Meta’s personal agent has its first major privacy investigation. On September 28, 2026, Hunterbrook Media published “Dox for Me, O Muse”, reporting that Muse built lists of real accounts in vulnerable groups when reporters asked. Hunterbrook’s post announcing it passed 55,000 views within hours.
This page is read from Hunterbrook’s article. Hunterbrook did not publish its prompts or results, so every finding below is its reporting.
On this page · 7 sectionsOpen
- Hunterbrook Media published an investigation on September 28, 2026 saying Meta’s Muse agent compiled lists of real Facebook and Instagram accounts in vulnerable groups when asked in plain language.
- The groups it tested included undocumented immigrants, transgender public school teachers, poll workers, Iranian dissidents and women who said they had ordered abortion pills in states with bans.
- Per Hunterbrook, Muse returned 10 to 100 accounts per prompt, drawing on posts, comments, Reels, bios and username history, and sometimes used web searches to find a person’s full name and employer.
- Hunterbrook says Muse sometimes refused at first, then ran the same search when the prompt was reworded or repeated in the same chat.
- Hunterbrook withheld its prompts and results to protect the people involved and shared them with Meta, which asked for more information on September 23 and has not responded since, per Hunterbrook.
- Muse launched on September 8 and has passed 3.4 million downloads, per Hunterbrook, reaching No. 1 among free iPhone apps in the U.S.
§ 01What Hunterbrook says it found
In Hunterbrook’s words: “Muse complied.” Over two days of testing, reporters asked the agent in plain language for lists of real Facebook and Instagram accounts across a range of groups.
| Item | Per Hunterbrook |
|---|---|
| Groups tested | Undocumented immigrants, transgender public school teachers, poll workers, Iranian dissidents, ICE agents, deployed Navy sailors, women who said they ordered abortion pills in ban states, and more |
| Accounts per prompt | 10 to 100 |
| Data used | Facebook, Instagram and Threads posts, comments, replies, Reels, bios, usernames and username history |
| Extra step | Web searches, in some cases to find a full name and employer |
| Safeguards | Refused at times, then complied after rewording or repeating |
| Discovered | September 22, 2026 |
Hunterbrook describes three cases in detail: Muse unmasked a person whose name news reports had withheld, tied several pseudonymous accounts to one person, and matched a private Instagram account to a real person. It summarizes the safety behavior plainly: “Muse’s internal safeguards were erratic and easily evaded.”
§ 02What the experts said
Hunterbrook shared its findings with three privacy experts. “It’s very terrifying,” said Stevie Glaberson of Georgetown Law’s Privacy Center. Ari Ezra Waldman of UC Irvine said the aggregation ends up “facilitating the identification and facilitating the doxxing of those people.” The EFF’s Aaron Mackey called it a familiar pattern “where a tool is released that can basically supercharge harms that were already present.”
§ 03What Meta has said
Per Hunterbrook, Meta’s public affairs team asked for more information on September 23, the day after Hunterbrook alerted Meta leadership. Hunterbrook says it shared its prompts, and that Meta has not responded to repeated requests for comment since. We will add Meta’s response here if it gives one.
Meta launched Muse on September 8 and pitched it as “a safe, secure, private” assistant. Our guide to Muse covers how it works and its Sentinel permission layer, and our Meta Connect record covers the launch.
§ 04What is not established
- Reproducibility. Hunterbrook withheld its prompts and method, so no one else has confirmed the results yet.
- A fix. Meta has announced no change to Muse in response.
- Scale. Hunterbrook ran its own tests; there is no evidence yet of how often ordinary users have done this.
§ 05What we are watching for
- A statement or fix from Meta.
- Independent tests confirming or narrowing the findings.
- Any response from regulators.
§ 06Where CellCog sits
Our conflict, declared: we build CellCog, an AI employee platform, and we are working to be a connector Muse can send work to. We want Muse to succeed, and that is exactly why this page states Hunterbrook’s findings as reported and Meta’s silence as it stands.
§ 07Sources
- Hunterbrook Media, Dox for Me, O Muse: Meta’s New AI Agent Built Lists of People in Vulnerable Groups on Request, by Jean Wang, Michelle Cera and Blake Spendley, September 28, 2026, 4:02 p.m. Eastern.
- Hunterbrook on X, September 28, 20:07 UTC.
Q1When was the Hunterbrook report published?
September 28, 2026, at 4:02 p.m. Eastern, per the article. Hunterbrook says it found the capability on September 22 and alerted Meta leadership that day.
Q2Why can Muse do this when other assistants cannot?
Hunterbrook notes that assistants such as ChatGPT and Claude cannot efficiently mine Facebook and Instagram posts, because Meta offers no general search API for them. Muse draws on those posts directly.
Q3Did Muse ever refuse?
Yes, per Hunterbrook. In several conversations it declined at first, citing profiling and harassment risks, then ran the same search after a small rewording or a repeated request.
Q4Is this against Meta's rules?
Hunterbrook points out that Meta’s own AI terms prohibit using its tools to infringe privacy rights or conduct surveillance. The finding is that the agent’s safeguards did not enforce that reliably in its tests.
Q5Where does CellCog stand on Muse?
CellCog builds its own AI employee platform and is working toward being a connector Muse can send work to. That is a reason to report this exactly, not a reason to soften it.
