Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts
2026-06-08T19:23:31Z•44fde0ad1f6b6d556b6a68d480a6a2adb2db2cb01b7d4a4c6c65ebd5498209bf
account-takeoverai-abuseanti-ddos-abusearrestsaws-govcloudbotnetcanvascisacredential-exposuredata-extortiondata-leakddosgithubhosting-abuseinstagramiotkimwolfmetanetherlandspatch-tuesdayrussian-opssharepoint','bluehammer','windows','chrome','adobesocial-engineeringtelegramzero-day
What happened
A series of high-impact cyber incidents were reported: attackers published instructions on Telegram to trick Meta’s AI support assistant into resetting Instagram passwords, briefly hijacking high-profile accounts. A CISA contractor accidentally exposed highly privileged AWS GovCloud credentials and internal build/deploy artifacts on a public GitHub repo, triggering congressional scrutiny and widespread remediation. A large-scale data‑extortion attack against Canvas disrupted classes and threatened data from ~275 million students and staff. Law enforcement arrested the alleged Kimwolf botnet 'D
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 44fde0ad1f6b6d556b6a68d480a6a2adb2db2cb01b7d4a4c6c65ebd5498209bf
- Enrichment time
- 2026-06-08T19:23:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.