All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.
First reported by bsky
Logic flaw in Meta's AI support chatbot allowed attackers to bypass 2FA and hijack Instagram accounts

Meta confirms thousands of Instagram accounts hijacked via AI chatbot password reset exploit

By

Zack Whittaker

3h ago· 4 min readenNews

Summary

Meta has confirmed that thousands of Instagram accounts were hijacked over several months through abuse of its AI chatbot. Hackers tricked the Meta AI chatbot into resetting passwords on accounts lacking two-factor authentication. The company has begun notifying affected users via data breach notification letters. The bug has since been fixed by Meta.

Key quotes

· 3 pulled
Meta is notifying thousands of people whose Instagram accounts were hijacked during the months-long abuse of the company's AI chatbot, which hackers repeatedly tricked into taking control of a person's account.
In a new data breach notification letter, seen by this week in security, Meta has revealed for the first time how many people had their accounts hijacked as part of the long-running hacking campaign.
Meta fixed the bug that let anyone trick its Meta AI chatbot into resetting the password on Instagram accounts that didn't have two-factor authentication.
Snippet from the RSS feed
Meta fixed the bug that let anyone trick its Meta AI chatbot into resetting the password on Instagram accounts that didn't have two-factor authentication.

You might also wanna read