Meta launched Muse Image, an AI image-generation feature linked to public Instagram accounts that lets users create synthetic images of a person by entering that person’s Instagram handle. Reporting says the setting is enabled by default for public profiles, affected users are not notified when their likeness is used, and opting out only stops future use rather than removing images already generated and shared.
Privacy and security researchers warned the feature lowers the barrier to deepfakes, impersonation, phishing, identity fraud, and scam activity by turning public profile photos into ready-made source material for abuse. The criticism builds on broader concerns about Meta’s AI and identity controls, including prior scrutiny of its opt-out approach to AI data use in Europe and references to an earlier alleged flaw in a Meta AI support chatbot that could permit account changes without strong identity verification.

Get the infrastructure and lures behind it.
2 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-09, Malwarebytes published a warning urging users to turn off a Meta setting before someone could generate AI images of them. The article reflects public reporting and concern around the privacy implications of Meta's feature.
On 2026-07-07, Meta launched Muse Image, an AI image-generation feature that can generate synthetic images of a person by referencing their public Instagram handle. The feature was reported as enabled by default for public accounts and did not notify affected users when their likeness was used.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcemalwarebytes.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.