Apps & Consumer
Meta fixes Instagram flaw that allowed account hijacking
Meta has resolved a security flaw that appeared to allow attackers to hijack Instagram accounts by tricking the company's AI-powered support chatbot into granting unauthorized access.
Instagram has resolved a security issue that allowed several users’ accounts to get hijacked. The attack appeared to rely on tricking Meta’s own AI-powered support chatbot into granting access to a victim’s account. Over the weekend, several users on Reddit claimed that their Instagram accounts had been compromised, and a number of users on X warned of similar account hijackings. On Monday, Instagram spokesperson Andy Stone confirmed that the issue was fixed.
The exploit involved using a Virtual Private Network (VPN) to spoof the targets’ presumed location, which allegedly allowed the attacker to avoid triggering Instagram’s automated account protections. The step-by-step process was shown in a video posted on X. In the video, the attacker opened a chat with the Meta AI Support Assistant chatbot and asked the bot to add a new email address to the target’s account. The chatbot then sent a verification code to the email address provided by the hacker. TechCrunch was able to verify that the hacker’s public email mailbox, which was displayed in the video, effectively received the verification code. After the hacker shared the verification code back with the chatbot, the bot prompted them with a button to reset the password, allowing the attacker to enter a new password and take over the victim’s account. Crucially, the attack relied on the fact that at no point did the hacker have to take over the legitimate email address linked to the victims’ Instagram account.
Security researcher Jane Wong and U.S. Space Force chief master sergeant John Bentivegna were among those whose accounts were compromised. Wong, who described the experience as quite concerning, stated, “The password got changed without my knowledge and I was getting different password reset attempts throughout yesterday.” While the security issue has been resolved, it remains unclear how many Instagram users had their accounts improperly accessed. The compromised accounts included high-profile handles, such as the Obama-era White House account, which appears to have been inactive since 2017.
Why it matters
This incident highlights a critical vulnerability where AI-driven customer support tools can be manipulated to bypass standard security protocols, effectively allowing account takeovers without requiring access to a user’s primary email.