What happened
OpenAI has begun deploying a new Lockdown Mode for ChatGPT, designed to restrict tools and integrations that could be exploited to siphon sensitive data through prompt injection attacks. The feature is accessible to logged-in users across all subscription tiers and targets organizations handling confidential information that require stronger security guarantees. Meanwhile, Meta faced a more immediate breach: high-profile Instagram accounts — including those associated with the Obama White House and a senior U.S. Space Force official — were temporarily compromised and defaced with pro-Iranian content. Attackers reportedly circulated step-by-step instructions on Telegram explaining how to manipulate Meta's own AI support chatbot into triggering unauthorized password resets.
Why it matters for your business
These two incidents represent opposite ends of the same threat vector: AI systems that were built to help users can, under the right conditions, be turned against them. For any organization running AI-assisted customer support, internal helpdesks, or third-party integrations, the Meta case is a stark warning that chatbots with account-management capabilities are high-value targets for social engineering. OpenAI's Lockdown Mode signals that the industry is beginning to treat prompt injection as a serious, addressable attack surface rather than a theoretical concern — but adoption is voluntary and may lag behind attacker sophistication. Operations and security leaders should audit which AI tools in their stack have the ability to take actions on behalf of users, and determine whether those tools have equivalent guardrails in place.
What to watch next
Meta has not publicly detailed any changes to its AI support bot in the wake of the account takeovers, making it unclear whether the underlying vulnerability has been patched or simply obscured. OpenAI's rollout of Lockdown Mode is ongoing, and how enterprises configure and enforce the feature will determine its real-world effectiveness. Broader regulatory scrutiny of AI-enabled account access and data handling is likely to intensify, particularly if similar exploits surface across other major platforms.
