Hackers exploited a vulnerability in Meta’s AI support chatbot to hijack Instagram accounts by tricking the automated system into resetting passwords and bypassing standard security verification protocols.
Key Points
- Attackers used VPNs to spoof target locations and avoid triggering Instagram’s automated security protections.
- The exploit involved convincing the Meta AI Support Assistant to add a hacker-controlled email address to a victim's account.
- By sharing verification codes with the chatbot, hackers gained the ability to reset passwords and seize full account control.
- Instagram spokesperson Andy Stone confirmed on Monday that the specific vulnerability has been patched.
- Security experts warn that LLM-based chatbots remain susceptible to various evolving manipulation tactics that are difficult to block entirely.