Particle.news
Download on the App Store

Meta Confirms Instagram Support AI Was Abused to Steal Accounts

The company says it patched the flaw, signaling risks in letting automated assistants handle sensitive account-recovery actions.

Overview

  • Meta confirmed on Tuesday that a vulnerability in its Instagram support chatbot let attackers take over accounts and that the company has patched the flaw.
  • Investigators reported the attackers used a simple conversational prompt to the AI to add an attacker-controlled email and then accepted a verification code to reset the password.
  • The technique combined VPN-based location spoofing with the chat-based 'forgot password' flow so attackers did not need to control victims’ original email accounts.
  • Reports say high-profile and inactive handles were among those taken and researchers warn the flaw may have been active since February, but Meta has not disclosed how many accounts were affected.
  • Security experts say the incident shows automated support can be vulnerable to social-engineering at scale and that platforms should add stronger authentication, logging, and human oversight for recovery flows.