Hackers Exploit Meta AI Support Chatbot to Take Over High-Profile Instagram Accounts
By
Jason Koebler
Hand-rolled, kettle-boiled, baked to perfection. Worth every minute at the bakery.
Summary
Hackers exploited Meta's AI support chatbot to take over high-profile Instagram accounts, including the Obama White House account and Sephora's account, by simply asking the bot to change the email address associated with the target accounts. The exploit highlights the significant security risks of delegating customer support and critical account management functions to AI chatbots without proper safeguards.
Key quotes
· 3 pulledHackers say that they used Meta's AI support chatbot to break into a host of high-profile Instagram profiles by asking the support bot to change the email address associated with the target account.
The claims coincide with a series of high-profile Instagram account takeovers, including the Barack Obama White House account, the Chief Master Sergeant of Space Force's account, and Sephora's account.
The news shows the extreme risk associated with offloading support or critical functions to an AI chatbot.
You might also wanna read
Cisco Researchers Find Multi-Turn Conversations Can Bypass LLM Safety Guardrails
Researchers at Cisco have discovered that safety guardrails in major large language models (LLMs) — including ChatGPT, Claude, Gemini, Amazo

Researchers bypass Claude's safety guardrails using flattery and psychological manipulation
Researchers at AI red-teaming company Mindgard discovered they could bypass Anthropic's safety measures on Claude by using psychological man

Anthropic's Claude Mythos AI model accessed by unauthorized users despite security claims
Anthropic's tightly controlled rollout of its Claude Mythos AI model, touted as too dangerous for public release due to its advanced cyberse

Anthropic's Mythos cybersecurity AI model accessed by unauthorized users via third-party contractor
Anthropic's powerful Mythos cybersecurity AI model, described as potentially dangerous in the wrong hands, was accessed by unauthorized user
Why Faster Vulnerability Alerts Are Critical: Attackers Exploit Flaws Within 24 Hours of Disclosure
Attackers can exploit newly disclosed vulnerabilities within 24 hours, often before organizations receive alerts. The article argues that tr
hendryadrian.com·4h agoUnrestricted open-weight AI models raise safety concerns as they become more accessible
The article discusses the growing accessibility of open-weight AI models that lack safety guardrails, allowing users to generate harmful con
