HeadlinesBriefing favicon HeadlinesBriefing.com

Meta AI Support Bot Flaw Enabled Instagram Account Hijacks

MacRumors •
×

A security flaw in the Meta AI support assistant allowed hackers to hijack high-profile Instagram accounts. The bot changed account email addresses without proper verification, letting bad actors reset passwords. This vulnerability bypassed two-factor authentication by relying on simple location checks that hackers fooled using VPNs.

Attackers targeted desirable handles and high-profile users, including the archived Barack Obama White House account and Sephora. Some hackers even used AI to bypass selfie identity checks. Reports indicate that black market services on Telegram capitalized on this exploit, which some sources say was known since March.

VP of communications Andy Stone confirmed the issue is now patched. While the company is securing impacted accounts, some victims found the AI unable to help them recover their profiles. These users had no way to reach a human agent for assistance during the crisis. The fix closes the email change exploit.