Neowin
Meta AI Exploit Allows Account Takeovers on Instagram
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A security flaw in Meta's AI support chatbot has led to the hijacking of several high-profile Instagram accounts, including those of Barack Obama's White House and the U.S. Space Force Chief Master Sergeant. Hackers utilized a VPN to spoof their location and prompted the AI to send password reset codes to their own email addresses, bypassing traditional security measures. This exploit reportedly allowed unauthorized access even for accounts with two-factor authentication enabled. The incident highlights significant vulnerabilities in Meta's AI systems, which were active for months before being patched. Users are advised to enable two-factor authentication to enhance account security. Meta has stated that the issue has been resolved and affected accounts secured.
Key Points: • Meta's AI chatbot was exploited to hijack Instagram accounts without proper verification. • High-profile accounts, including the Obama White House, were compromised using this method. • The exploit was active for months, affecting potentially thousands of users before being patched.