All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.
First reported by bsky
Logic flaw in Meta's AI support chatbot allowed attackers to bypass 2FA and hijack Instagram accounts

Hackers hijack Instagram accounts by exploiting Meta's AI chatbot to change emails without verification

57m ago· 1 min readenNews

Summary

Hackers exploited Meta's AI customer support chatbot on Instagram to hijack high-profile accounts by tricking it into changing account email addresses without proper identity verification. The attackers then reset passwords and locked out owners. The exploit spread via Telegram channels where stolen handles were advertised. Compromised accounts included the dormant Obama White House Instagram profile (used to post unauthorized AI-generated images) and US Space Force chief master sergeant John Bentivegna's account. Meta claimed the issue was fixed, but reports indicated the exploit continued working.

Key quotes

· 3 pulled
Hackers hijacked high-profile Instagram accounts by prompting Meta's AI customer support chatbot to change the account email address without verifying the requester's identity.
Compromised accounts included the dormant Obama White House Instagram profile, used to post unauthorized AI-generated images, and US Space Force chief master sergeant John Bentivegna's account.
Meta said the issue was fixed, but additional users reported account loss and Telegram claims indicated the exploit continued working.
Snippet from the RSS feed
Hackers hijacked high-profile Instagram accounts by prompting Meta’s AI customer support chatbot to change the account email address without verifying the requester’s identity. After the email change, attackers reset the password and locked out the rightf

You might also wanna read

Hackers exploited Meta's AI chatbot to hijack Instagram accounts before patch

Meta's AI-powered support chatbot was exploited by hackers to hijack Instagram accounts by tricking it into changing the email associated wi

The Verge·2d ago

Hackers Exploit Meta's AI Support Bot to Hijack High-Profile Instagram Accounts

Hackers exploited Meta's AI customer support bot on Telegram to reset passwords and briefly deface high-profile Instagram accounts, includin

krebsonsecurity.com·2d ago

Instagram accounts compromised through AI verification bypass using animated public photos

A wave of Instagram account takeovers, including high-profile ones like the Obama White House account, exploited a flaw in Instagram's AI id

0xsid.com·1d ago

Instagram accounts compromised through AI verification bypass using animated public photos

A wave of Instagram account takeovers, including high-profile ones like the Obama White House account, exploited a flaw in Instagram's AI id

0xsid.com·1d ago

Personal Experience: AI Impersonation After Announcing Divorce on Instagram

The author shares a personal experience of announcing their divorce on Instagram, only to have their identity and content stolen by AI imper

eiratansey.com·5mo ago

Instagram Head Warns About AI's Threat to Authenticity on the Platform

Instagram head Adam Mosseri expressed concerns about AI's impact on the platform, warning that AI-generated content threatens authenticity a

The Verge·4mo ago

Meta launches encrypted 'Incognito Chat' for Meta AI with no server-side conversation logs

Meta CEO Mark Zuckerberg announced Incognito Chat for Meta AI, a new private chat mode that uses end-to-end encryption and 'Private Processi

The Verge·21d ago