Tech Souls, Connected.

Meta Says It Fixed Vulnerability Used to Hijack Instagram Accounts

Meta has begun notifying Instagram users targeted in a recent wave of account takeovers linked to its AI-powered support chatbot, as reports emerged that some attacks may have continued even after the company said it had fixed the vulnerability.

Over the weekend, hackers claimed they were exploiting Meta’s AI chatbot to gain control of Instagram accounts, including several high-profile profiles. At the same time, numerous users reported losing access to their accounts.

How the attacks worked

According to reports, attackers told Meta’s AI support chatbot that they owned a targeted Instagram account and requested that it be linked to an email address under their control.

The chatbot allegedly complied, allowing attackers to:

  • Trigger password resets
  • Gain control of accounts
  • Lock out legitimate users

No Meta employees or contractors were involved in the chats, according to the report.

High-profile accounts targeted

TechCrunch reported examples of compromised accounts with sought-after “OG handles,” including usernames based on common names and country names, which are often traded on secondary markets.

Other accounts reportedly targeted included:

  • The dormant Obama White House Instagram account, a claim Meta disputed
  • The account of U.S. Space Force Chief Master Sergeant John Bentivegna

Meta says issue has been fixed

On Monday, Meta spokesperson Andy Stone said the problem had already been resolved.

However, additional users reported account takeovers on Tuesday.

TechCrunch said discussions in a Telegram channel used by people sharing the technique indicated that some members claimed they could still exploit the chatbot. The channel also reportedly featured listings for allegedly compromised usernames.

Stone later said on X that some users might receive:

  • Password reset notifications
  • Security questions when attempting to log in

Meta secures affected accounts

According to Stone, Meta secured affected accounts on Monday and began sending password reset emails to impacted users.

The company did not disclose how many users were affected.

Some victims shared emails from Instagram stating that the company had:

  • Detected suspicious activity
  • Taken steps to secure the account
  • Asked users to reset their passwords

AI support system introduced earlier this year

Meta announced in March that it was expanding AI-powered customer support.

The company said the chatbot was designed to resolve account issues from start to finish and had the ability to securely reset passwords.

The incident has drawn attention because account takeovers involving valuable Instagram usernames traditionally relied on more complex tactics, including:

  • Phishing attacks
  • SIM-swapping schemes
  • Bribing telecom insiders

In this case, attackers allegedly obtained access through interactions with the chatbot itself.

TL;DR

Meta has started warning Instagram users targeted in a hacking campaign that exploited its AI support chatbot. The company says it fixed the issue and secured affected accounts, though reports of additional account compromises surfaced after the announced patch.

AI summary

  • Meta has begun notifying Instagram users affected by chatbot-related attacks.
  • Attackers allegedly convinced Meta’s AI chatbot to reset passwords.
  • Victims included accounts with valuable “OG” usernames.
  • Meta says it fixed the vulnerability and secured affected accounts.
  • The company has not disclosed how many users were impacted.
Share this article
Shareable URL
Prev Post

Amazon Expands AI Push With Visual Search Suggestions

Next Post

Bezos-Backed Slate Auto Grants Carvana Share Purchase Warrant

Read next