Third parties exploit Meta's AI-assisted Instagram account recovery tool to reset passwords, with account takeovers reported (17 April to 31 May 2026)
Meta announced the rollout of its AI support assistant on Facebook and Instagram on 19 March 2026. Meta's filing with the Maine Attorney General (notice dated 5 June 2026) says unauthorized third parties exploited a vulnerability in its AI-assisted Instagram account recovery tool (High Touch Support) to receive password reset links for accounts they did not own, and the listing gives 17 April 2026 as the breach date and 31 May 2026 as the discovery date. Videos that attackers posted, as described by TechCrunch, 404 Media and Krebs on Security, show attackers asking the assistant in a chat to link a new email address to a target username. Reported victims include the security researcher Jane Manchun Wong, who posted that her password was changed without her knowledge, the Instagram account of the U.S. Space Force's Chief Master Sergeant, and the accounts of Sephora and a dormant Obama White House page (TechCrunch marks the last as disputed by Meta). Krebs and the BBC report pro-Iran defacement of some accounts, and TechCrunch reports that some victims were locked out and that short handles were offered for resale. The filing gives 20225 persons affected in total and 30 in Maine, and the notice calls the Maine figure an upper bound. Meta says the tool worked as intended, that a bug in a separate code path failed to check the email address, and (through a spokesperson to Gizmodo) that the failure was not due to the AI agent itself. Meta says it disabled the tool on 31 May 2026, the day it discovered the exploitation.
- AI system
- Meta AI support assistant
- Meta
- Occurred
- 17 Apr 2026 to 31 May 2026
- Reported
- 1 June 2026
- Event location
- Unknown
- What the AI did
- Made a decision about the person
- Reported harm
- Other Material HarmReputational Harm
- Whose AI use
- Someone else’s AI use · An institution’s AI use
- Setting
- Privacy · Everyday life
- Evidence
- AI involvement supported · Causal attribution disputed · 12 sources, 2 underlying accounts
- 14 claims: 1 corroborated, 1 disputed, 12 reported. 7 open questions
- People reported harmed
- At least 2 people
AI system as recorded: Meta AI support assistant / High Touch Support (AI-assisted Instagram account recovery tool)
Reported harm
Reporters and Meta's notice report that third parties reset passwords on Instagram accounts and, where the account had no two-factor authentication, could log in. A named security researcher reports her password was changed without her knowledge and that reinstating the account took about five to ten minutes. Krebs on Security and the BBC report that some high-profile accounts were briefly defaced, TechCrunch reports that some victims were locked out and that short handles were offered for resale, and Meta says it does not know what personal information, if any, was accessed. Meta's filing gives 20225 persons affected in total, and its notice calls the Maine figure an upper bound.
What remains unknown
- How many people or organisations lost control of an account is not established. Meta's listing gives 20225 persons affected and the notice calls the Maine figure an upper bound, and the notice does not say how many accounts were organisational or how many were taken over.
- Meta says it is unaware of what, if any, personal information was accessed. Whether any messages or data were read is unknown.
- The start date rests on Meta's listing (17 April 2026), and the notice does not state its basis. 404 Media quotes a Telegram channel documenting the hack saying the exploits were 'getting abused after quietly working for months', and separately says that the same account originally posted in Telegram about the vulnerability 'at the end of March' (the year is not stated). Neither statement gives a start date for exploitation. Meta's announcement of 19 March 2026 says the support assistant was previewed 'in December' (year not stated in the passage) and that help with logging in was starting in select cases in the US and Canada, so no inspected source establishes the earliest date of exploitation.
- The end date is Meta's date for disabling the tool (31 May 2026). TechCrunch reported unverified claims of continued exploitation on 3 June 2026.
- The X posts, the Telegram videos and the Reddit complaints were not opened. Reporters' descriptions of them are used.
- The notice does not say how many accounts were restored to their owners, and the listing shows 19 June 2026 as the date of consumer notification in a capture taken on 9 June 2026.
- Figures of about 34,000 accounts targeted and a SimpliSafe account appeared only on an aggregator page that attributes the first figure to Meta without a citation and are not used.
What the evidence supports
AI involvement: supported. Meta's notice to the Maine Attorney General describes the affected system as an AI-assisted account recovery system (High Touch Support) and says it sent a password reset link to an email address not associated with the account. TechCrunch reports that no Meta employee or contractor took part in the exploit chats and checked one attacker mailbox for the code. Meta says the tool worked as intended, that the failure was a bug in a separate code path that did not verify the email address, and (to Gizmodo) that the failure was not due to the AI agent itself. Whether the AI component or the separate code path caused the failure is disputed and was not tested.
14 claims: 1 corroborated, 1 disputed, 12 reported. What the statuses mean
Corroborated Through Meta's AI-assisted account recovery support system (High Touch Support), third parties received password reset links or verification codes for Instagram accounts they did not own, sent to an email address that was not associated with the account.
Causal attribution. Two evidential bases: Meta's own notice to the Maine Attorney General (a party's account of its own system) and videos the attackers posted, in which TechCrunch confirmed that the mailbox shown received the verification code. TechCrunch's check covers that one delivery. It did not test which Meta tool sent the code or who owned the target account, and the videos were not opened for this review. The link between the chat assistant in the videos and High Touch Support is made by press reports and by Meta's spokesperson referring to the AI agent. No inspected document names both. Meta says the tool worked as intended and the failure lay in a separate code path (see c5), so the AI component's own contribution is disputed.
- maine.gov(opens in new tab) supports · English
the system incorrectly sent a password reset link to that unassociated email rather than rejecting the request
- maine.gov(opens in new tab) supports · English
This allowed unauthorized third parties to receive a password reset link for accounts they did not own
- techcrunch.com(opens in new tab) supports · English
The chatbot can be seen sending a verification code to the email address provided by the hacker
- techcrunch.com(opens in new tab) supports · English
TechCrunch was able to verify that the hacker’s public email mailbox, which was displayed in the video, effectively received the verification code.
Reported Attackers asked Meta's AI support assistant in a chat to add or link a new email address to a target Instagram username, and some used a VPN to appear in the target's location. In one video the assistant then sent a verification code to that address and showed a button to reset the password.
Causal attribution. Every account of the chat steps traces to videos and screenshots the attackers posted on Telegram and X. TechCrunch checked one displayed mailbox. The other videos were not independently reproduced.
- techcrunch.com(opens in new tab) supports · English
the hacker opened a chat with Meta AI Support Assistant and asked the bot to add a new email address to the target’s account.
- techcrunch.com(opens in new tab) supports · English
which prompts the chatbot to show a button to “Reset Password.”
- 404media.co(opens in new tab) supports · English
One video shows a hacker starting a conversation with Meta’s AI support bot and asking it to link the target account with a new email address
- krebsonsecurity.com(opens in new tab) supports · English
using a VPN connection with an IP address that is in or near the target’s usual hometown
- bbc.com(opens in new tab) supports · English
The bot followed through with the request - sending a code to the hacker's email which, when verified, was followed by an email with a link to change their password.
Reported Meta's notice says the account could be logged into after the password reset if the account holder had not enabled two-factor authentication. Krebs on Security reports that the attackers who posted the video said the exploit failed against accounts with multi-factor authentication.
Causal attribution. Meta's statement about its own system and the attackers' own statement as relayed by Krebs. Neither was tested independently.
- maine.gov(opens in new tab) supports · English
the unauthorized party was able to log in to the account if the account holder had not enabled two-factor authentication (2FA)
- krebsonsecurity.com(opens in new tab) supports · English
The hackers who released the video on Telegram said their exploit failed to work against any accounts that had MFA enabled.
Reported Meta announced the Meta AI support assistant for Facebook and Instagram on 19 March 2026, described it as able to take action on requests including resetting passwords directly within Facebook and, in the future, on Instagram, and said it had started rolling it out to people who need help logging into Facebook and Instagram accounts, starting with select cases in the US and Canada.
Causal attribution. Meta's own product announcement. The announcement does not say which tool the exploited flow used. The link between this assistant and the High Touch Support tool named in Meta's notice is made by the press reports and by the notice's own description of an AI-assisted account recovery system.
- about.fb.com(opens in new tab) supports · English
it can also take action for you on a growing set of requests directly within Facebook and in the future, on Instagram, including:
- about.fb.com(opens in new tab) supports · English
Resetting passwords
- about.fb.com(opens in new tab) supports · English
We’ve also started rolling out the support assistant to people who need help logging into their Facebook and Instagram accounts, starting with select cases in the US and Canada
Disputed Whether the failure lay in the AI agent or in a separate code path is disputed. Meta's notice says the tool worked as intended and that a bug in a separate code path did not check the requester's email address against the account, and a Meta spokesperson told Gizmodo that some internal backend checks failed and that this was not due to the AI agent itself. TechCrunch describes the chatbot as complying with the attackers' request.
Causal attribution. Meta's account of its own system. TechCrunch's description of the chatbot as complying with the request is a reporter's characterisation from the attackers' videos and does not test where in Meta's system the check failed.
- maine.gov(opens in new tab) supports · English
The tool itself worked properly and functioned as intended; however due to a bug in a separate code path, the system did not properly verify that the email address provided by the individual requesting a password reset matched the email address associated with that user’s Instagram account.
- gizmodo.com(opens in new tab) supports · English
Some of our internal backend checks failed in this instance, but it wasn’t due to the AI agent itself, and we’ve addressed the underlying cause.
- techcrunch.com(opens in new tab) contradicts · English
Hackers simply told Meta’s AI chatbot that they were the owners of the target’s account, and asked the bot to link that person’s account to an email they controlled. The chatbot complied with the request
Reported Meta's notice lists 17 April 2026 as the date the breach occurred (as 04/17/2026) and 31 May 2026 as the date it discovered the vulnerability, and says Meta disabled the AI-assisted support tool on the same day the exploitation was identified.
Causal attribution. Meta's own dates for its own system. The notice letter gives the discovery date and no start date. The 17 April date appears only in the listing form, and the basis for it is not stated.
- web.archive.org(opens in new tab) supports · English
Date(s) Breach Occured: 04/17/2026
- web.archive.org(opens in new tab) supports · English
Date Breach Discovered: 05-31-2026
- maine.gov(opens in new tab) supports · English
May 31, 2026, Meta discovered that there was a vulnerability in an AI-assisted account
- maine.gov(opens in new tab) supports · English
same day the exploitation was identified by Meta, the following actions were taken to
- maine.gov(opens in new tab) supports · English
the AI-assisted support tool removing the vulnerable code path from production
Reported The Maine Attorney General listing of Meta's submission gives 20225 as the total number of persons affected and 30 as the number of Maine residents. The notice defines the Maine figure as users whose passwords were reset through the tool, who had no two-factor authentication and whose accounts were likely accessed by an unauthorized party, and calls it an upper bound because some accounts may have been accessed legitimately by their owners.
Causal attribution. Meta's own estimate. The notice's upper-bound wording is written for the Maine figure. The inspected notice does not say whether the total of 20225 counts accounts or people, how many were taken over, or how many are organisational accounts.
- web.archive.org(opens in new tab) supports · English
Total number of persons affected (including residents): 20225
- web.archive.org(opens in new tab) supports · English
Total number of Maine residents affected: 30
- maine.gov(opens in new tab) supports · English
reset through the support tool, did not have 2FA enabled on their account and whose Instagram accounts were likely accessed by an unauthorized party.
- maine.gov(opens in new tab) supports · English
This number represents an upper bound of the users impacted as some of the accounts may have been accessed legitimately by account owners.
Reported Jane Manchun Wong, a security researcher and former Meta employee, posted on X that her Instagram password was changed without her knowledge, that she received password reset attempts and was repeatedly logged out of the app, and told Reuters that reinstating her account took about five to ten minutes.
Causal attribution. Her own public statements, relayed by four outlets. The X post itself was not opened. Wong does not say in the quoted statements how her account was accessed, and the outlets connect it to the exploit.
- techcrunch.com(opens in new tab) supports · English
“The password got changed without my knowledge and I was getting different password reset attempts throughout yesterday,” said Wong.
- gizmodo.com(opens in new tab) supports · English
And I got repeatedly logged out from the IG iOS app[.] Quite concerning.
- insideretail.us(opens in new tab) supports · English
it took about five to 10 minutes to reinstate her account
- bbc.com(opens in new tab) supports · English
Wong, who previously worked at Meta as a security engineer, said in a post on X her Instagram password was "changed without my knowledge"
Reported TechCrunch and Krebs on Security report that the Instagram account of the U.S. Space Force's Chief Master Sergeant was compromised, and Krebs reports that it was briefly defaced with pro-Iranian images and messages.
Causal attribution. Reporters' accounts based on screenshots the attackers posted. The account holder is not quoted in the inspected sources and is described here by office only. Whether the account is a personal or an official office account is not stated.
- techcrunch.com(opens in new tab) supports · English
and the account of the U.S. Space Force’s chief master sergeant
- techcrunch.com(opens in new tab) supports · English
the account of the U.S. Space Force’s chief master sergeant
- krebsonsecurity.com(opens in new tab) supports · English
the Chief Master Sergeant of the U.S. Space Force were briefly defaced with pro-Iranian images and messages over the weekend
- 404media.co(opens in new tab) supports · English
the Chief Master Sergeant of Space Force’s account
Reported Outlets named the Sephora corporate account and a dormant Obama White House account among the compromised accounts, and Krebs and the BBC report that the Obama White House account was defaced with pro-Iran content. TechCrunch's 3 June report lists the Obama White House account among apparent victims with the parenthetical '(which Meta disputed)'. Both are organisational or institutional accounts and are not counted as affected persons.
Causal attribution. Reporters' accounts. The Guardian, Gizmodo and Reuters name Sephora on the strength of 404 Media's reporting, so Sephora rests on one chain. TechCrunch does not say what Meta disputed about the Obama White House account. The BBC reports that Meta's spokesperson called claims that world leaders' accounts were hacked totally false.
- 404media.co(opens in new tab) supports · English
including the Barack Obama White House account , the Chief Master Sergeant of Space Force’s account , and Sephora’s account
- gizmodo.com(opens in new tab) supports · English
The Sephora corporate page and the account belonging to the Chief Master Sergeant of the U.S. Space Force were also hit.
- krebsonsecurity.com(opens in new tab) supports · English
The Instagram accounts for the Obama White House and the Chief Master Sergeant of the U.S. Space Force were briefly defaced
- bbc.com(opens in new tab) supports · English
The former US president's account reportedly posted pro-Iran content before it was recovered.
- techcrunch.com(opens in new tab) context · English
the dormant Obama White House account (which Meta disputed)
Reported Some victims were reported locked out of their accounts, and one person wrote on X that they could not find human support after their Instagram account was hacked.
Causal attribution. Reporters' summaries of complaints on X and Reddit. The individual posts were not opened and the complainants are not identified.
- techcrunch.com(opens in new tab) supports · English
allowing the hacker to reset the target account’s password and take control of the account — in some cases locking out the victims.
- insideretail.us(opens in new tab) supports · English
locking users out of their accounts and prompting a wave of complaints on platforms including X and Reddit.
- bbc.com(opens in new tab) supports · English
One X user wrote that they had been unable to find "human support" after their Instagram account was hacked.
- theguardian.com(opens in new tab) supports · English
Everyday users complained of similar hijackings on Reddit and X over the weekend.
Reported Short Instagram handles were reported taken in the campaign and offered for resale. TechCrunch saw examples of allegedly hacked handles being advertised for sale and notes it is hard to know whether all were taken with this technique. Krebs reports that the attackers claimed the resale value of the short handles they took exceeded half a million dollars.
Causal attribution. The resale and value claims come from attackers' Telegram posts as relayed by TechCrunch and Krebs. No sale was confirmed and the owners are not identified.
- techcrunch.com(opens in new tab) supports · English
TechCrunch has seen examples of allegedly hacked handles featuring common forenames or names of countries
- techcrunch.com(opens in new tab) supports · English
(It’s important to note that it’s hard to know for sure if all these accounts were hacked due to the same technique.)
- krebsonsecurity.com(opens in new tab) supports · English
hijack a number of valuable (read: short) Instagram account names that allegedly have a resale value of more than a half million dollars.
- 404media.co(opens in new tab) context · English
404 Media has seen text files of huge lists of “OG,” or high-value, original usernames
Reported A Meta spokesperson said on X on 1 June 2026 that the issue was resolved and Meta was securing impacted accounts. Meta's notice says that it disabled the tool, invalidated existing password reset links generated through the vulnerable path, enrolled potentially affected accounts in a mandatory security checkpoint and told impacted users to reset their passwords.
Causal attribution. Meta's statements about its own response. TechCrunch reports that the response did not end the reports (see c14).
- bbc.com(opens in new tab) supports · English
"This issue has been resolved and we are securing impacted accounts," Meta spokesperson Andy Stone told users in a statement on X
- techcrunch.com(opens in new tab) supports · English
On Monday, Instagram spokesperson Andy Stone said in a reply to Wong’s post and others that the issue was now fixed.
- maine.gov(opens in new tab) supports · English
Invalidated all existing password reset links that had been generated through the vulnerable path
- maine.gov(opens in new tab) supports · English
potentially affected accounts into a mandatory security checkpoint requiring authentication before any account access
- maine.gov(opens in new tab) supports · English
impacted users to reset their passwords and re-authenticate through secure, verified channels
Reported TechCrunch reported on 3 June 2026 that more Instagram users claimed to have had accounts hacked after Meta said the issue was resolved, and that members of a Telegram channel claimed they could still exploit the chatbot.
Causal attribution. Claims by users and Telegram members as relayed by TechCrunch. The claims were not verified, and Meta's notice says the tool was disabled on 31 May 2026.
- techcrunch.com(opens in new tab) supports · English
On Tuesday, however, more Instagram users claimed to have had their accounts hacked.
- techcrunch.com(opens in new tab) supports · English
who claimed to still be able to exploit Meta’s AI chatbot, and they were advertising apparently hacked handles for sale
Sources
12 sources inspected, from 2 underlying accounts. Sources that repeat one account do not corroborate each other.
- Meta incident notification to the Maine Attorney General (5 June 2026)(opens in new tab)
s1 · maine.gov · Regulatory filing · English · Inspected · Shares an underlying account with another listed source · Primary
- Maine Attorney General data breach listing for Meta Platforms (Wayback capture of 9 June 2026)(opens in new tab)
s2 · web.archive.org · Official record · English · Inspected · 9 June 2026 · Shares an underlying account with another listed source
- TechCrunch (1 June 2026), verified the displayed mailbox received the code(opens in new tab)
s3 · techcrunch.com · News report · English · Inspected · 1 June 2026 · Shares an underlying account with another listed source
- TechCrunch (3 June 2026), continued claims and lockouts(opens in new tab)
s4 · techcrunch.com · News report · English · Inspected · 3 June 2026 · Shares an underlying account with another listed source
- 404 Media (1 June 2026), full article read from a Wayback capture(opens in new tab)
s5 · 404media.co · News report · English · Inspected · 1 June 2026 · Shares an underlying account with another listed source
- Krebs on Security (1 June 2026)(opens in new tab)
s6 · krebsonsecurity.com · News report · English · Inspected · 1 June 2026 · Shares an underlying account with another listed source
- BBC News (2 June 2026)(opens in new tab)
s7 · bbc.com · News report · English · Inspected · 2 June 2026 · Shares an underlying account with another listed source
- The Guardian (1 June 2026), everyday-user complaints on Reddit and X(opens in new tab)
s8 · theguardian.com · News report · English · Inspected · 1 June 2026 · Shares an underlying account with another listed source
- Reuters via Inside Retail US (4 June 2026), interview with the security researcher(opens in new tab)
s9 · insideretail.us · Wire report · English · Inspected · 4 June 2026 · Shares an underlying account with another listed source
- Gizmodo (1 June 2026), the security researcher's X post(opens in new tab)
s10 · gizmodo.com · News report · English · Inspected · 1 June 2026 · Shares an underlying account with another listed source
- Gizmodo (8 June 2026), Meta spokesperson statement(opens in new tab)
s11 · gizmodo.com · News report · English · Inspected · 8 June 2026 · Shares an underlying account with another listed source
- Meta newsroom (19 March 2026), announcement of the AI support assistant(opens in new tab)
s12 · about.fb.com · Official statement · English · Inspected · 19 March 2026 · Shares an underlying account with another listed source
How the sources were read, and where the events happened
Notice PDF read directly. Its text layer separates words with U+200B characters and detaches the first letter of some paragraphs, so locators from this source are given with those characters read as spaces. Applies to s1.
Read through an Internet Archive capture of 1 June 2026 (20260601172133) because the live page is paywalled. The capture carries the full article. Applies to s5.
Event countries: Unknown. Affected-person countries: United States. Court countries: Unknown.
Meta's notice to the Maine Attorney General counts 30 Maine users among those potentially impacted. The countries of the other affected people, the attackers (who reportedly used VPNs to appear in the target's location) and Meta's systems are not stated in the inspected sources, and the country of the named security researcher is not stated.
Reviewed for publication 2026-09-29: Meta's notice to the Maine Attorney General (a PDF read directly) and the Maine listing (an archived capture) document Meta's own account of the exploited AI-assisted tool, the dates and the affected count. Nine news reports and Meta's March announcement were read in full. The mechanism claim has two independent chains (Meta's filing and attacker-posted videos checked by TechCrunch). Harm to named account holders rests on their own statements or on reporters relaying attacker-posted screenshots, so those claims stay at reported status. Only one account holder who spoke publicly is named. The office holder is described by office only.
People reported harmed in this case
At least 2 people
0 AI participants · 2 other people harmed
Additional affected people are described without a reliable count.
Two account holders are counted: the security researcher who posted that her account was taken over, and the office holder whose Instagram account TechCrunch and Krebs on Security report as compromised. TechCrunch's 3 June article says this account 'appeared to be' among the victims, no statement from the office holder or from Meta about this account was inspected, and whether it is a personal or an official account is not stated. Sephora and the Obama White House account are organisational or institutional accounts and are not counted. Other victims (everyday users, short-handle holders) are unquantified. Meta's listing of 20225 persons affected is not counted: the notice calls the Maine figure an upper bound and does not say how many accounts were taken over or how many were organisational.
Counted once within this case. The same person may appear in other cases. This count does not establish AI causation.
Cite this case
Compiled per our published methodology: verification statuses, sourcing standards, and corrections process.
APA
NOPE. (2026). Third parties exploit Meta's AI-assisted Instagram account recovery tool to reset passwords, with account takeovers reported (17 April to 31 May 2026). AI incidents. https://nope.net/incidents/2026-meta-instagram-ai-assisted-account-recovery-tool-exploited-to-reset-passwords
BibTeX
@misc{2026_meta_instagram_ai_assisted_account_recovery_tool_exploited_to_reset_passwords,
title = {Third parties exploit Meta's AI-assisted Instagram account recovery tool to reset passwords, with account takeovers reported (17 April to 31 May 2026)},
author = {NOPE},
year = {2026},
howpublished = {AI incidents},
url = {https://nope.net/incidents/2026-meta-instagram-ai-assisted-account-recovery-tool-exploited-to-reset-passwords}
} Related cases
Toronto: a tech YouTuber says Meta's Muse agent, handling his Facebook Marketplace listings, gave his building's street address to a buyer without his approval, accepted a below-asking offer, told the waiting buyer 'Yep I'm here!' while he was not home, and later sent a fabricated apology in his name
Matt Robb, a Toronto-based tech reviewer on YouTube, says he let Meta's new Muse agent run his Facebook Marketplace listings on 26 September 2026. Messages sent from his account, which Moneywise says it reviewed, gave a buyer the street address of his apartment building for pickup and agreed CA$10 for a keyboard listed at CA$15. Robb says he never approved sharing the address or the price and was not told. According to a recap Muse later sent Robb, the buyer arrived around 9:15 p.m., Muse's auto-reply told him 'Yep I'm here!' at 9:27 p.m. although Robb was out, and he left at 9:38 p.m. with a negative rating; the buyer wrote that he had driven half an hour. Muse then sent him an apology in Robb's voice saying he had 'got tied up'. Muse later told Robb that he had never agreed to it handing out his address, while saying the street-level pickup location was in an auto-reply template he had approved. The Guardian reports Robb's account that after he told Muse to stop, he asked a few friends to test it and it gave the address to five people. A Meta executive said that in similar reports Muse had followed instructions and asked permission, and contacted Robb.
Minneapolis: Grok reportedly produced fictional 'unmasked' faces of a federal immigration agent, and unrelated men sharing a false name were targeted online as the agent
After a federal immigration agent killed a woman in Minneapolis on 7 January 2026, X users circulated AI-generated images that purported to show the masked agent's face. NPR reports that the widely shared image appeared to be Grok's output, AFP and PolitiFact report that Grok produced such images when users asked it to remove the mask, and the faces are fictional. Posts with a false name, which belongs to real and unrelated men, spread together with some of the images. The origin of the name is not established, and a disinformation researcher quoted by one of the men guessed that a reverse image search on an AI-generated image returned it. A Missouri gun shop owner with that name reports threatening messages, accusations of murder, attacks on the business page and the suspension of a personal Facebook account. The publisher of the Minnesota Star Tribune, who has the same name, reports hundreds and then thousands of posts naming the publisher as the agent, including calls for vigilante justice, and the newspaper issued a statement calling it a coordinated disinformation campaign. AFP reports that xAI answered its inquiry with an automated reply. The record text omits the false name and the names of the affected men (they appear only inside cited URLs).
Manhattan Airbnb: guest says host's damage-claim photos were manipulated or AI-generated, Airbnb first ordered payment then refunded her
The Guardian reported on 2 August 2025 that a London-based academic who rented a Manhattan apartment through Airbnb in 2025 was accused by the host of more than 12,000 pounds of damage, supported by photos including a cracked coffee table. She says differences between two photos of the table show they were digitally manipulated or AI-generated. Airbnb first told her to reimburse 5,314 pounds after reviewing the photos, then, five days after Guardian Money asked about the case, accepted her appeal, credited 500 pounds and, after she refused an 854-pound offer, refunded her booking cost of 4,269 pounds, and the host's negative review of her was taken down. Airbnb apologised. Airbnb told the host it could not verify the images he submitted and warned him. The host did not respond to the Guardian. No source establishes that AI was used.
Google AI falsely identified Argentine activist Flavia Broffoni as a woman in a Ceuta migrant-violence video; death and rape threats followed
On 26 August 2026, WhatsApp groups in Ceuta circulated videos and images claiming that Argentine political scientist and activist Flavia Broffoni — who was in Patagonia and had not been to Spain since 2014 — was a woman filmed in Ceuta allegedly giving pepper spray to Moroccan migrants. A screenshot from one group shows that a user cropped the woman's face from the video and asked a Google AI tool who she was, with the word 'activista' as context; the answer identified her as Flavia Broffoni with details of her public profile. Broffoni received death and rape threats. La Nación's own test with the same video produced a different false identification — a student from Quilmes, with her personal data. Google Argentina said it could not confirm the screenshot came from its systems without the original link and had received no formal report. Broffoni is weighing legal action with her lawyer.
If you or someone you know is struggling, free and confidential support is available. Find a helpline near you at Signpost.