Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts
Hackers exploited Meta’s AI support bot on Instagram to gain unauthorized access to accounts, including those belonging to the Obama White House and the U.S. Space Force. The tactic involved tricking the bot into resetting passwords by adding new email addresses to existing accounts. This incident highlights a new vulnerability arising from the increasing use of AI in customer support systems.
The attack began with the dissemination of instructions on Telegram detailing how to leverage Meta’s AI support assistant to reset Instagram account passwords. A video showcased the process, demonstrating how a VPN connection and a targeted request to the bot could be used to link an account to a new email address, subsequently receiving a password reset code. This method exploited a flaw in Meta’s automated recovery workflow, specifically the bot’s willingness to add email addresses to accounts. The resulting defacement of high-value Instagram accounts, reportedly worth over half a million dollars, underscores the potential impact of such vulnerabilities.
Meta responded by deploying an emergency patch and confirming no database breach occurred. However, the incident revealed a critical weakness in Instagram’s customer support infrastructure and raised concerns about the security of AI-powered assistance tools. Threat researchers like Ian Goldin emphasized the emerging attack surface created by these chatbots, predicting a rise in similar exploits. The incident also highlighted the importance of robust multi-factor authentication (MFA) to mitigate such risks.
