Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts
2026-06-09T01:23:32Z•d20d7ab1714fe2a6d03150464afbe108dafd5995b68711a87bcde820f7216f93
account-takeoverai-support-botanti-ddos-abuseaws-govcloudcanvascisacongressional-inquirycredentials-leakdata-extortiondata-leakddoseducation-sectorgithub-exposurehosting-abuseinstagramiot-botnetkimwolfmetanetherlandspatch-tuesdayrussian-influence-opsserver-seizuresharepoint-zero-day','bluehammer','chrome-zero-day','adobe-rce'social-engineeringzero-day
What happened
Multiple high-impact incidents reported by KrebsOnSecurity: attackers manipulated Meta’s AI support assistant to reset Instagram passwords and briefly deface high-profile accounts; a CISA contractor publicly exposed AWS GovCloud credentials and internal build/deploy files on GitHub, prompting congressional inquiries; the Netherlands seized ~800 servers and arrested operators of hosting firms tied to Russian cyber/influence campaigns; a suspected Kimwolf IoT botnet operator was arrested and charged in Canada and the U.S.; the Canvas education platform suffered a large data-extortion breach that
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- d20d7ab1714fe2a6d03150464afbe108dafd5995b68711a87bcde820f7216f93
- Enrichment time
- 2026-06-09T01:23:32Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.