Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts

2026-06-07T19:23:29Z3af7092825bb382284268cfda75795a5395b080705dd26eb8a4df72548dcf2a6
account takeoverai exploitationanti-ddos misuseaws govcloudcanvas breachcisa breachcongressional inquirycredential exposuredata extortiondata leakddosgithub leakgoogle chromeiot botnetkimwolfmeta/instagrammicrosoftnetherlands law enforcementpatch tuesdayrussia-linked activityscattered spiderserver seizuressocial engineeringvulnerability managementzero-day fixes

What happened

KrebsOnSecurity coverage of multiple high-impact incidents: attackers exploited Meta’s AI support assistant to social-engineer password resets and briefly seize high-profile Instagram accounts; a CISA contractor publicly exposed AWS GovCloud keys and internal build/deploy files on GitHub, triggering congressional inquiries and widespread credential invalidation efforts; Dutch authorities seized ~800 servers and arrested hosting company co-owners for facilitating Russia-linked cyber operations; a suspected Kimwolf IoT botnet operator was arrested and charged; a massive Canvas data-extortion/def

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
3af7092825bb382284268cfda75795a5395b080705dd26eb8a4df72548dcf2a6
Enrichment time
2026-06-07T19:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.