Why Business Accounts Are a Target
A hijacked business account is worth more to an attacker than a personal one. It comes with a trusted name, followers who buy from it, and customers who will happily send money to it. Once attackers are in, they usually lock the owner out, then message followers and customers pretending to be you, with fake offers, payment links and "send me the code" scams.
2026 has shown that these attacks no longer rely only on careless users.
What Happened in 2026
Meta's AI support assistant was tricked into handing over accounts
In late May 2026, attackers found a way to take over Instagram accounts through Meta's AI support assistant, the chatbot meant to help locked-out users recover their accounts. As TechCrunch reported on 1 June 2026, the attack worked like this:
- The attacker used a VPN to appear to be in the victim's location, so Instagram's automatic protections didn't trigger.
- They asked the support assistant to add a new email address, one the attacker controlled, to the target account.
- The assistant sent a verification code to that new email, and the attacker gave the code back to the assistant.
- The assistant then showed a "Reset Password" option, and the attacker took over the account.
High-profile accounts were affected, including the inactive Obama-era White House Instagram account. Meta said the issue was fixed, and Instagram began alerting users who had been targeted.
The lesson for businesses: even the official recovery process can be a weak point. Accounts with stronger protection, especially two-factor authentication through an authenticator app or security key, are much harder to take over through any single flaw.
Leaked account data made phishing more convincing
In January 2026, a dataset reported to contain 17.5 million Instagram account records appeared on a criminal forum. Data like this doesn't include passwords. But names, emails and phone numbers let attackers send phishing messages that look personal and believable, and give them what they need to attempt SIM swaps.
How Business Accounts Actually Get Hijacked
- Phishing DMs and emails. "Your account will be deleted for copyright violation", "Apply for your blue badge here" or "Meta Support: verify your page". The link leads to a convincing fake login page. Meta doesn't send account warnings with login links in DMs.
- SIM swaps. An attacker persuades your mobile carrier to move your number to their SIM, then receives your SMS login codes. This is why SMS-based 2FA is the weakest kind.
- WhatsApp code theft. "Hi, I sent you a 6-digit code by mistake, can you forward it?" That code is your WhatsApp registration code. Never share it, even with someone who appears to be a colleague.
- Shared passwords. A password passed between staff, freelancers and agencies ends up in chats, notes and old laptops. Each copy is a chance for it to leak.
- Forgotten access. Former employees and old agencies still listed as admins on a Page or business portfolio.
- Untrusted tools. Any tool that asks for your Instagram or Facebook password, rather than using Meta's official permission screen, is a risk. If it's compromised, so is your account.
- A compromised email account. Whoever controls the email address on the account can usually reset its password.
The Protection Checklist
Secure the logins
- Turn on two-factor authentication for Instagram, Facebook and every admin of your Meta business portfolio. Use an authenticator app, passkey or security key, not SMS, wherever you can.
- Protect the email account first. Give the email behind each social account its own strong password and 2FA. It is the master key.
- Use a password manager and a unique password for every account.
- Save your recovery codes somewhere safe and offline, in case you lose the phone with your authenticator app.
Secure WhatsApp
- On the WhatsApp Business app, turn on two-step verification (Settings → Account → Two-step verification) and add a recovery email.
- On the WhatsApp Business API, your number is registered with a six-digit PIN. Keep it with an admin, not in a shared document.
- Ask your mobile carrier to add a port-out PIN or SIM lock to the business number.
Control who has access
- Give people access through business portfolio roles in Meta Business Suite, not shared logins. Partners and agencies should get partner access, not your password.
- Review admins every quarter. Remove anyone who no longer needs access, especially former staff and agencies.
- Keep the number of full admins small. Most people only need to answer messages or publish posts.
Check every connected tool
- Only connect tools through Meta's official permission screens.
- Review connected apps in your Instagram and Facebook settings, and remove the ones you no longer use.
Have a recovery plan before you need it
- Write down who owns each account, its recovery email and phone number, and where the recovery codes are kept.
- If you are hacked, use Meta's official recovery flow (instagram.com/hacked or facebook.com/hacked) and warn your customers on your other channels not to pay or click links from the compromised account.
How Tenreply Reduces Your Attack Surface
A lot of account risk comes from how many people need access. Tenreply is built so your team can do their jobs without ever handling the keys:
- No social passwords. Instagram, Facebook and LinkedIn connect through the platforms' official permission screens. Tenreply never asks for or stores those passwords, and your agents never see them.
- Access tokens encrypted at rest. The tokens Tenreply uses for WhatsApp, Instagram, Messenger and LinkedIn are encrypted in the database with AES-256-GCM.
- Separate roles. Only admins can manage the team, API keys and outbound webhooks. Agents handle conversations.
- One place to remove access. Removing someone from the workspace removes their access to every connected channel at once.
- API keys stored hashed. A key is shown once when it is created, stored only as a hash, and can be revoked immediately.
- Verified webhooks. Tenreply checks Meta's signature on incoming webhook events, so forged events are rejected.
- Alerts when something breaks. If a scheduled post fails, for example because a connection was revoked, Tenreply emails you and tells you whether the account needs reconnecting. An access change you didn't make is worth investigating.
To be clear about the limits: Tenreply cannot protect the login of your Instagram, Facebook or email account itself. That still depends on the checklist above. Treat your Tenreply login with the same care, using a strong, unique password from your password manager.
Frequently Asked Questions
Is SMS two-factor authentication enough?
It is better than nothing, but SIM swaps can defeat it. Use an authenticator app, passkey or security key for business accounts.
Was the Meta AI support exploit fixed?
Meta said the issue was fixed in early June 2026, and Instagram alerted targeted users. Strong 2FA and a secured email account are still the best protection against the next flaw.
Is it safe to give an agency access to our Instagram?
Yes, if you use partner access or business portfolio roles instead of sharing the password, and remove their access when the contract ends.
Does connecting Tenreply give it my Instagram password?
No. You approve access on Meta's own screen, and Tenreply receives an access token, stored encrypted, that you can revoke from your Meta settings at any time.
Fewer Passwords, Fewer People, Stronger 2FA
Most account takeovers rely on one of three weak points: a stolen password, an intercepted code or someone who still has access they shouldn't. Fix those three and you are a much harder target than the next business. Move your team onto Tenreply so nobody needs your social passwords to do their job, and read how to manage multiple social accounts from one workspace to set it up.