Video summary

So Instagram Got Completely Hacked...

Main summary

Key takeaways

News and Commentary

Summary of the subtitles (main points)

  • The video discusses a “wild hack” involving Instagram accounts linked to Meta AI. The creator argues that the incident wasn’t a true breach of internal systems, but rather an exploitation of Meta’s intended account-recovery flow—unintentionally made abusable by the AI support/chat system.

  • Core claim: attackers could prompt Meta AI during the password-reset/support process to provide verification steps and enable password changes. The creator describes a method where:

    • Attackers route account access through regions where Meta AI is available (e.g., via VPN).
    • They trigger a password reset.
    • Then they interact with Meta AI and submit a “new email” so the verification code is sent there.
    • After receiving the code, they complete the password reset and regain account access.
  • The creator emphasizes this is “stupid” or “impossibly stupid” because it appears to turn customer-support functionality into a security gate, with AI effectively handing out the “keys” to accounts.

  • The video states the issue was reported as fixed by Meta (citing Andy Stone), but warns against complacency: with AI, other vulnerabilities/hallucinations can be discovered again even after patches.

  • Alleged impact examples mentioned:

    • A Space Force chief/master sergeant’s Instagram account allegedly got hacked and used for pro-Iran content, framed as part of US–Iran digital hostilities.
    • An Obama archived White House-related account allegedly circulated pro-Iran spam (with clarification that it was an archived account, not “Obama himself”).
  • The creator further claims the bot could bypass two-factor authentication, including selfie verification, by using AI-generated images to satisfy the verification step (described as “circumventing” selfie checks).

  • Meta’s framing (as relayed in the video) is that there was no data breach—instead, Meta purportedly fixed an issue where an external party could request password reset emails for some Instagram users, with no direct theft of data. The creator argues that allowing unauthorized account takeover through an AI-assisted recovery feature is still effectively a security failure.

  • The video connects the problem to broader organizational and policy issues at Meta:

    • It references past concern that attorneys general warned Meta about rising account takeovers.
    • It suggests Meta has reduced staffing in risk/security/privacy roles (citing a Business Insider memorandum) and shifted more security responsibility toward AI systems.
  • The creator ends with a broader warning: if AI-assisted security systems are exploitable at Meta, similar failures could occur at Google, Microsoft, and other major tech platforms as AI becomes deeply integrated into account and identity workflows. The video portrays this as a systemic trend, not a one-off incident.

Presenters or contributors

  • Me Mutahar (video presenter)

Original video