A security flaw in Meta’s automated AI support system allowed hackers to compromise over 34,000 Instagram accounts by manipulating password recovery workflows to gain unauthorized access to user profiles.
Key Points
- Hackers exploited an AI chatbot to change account recovery emails, enabling them to reset passwords and hijack approximately 20,000 Instagram profiles.
- The breach exposed sensitive personal data, including phone numbers, email addresses, and birth dates, for thousands of affected users.
- High-profile accounts, including those belonging to businesses and government-linked organizations, were among the profiles compromised during the incident.
- Meta has paused the specific automated recovery tool involved in the breach while continuing its broader integration of AI-powered customer support systems.
- The company is currently conducting a comprehensive security review and notifying affected users and regulators about the unauthorized access.