Particle.news

Meta Fixes AI Support Bug After Attackers Used Chatbot to Hijack Instagram Accounts

Meta's AI linked attacker-controlled emails to accounts, sent verification codes to those addresses, enabling account takeovers.

Overview

  • Security researchers and videos published by 404 Media showed attackers used Meta's AI support chatbot to add an attacker-controlled email to a target account and obtain a verification code that let them reset the password and take control of the account.
  • The exploit circulated in Telegram groups where step‑by‑step guides and lists of stolen or vulnerable usernames were shared and some compromised profiles were offered for sale.
  • High-profile targets reported in multiple outlets included the archived Obama White House Instagram, a senior U.S. Space Force account, and the Sephora profile, and researchers say the method may have been used since February or March.
  • Meta confirmed on Tuesday that it has fixed the vulnerability and said it is securing affected accounts but has not disclosed how many users were compromised.
  • Security experts say stronger identity checks and two‑factor authentication would have reduced risk, and the incident highlights the danger of giving automated support systems broad powers without layered human checks.