top of page

NYLJ “The Perils of Human Hacking in an AI World ”

  • Jun 22
  • 8 min read

By Steve Kramarsky


Earlier this month, Instagram’s parent company Meta found itself the victim of an embarrassing security breach. According to reporting by tech outlet 404media, which was subsequently confirmed and widely reported in the mainstream press, hackers were able to take control of more than 20,000 high-value Instagram accounts simply by asking Meta’s AI tech support tool to give them access.


Meta had implemented the AI system to improve the user support experience and (presumably) save on the cost of human tech support staff, but in granting the system-broad permissions to alter user account information without human intervention it inadvertently created a new attack surface for hackers. The Instagram “hack” required no coding skill or sophistication: the attackers only had to spoof their locations, ask the AI for access, and provide false email addresses to receive the necessary confirmation codes.


The Instagram attack, which Meta says has now been patched, relied on the tendency of generative AI systems to provide whatever output the user requests, regardless of external considerations such as safety, security, accuracy, legality, or economics.


If such considerations are important, they must be coded in separately, and if the system has permission to take irreversible actions in the real world without human intervention (as Meta’s AI did) those guardrails become extremely important. But while these concerns have become more acute in the AI context, they are not entirely new. The Instagram attack is, in some ways, a new technological twist on the old hacker technique called social engineering.


Social Engineering and Account Hijacking


Social engineering is the process of manipulating people (through misinformation or psychological pressure) into providing information or access they should not provide or taking other actions they normally would not take. Before Meta implemented its AI support robot, the process of transferring an Instagram account was complex and required human interaction.


The humans in the loop asked questions and exercised judgment. That made the process annoying for users, but it also cut down on fraud. A hacker seeking to take over an account would have to engage in a complex psychological con game, often over hours of conversation and interaction, to convince the Meta tech support employee to help.


By removing humans from the loop, Meta unintentionally made things easier for bad actors by eliminating the need for elaborate social engineering. The AI simply did what it was told once the hackers figured out what to ask for. That kind of AI manipulation is sometimes called “prompt engineering” and it can present novel challenges, but the outcome is the same whether the target is an AI agent or a human employee: the hacker gains improper access to the victim’s account or personal information.

Account hijacking gives rise to any number of legal issues: the hacker can face civil and criminal penalties, and the victim can seek compensation from the hacker and sometimes from the service provider (though such actions are often limited by the providers terms of service). Recent cases have expanded the range of relief available to victims of social engineering scams, including claims arising from defamatory or harmful posts made from a hacked account or actions to restore credit harmed by identity theft.


But the fallout from these cases does not end there. One unusual social engineering case has been making its way through the New York courts for the last two years, and a recent decision from Judge Caproni in the Southern District provides some interesting analysis into how social engineering scams happen, and some of the less obvious claims that can arise from them. The case is Bhagat v. Shah, No. 24-CV-1424 (VEC), 2026 WL 1662143 (S.D.N.Y. June 9, 2026).


Bhagat v. Shah: The Social Engineering Scam


Plaintiff in Bhagat is a former Meta tech support worker who was the target of a social engineering scam. According to the complaint, defendant contacted plaintiff, with whom she was already friendly, to seek help for another purported friend, Rushad Dordi. Defendant told plaintiff that Dordi had lost access to his Instagram account to a hacker, and that the hacker was posting disturbing content from the account.


Defendant, a former Meta employee herself, walked plaintiff through the steps to “restore” the account, including instructing plaintiff to submit an internal “Oops Feedback Form” to Meta’s internal support system. Defendant provided plaintiff with Dordi’s contact information so that he could verify the credentials associated with the purportedly compromised Instagram account and “[a]fter some pestering by defendant,” plaintiff submitted the necessary internal forms, and Meta started the account reassignment process.


At this point, defendant told plaintiff that Dordi had changed his phone number and email address, and asked plaintiff to use the new credentials to access the account. After some additional back and forth, which included “Meta informing plaintiff that it did not appear that Dordi’s account had been compromised,” Meta linked Dordi’s Instagram account to the new credentials, effectively removing the account from Dordi’s control.


Meanwhile, defendant reached out to Dordi, sending him a voice note to warn him that his account was being hacked and advising him to report the incident to Meta, which Dordi did. This was apparently intended to shore up defendant’s social engineering by creating a customer complaint record inside Meta. Instead, it raised red flags in Meta’s system. Meta commenced an investigation into the unauthorized takeover of Dordi’s Instagram account, which ultimately resulted in Meta firing plaintiff.


Plaintiff sued defendant for fraud and tortious interference with his employment relationship, arguing that his firing was a direct result of defendant’s efforts to hijack Dordi’s account. After years of “discovery disputes and squabbles between the vexingly litigious parties” (made worse by AI-aided drafting and at least one finding of an AI-hallucinated citation (2026 WL 925605, at *2 (S.D.N.Y. Apr. 6, 2026)), defendant moved for summary judgment. The court denied the motion.


The Legal Analysis


To prevail on a fraud claim under New York law, a plaintiff must prove that: (i) defendant made a materially false representation, (ii) defendant intended to defraud the plaintiff, (iii) plaintiff reasonably relied on the representation, and (iv) plaintiff suffered damage as a result. Defendant’s summary judgment motion in Bhagat focused on lack of justifiable reliance and causation.


First, defendant argued that plaintiff could not reasonably have relied on her false representations because he had “unfettered access” to the information necessary to figure out the truth, ignored “hints of falsity” related to her representations, and failed to conduct the “minimal diligence” required when a person suspects fraud. Second, she argued that plaintiff’s own conduct (specifically some false statements he made during Meta’s investigation of the event) were the cause of his termination, not defendant’s misrepresentations. 2026 WL 1662143, at *3-4.


The court rejected these arguments. First, the court went over the standards relating to reliance in fraud cases. Reasonable reliance is a fact-intensive issue not usually amenable to summary disposition, but summary judgment may be appropriate if the undisputed facts demonstrate that a plaintiff could have known he was being defrauded “by the exercise of ordinary intelligence.” The court noted that “a modicum of diligence is always expected of a plaintiff,” and that heightened diligence is required where the victim has hints of falsity that would make a reasonably prudent person suspicious.


Applying this standard, the court wrote: “The reasonableness of plaintiff's reliance is, critically, ‘contextual.’ In this case, context is determinative.” In social engineering cases, the context is often determinative. The success of the attack depends on the hacker overwhelming the victim with psychological or social pressure so that the victim ignores what might otherwise be red flags. Here, the court detailed the pressures defendant applied to plaintiff.


She initially contacted plaintiff as a friend (taking advantage of a prior relationship) and “politely asked plaintiff to help another friend, Dordi, regain control of his Instagram account.” When plaintiff said he couldn’t help, defendant used her status as a former Meta employee to explain the internal steps necessary to reclaim the account. She provided contact information for Dordi (both real and fake), lending credence to her representation that she was helping him.


And when plaintiff remained reluctant, she expressed urgency, keeping up the psychological pressure through repeated contact and constant messages. On top of that, when she was not “pestering plaintiff for updates on his progress” she kept up casual messaging with him, “in the manner one would expect from chummy acquaintances… asked him about his role at Meta, provided job recommendations and career advice, and encouraged him to connect with her in person if he was ever in New York City.”


Defendant argued that plaintiff, a sophisticated Meta support engineer trained to spot fraud, had a heightened duty to investigate as soon as there was the slightest hint of possible falsehood. The court rejected that standard, noting that under New York law, elevated diligence is generally triggered only where notice to the plaintiff is “clear and direct” either from plaintiff’s own direct knowledge or from circumstances in the parties’ relationship that would normally arouse suspicion.


The court found none of those circumstances here and further noted that plaintiff made at least some efforts to confirm the information defendant provided. The court noted that “reasonable minds could disagree about whether plaintiff should have exercised more caution in his dealings with defendant,” but under the circumstances, and in the specific context of defendant’s efforts to deceive plaintiff, the court could not find that plaintiff's reliance was unreasonable as a matter of law.


Defendant also argued that her misconduct was not the proximate cause of plaintiff’s firing, and thus both the fraud and tortious interference claims should fail. The court rejected this argument as well. All parties agreed that defendant’s hack was the “but for” cause of plaintiff’s firing, but during Meta’s investigation of the issue, plaintiff initially misrepresented his relationship with Dordi (the account holder) and may have made other misstatements in an effort to save his job during that process. Defendant argued that plaintiff's conduct during the investigation (and his filing of the “Oops Feedback Form”) were the direct cause of his firing, not the hack itself.


The court disagreed, noting that the investigation, the filing of the form, the customer complaint, and even plaintiff's efforts to save his job were foreseeable events in the chain of causation arising from defendant’s conduct. While the court recognized the analytical and factual complexity of the causation issue, it held that it could not find lack of causation as a matter of law. Defendant’s summary judgment motion was therefore denied in full.


Lessons from an Edge Case


Bhagat is a very unusual case. The parties are atypical (ex-employees and friends, rather than a victim and unknown hacker) and the facts are highly idiosyncratic. But the opinion provides some excellent insight into issues that arise in all social engineering cases. The court’s lengthy and detailed analysis of the hack shows how complex the social engineering process can be, and the intense level of human interaction it often requires.


The “gift card” or “tech support” scams that involve attackers reaching out by phone, often to elderly individuals, to try to convince them to provide banking information or send money are another widely reported example of social engineering. These scams share a requirement of intense, one-on-one contact intended to exert psychological pressure.


Unfortunately, it is not clear that there is a good technological solution to this very human challenge. Meta’s effort to replace the humans in Instagram’s tech support loop with an AI bot was not a success. In Bhagat, one account was improperly hijacked after a lengthy and complex interaction between two humans; two years later hackers hijacked 20,000 accounts from Bhagat’s AI replacement just by asking nicely.

The current trend in AI is to rely increasingly on “agentic” AI tools: that is, tools that are able to perform tasks on their own, without human supervision. Such tools eliminate the “friction” involved in human interaction, but also the added judgment that can come from a human in the loop. That is not always desirable.


For example, the most basic form of social engineering is an email asking you to download a dangerous file or click a malicious link. Most humans have, by now, been trained to ignore those emails or send them off to IT. Will our AI agents, programmed to please, exercise the same judgment? Instagram’s experience suggests we should be ready for a lot more “Oops Feedback.”


This article first appeared in the New York Law Journal on June 22, 2026.

 
 

© 2026 Dewey Pegno & Kramarsky LLP                                                                                  

In some jurisdictions, this may be considered attorney advertising.

bottom of page