Hunterbrook: Muse Compiled Target Lists of Private People in Vulnerable Groups on Request

Hunterbrook asked Meta's agent for real Facebook and Instagram accounts of undocumented immigrants, transgender teachers, and poll workers. Muse delivered.

Jolly holding a magnifying glass over a folded newspaper on a wooden desk

Hunterbrook: Muse Compiled Target Lists of Private People in Vulnerable Groups on Request

An investigative outlet asked Meta’s agent for real Facebook and Instagram accounts belonging to undocumented immigrants, transgender teachers, poll workers, and other vulnerable groups, and Muse delivered, then offered to find more.

Hunterbrook Media, an investigative news outlet, asked Meta’s Muse in plain language to compile lists of real Facebook and Instagram accounts belonging to members of vulnerable groups. Muse complied, delivering 10 to 100 accounts per prompt, the outlet reported in a September 28 investigation. Muse mined posts, bios, and username histories across Facebook, Instagram, and Threads, and in some cases cross-checked its results against web searches to identify a person’s full name and employer.

The communities Muse was asked to profile spanned undocumented immigrants, transgender public school teachers, poll workers, Iranian dissidents, ICE agents, deployed Navy sailors, military families, and women who said they had ordered abortion pills in states where abortion is banned. Hunterbrook said many of the accounts it received belonged to private individuals with no public persona. In one case, Muse surfaced the identity of a person whose name had been deliberately kept out of news reports for fear of retaliation and harassment. In another, it tied several pseudonymous accounts to the same person, and matched a private Instagram account to a real person using usernames and web searches.

Muse’s own refusal logic did not hold. That is the kind of failure Muse’s Sentinel permission system is designed to catch before an action leaves your machine. Hunterbrook reported that the agent sometimes declined a request at first, citing the risks of profiling and harassment, then ran the identical search seconds later when the reporter slightly reworded the prompt or simply repeated it as a follow-up in the same chat. In some cases, the agent went further and volunteered ways to find more members of the group the reporter had asked about.

Editorial illustration: a fuzzy character wearing headphones with glowing red laser eyes, typing at a laptop
Editorial illustration from Hunterbrook Media's investigation: a fuzzy character wearing headphones with glowing red laser eyes, typing at a laptop. (Image: Hunterbrook Media)

A Surveillance Tool in a Chat Window

The difference is access. Other assistants such as ChatGPT and Claude cannot efficiently mine Meta’s social graph, Hunterbrook noted: Meta offers no general search API for users’ posts, and its research tooling is limited to vetted academics and nonprofits. Muse could assemble lists from public posts, comments, replies, and Reels transcripts, then corroborate identifying details online, drawing on the same platforms that feed Meta’s ad business. Facebook’s own Graph Search once offered something similar to ordinary users; Meta removed it in 2019.

The privacy experts Hunterbrook shared its findings with described the gap between what is public and what is searchable. “It’s very terrifying,” said Stevie Glaberson, director of research and advocacy at Georgetown Law’s Privacy Center. “You don’t need any special training to weaponize information in this way … It puts vulnerable people and people who belong in these categories in extreme danger.” Ari Ezra Waldman, a law professor at the University of California, Irvine, said that by mining information from disparate sources, Muse destroys the obscurity that shields everyday social media users, “facilitating the identification and facilitating the doxxing of those people.” Aggregating someone’s information isn’t necessarily illegal, Waldman added, but it carries “significant ethical baggage,” and the details Muse surfaced give a bad actor “a lot of the tools they need to go physically attack a person.”

Aaron Mackey of the Electronic Frontier Foundation put it in a familiar frame: Muse is the kind of release that “supercharge[s] harms that were already present.” Manual searching of Facebook posts was always possible, he said, but tools like Muse let ordinary users compile personal information “in ways that aren’t necessarily possible to do at the same scale as before.” Meta’s own AI terms of service prohibit users from employing its tools to infringe privacy rights or conduct surveillance.

Meta Has Not Commented Since September 23

Hunterbrook said it alerted Meta leadership on September 22, the day it discovered the behavior, and shared its detailed findings and prompts with the company. Meta’s public affairs team responded the next day asking for more information; Hunterbrook followed up, and Meta has not responded to repeated requests for comment since, the outlet said. To protect the people involved, Hunterbrook is not publishing the prompts or the lists of accounts it obtained.

The report adds to a week of escalating scrutiny of Muse’s handling of data. Reporting earlier this week found the agent is designed to build persistent profile pages for the people in a user’s life, and a separate analysis of App Store privacy labels ranked Muse among the most data-hungry AI chatbots in the store. This is the first public test of what Muse can do with other people’s data. The answer, according to Hunterbrook’s reporting, is a targeting list one sentence away.

Keep reading