Meta AI chatbot exploit hijacks Instagram accounts
Hackers hijacked thousands of Instagram accounts by exploiting a security vulnerability in Meta's automated AI support chatbot to request unauthorized email changes and password resets. Meta has since patched the vulnerability and started restoring access to the affected accounts.
Replacing human support with conversational AI agents for critical account recovery operations is a massive security risk that invites prompt injection and automated social engineering against LLMs.
* AI support agents should never have permission to perform destructive actions or modify account-level security credentials without robust out-of-band verification.
* Simple geolocation matching using VPNs proved to be a single point of failure in Meta's verification checks, highlighting the fragility of location-based heuristics.
* The rush to reduce support costs via AI automation has created a new class of automated social engineering attack surfaces.
DISCOVERED
2h ago
2026-06-06
PUBLISHED
3h ago
2026-06-06
RELEVANCE
AUTHOR
speckx