news.mlab.sh
Back to the feed
threat-intel

Meta Says 20,000 Instagram Accounts Hacked via AI Tool Abuse

High
Summary

Meta has reported that approximately 20,000 Instagram accounts were compromised due to abuse of its AI-powered account recovery tool, High Touch Support (HTS). Hackers exploited a vulnerability in the tool to reset passwords by providing unrelated email addresses, gaining control of numerous accounts, including those of prominent organizations. Meta is taking steps to mitigate the damage, including disabling the tool and notifying affected users.

The attack leveraged a bug within Meta’s HTS tool, allowing unauthorized individuals to request password resets via email addresses not linked to the targeted Instagram accounts. This vulnerability stemmed from a failure to properly verify the provided email addresses against the user’s existing Instagram account information. Once a password reset link was sent to the incorrect email, attackers could then gain access to the compromised account if two-factor authentication (2FA) was not enabled. This highlights a critical security flaw in a widely used support tool.

Meta has taken immediate action to address the issue, including disabling the abused HTS tool and invalidating the compromised password reset links. Affected accounts have been enrolled in a mandatory security checkpoint and their passwords have been reset. While Meta is investigating whether personal information was accessed, the potential data exposed includes profile information, email addresses, phone numbers, dates of birth, direct messages, social media posts, and account activity history. The company plans to notify affected users and recommend enhanced security measures, such as enabling two-factor authentication.

Read the full article at SecurityWeek