comment deleted