Meta fixes AI customer service vulnerability after Instagram account was compromised.
TechCrunch
06-02 02:44
Ai Focus
Meta has patched a security vulnerability on Instagram that allowed attackers to reset passwords and take over some accounts using an AI-powered chatbot.
Helpful
No.Help

Instagram has fixed an account security issue. According to TechCrunch, attackers could manipulate Meta's AI chatbot to add new email addresses to other people's accounts, trigger password resets, and ultimately take over the accounts.

Multiple users reported that their accounts were hacked.

The incident garnered attention over the weekend. Multiple users on Reddit and X reported their accounts were compromised, including the Obama administration's White House Instagram account and the account of U.S. Space Force Chief of Staff John Bentinvegna. Security researcher Jane Wong also stated that her account's password was changed and it was taken over without her knowledge.

Attack process bypasses original email control

The report indicates that the attackers first used a VPN to disguise the target's location to reduce the probability of triggering the platform's automatic risk control measures. Subsequently, the attackers initiated a conversation with the Meta AI Support Assistant, requesting that a new email address be added to the target account.

In the demonstration video, the customer service chatbot sends a verification code to an email address provided by the attacker. The attacker then returns the verification code to the chatbot, and a "Reset Password" button appears. After this step, the attacker can set a new password and gain control of the account.

TechCrunch stated that they verified the email address publicly shown in the video and confirmed that the email address did indeed receive the verification code. Throughout the process, the attacker did not need to first gain control of the victim's originally linked email address.

Meta says the vulnerability has been fixed.

Instagram spokesperson Andy Stone stated on Monday in response to a related post on social media that the issue has been fixed. However, Meta has not yet specified how many users were affected.

Based on the disclosed information, this incident exposes the vulnerability of AI-powered customer service tools to account takeover if the identity verification process is inadequate, once they gain the authority to modify critical account information. Meta did not immediately respond to TechCrunch's request for further comment at the time of publication.

Tip
$0
Like
0
Save
0
Views 430
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Meta's oversight committee criticized the lack of transparency in the account banning process.
Meta's oversight committee stated that the platform's account suspension process lacks transparency and due process, and recommended clarifying the basis for violations, appeal channels, and the role of AI review.
TechCrunch
·2026-06-05 01:08:14
361
Zcash resumed operation after fixing the Orchard vulnerability, and ZEC rose by more than 10%.
Zcash completed the Orchard vulnerability fix and restored network functionality, and ZEC subsequently rose by more than 10%.
Coinpaper
·2026-06-04 02:37:06
112
Meta takes WhatsApp business AI agent to the world
Meta is expanding its AI agent for WhatsApp Business globally and plans to charge businesses for it.
TechCrunch
·2026-06-03 21:46:26
660
Companies like Meta are increasing their use of AI to track employees.
Companies like Meta, JPMorgan Chase, and KPMG are increasing their efforts to track employee AI usage, practices that have sparked controversy over costs, performance, and privacy.
Business Insider
·2026-06-04 00:07:08
562
Reports indicate that Meta is developing an AI-powered pendant device.
Reports indicate that Meta is developing an AI pendant, with plans to test it next year, and is also expanding its AI glasses and enterprise subscription business.
TechCrunch
·2026-05-31 00:23:09
374