Connect with us

Security

Meta’s AI Chatbot: A Gateway for Hackers to Hijack Instagram Accounts

Published

on

Hackers likely hijacked over 20,000 Instagram accounts with Meta’s AI chatbot

Instagram Security Breach: Meta Resolves Password Reset Vulnerability

A recent security incident on Instagram revealed a vulnerability in the password reset system. Although the tool itself functioned correctly, a bug in a separate code path allowed unauthorized individuals to receive password reset links for accounts they did not own. This flaw occurred when the system failed to verify that the email address provided for the reset matched the one associated with the Instagram account.

Meta, the parent company of Instagram, confirmed that the incident was first detected on May 31st and promptly resolved on June 1st. Several prominent Instagram accounts, including those of former President Barack Obama and Sephora, were affected by the breach. Meta stated that while it is uncertain if any personal data was accessed, the attackers could potentially have obtained sensitive information such as email addresses, phone numbers, and social media posts.

According to Meta, approximately 30 users in Maine were impacted by the breach. These users had their passwords reset through the compromised support tool and did not have two-factor authentication (2FA) enabled on their accounts. Meta has taken steps to enhance security measures, including disabling the AI support tool and implementing mandatory authentication checkpoints for all potentially affected accounts.

See also  Massive Data Breach: DentaQuest Exposes 2.6 Million Accounts

Trending