news.mlab.sh
Back to the feed
data-breach

Over 20,000 Instagram accounts stolen in Meta AI support hack

High
Summary

Over 20,000 Instagram accounts were compromised due to a vulnerability in Meta’s AI-powered support system, High Touch Support (HTS). Attackers exploited the system to reset passwords, gaining unauthorized access to user accounts despite the lack of two-factor authentication. Meta has since disabled the HTS system and implemented security measures to prevent further attacks and secure affected accounts.

A recent security incident involving Meta’s High Touch Support (HTS) AI-powered support system resulted in the hijacking of over 20,000 Instagram accounts. Attackers leveraged a flaw in HTS, which was used to reset passwords for users locked out of their accounts. The vulnerability stemmed from HTS’s failure to verify email addresses associated with Instagram accounts, allowing attackers to obtain password reset links and gain control. This incident highlights the risks associated with relying on AI-powered support systems without robust authentication mechanisms.

Meta has taken immediate action to contain the breach, including disabling the HTS system and enrolling affected accounts into a mandatory security checkpoint. Users were instructed to reset their passwords and re-authenticate to regain control of their accounts. Furthermore, Meta is conducting a comprehensive review of similar account recovery flows across its platforms to identify and remediate any potential vulnerabilities. This event follows previous fines levied against Meta for data breaches and security lapses, including a $264 million fine in 2018 and a $275.5 million fine in 2022.

The compromised accounts potentially exposed a range of user data, including contact information, social media content, direct messages, and account activity. The incident underscores the importance of continuous security assessments and proactive vulnerability management within large tech platforms.

Read the full article at BleepingComputer