Hackers Exploit Meta AI Support Flaw to Steal Instagram Accounts
Meta introduced an AI customer-support assistant to help Instagram users recover their accounts, but hackers were able to combine prompt injection with a VPN to bypass identity checks and reset passwords. The incident shows that enterprise AI systems with account-management privileges can become a new avenue for taking over high-value accounts if they lack rigorous verification controls.
Meta recently confirmed that the vulnerability was exploited for about 1.5 months, resulting in the theft of more than 20,000 Instagram accounts. None of the victims had enabled two-factor authentication, or 2FA. Meta has not disclosed the exact dates when the vulnerability was active, the identities of the affected accounts or the amount of losses, and urged users to enable two-factor authentication immediately to reduce their risk.
All Coverage
7 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.