Overview
- Meta confirmed on Tuesday that a vulnerability in its Instagram support chatbot let attackers take over accounts and that the company has patched the flaw.
- Investigators reported the attackers used a simple conversational prompt to the AI to add an attacker-controlled email and then accepted a verification code to reset the password.
- The technique combined VPN-based location spoofing with the chat-based 'forgot password' flow so attackers did not need to control victims’ original email accounts.
- Reports say high-profile and inactive handles were among those taken and researchers warn the flaw may have been active since February, but Meta has not disclosed how many accounts were affected.
- Security experts say the incident shows automated support can be vulnerable to social-engineering at scale and that platforms should add stronger authentication, logging, and human oversight for recovery flows.