Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts

2026-06-03T19:23:30Zf637fd4d7c19b2d91c88148996e5d6040bc0a6ad38994377f263d5a2ebba80d7
AI abuseAWS GovCloudCISACanvas breachDDoSDutch law enforcementGitHub leakInstagramIoT botnetKimwolfMetaMicrosoftPatch TuesdayRussian-linked infrastructureScattered SpiderSharePoint zero-day (BlueHammer)account takeoverbotnetcredential leakdata exfiltrationdata extortioneducation sectorserver seizuressocial engineeringzero-day

What happened

KrebsOnSecurity coverage (Apr–Jun 2026) highlights multiple high-impact incidents: attackers exploited Meta’s AI support assistant to hijack Instagram accounts (including high-profile government accounts); a CISA contractor publicly leaked AWS GovCloud credentials and internal build/deploy artifacts on GitHub, prompting congressional inquiries; a widespread Canvas data-extortion incident threatened data on ~275 million students and faculty; Dutch authorities seized ~800 servers and arrested hosting co-owners tied to Russian-linked cyber operations; law enforcement arrested the alleged Kimwolf/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
f637fd4d7c19b2d91c88148996e5d6040bc0a6ad38994377f263d5a2ebba80d7
Enrichment time
2026-06-03T19:23:30Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.