Connect with us

Security

Meta’s AI Breached: Instagram Accounts Hijacked

Published

on

Meta’s own AI was exploited to hijack Instagram accounts

Meta’s AI Support Chatbot Enables Instagram Account Hijacking

Recent reports have surfaced detailing how Meta’s AI support chatbot was exploited by hackers to gain unauthorized access to Instagram accounts. According to 404 Media, a hacker demonstrated in a video shared on Telegram how they were able to manipulate the chatbot to switch the email associated with a targeted profile and subsequently reset the password.

AI Assistant Vulnerabilities Exposed

Meta introduced its AI-powered support assistant in March to assist users with tasks such as password resets, two-factor authentication setup, and account recovery. However, the Telegram video showcased how a hacker could easily trick the chatbot into sending a verification code to their email address, allowing them to seize control of the account by setting a new password, effectively locking out the legitimate owner.

Exploiting VPNs for Location Spoofing

Some hackers, including those featured in the embedded video, utilized virtual private networks (VPNs) to mask their true location when contacting Meta support. By spoofing their location to appear in close proximity to their target, the attackers focused on high-value usernames, particularly those consisting of single letters or words such as “h” or “eggs.”

Security Expert Falls Victim

Even security researcher Jane Manchun Wong fell victim to the account hijacking scheme, experiencing unauthorized password changes and multiple reset attempts. Wong reported being frequently logged out of the Instagram iOS app, indicating the extent of the breach.

Concerns Over Instagram’s Security Measures

Gergely Orosz, the mind behind The Pragmatic Engineer newsletter, raised concerns about Instagram’s trust and safety team being understaffed and reassigned to non-security-related tasks like AI labeling. Orosz highlighted the lack of emphasis on security within Instagram’s engineering practices, attributing the breach to an overreliance on AI solutions without adequate safeguards in place.

See also  Security Vulnerability in WP Maps Pro Allows Creation of Unauthorized Admin Accounts on WordPress Sites

Trending