Tech

Instagram fixes AI chatbot flaw that enabled account hijacking

Navigation

Ask Onix

Instagram resolves AI support tool vulnerability

Meta announced on Tuesday that it had fixed a security flaw in Instagram's AI-powered support chatbot, which hackers exploited to gain unauthorized access to user accounts.

How the exploit worked

According to screenshots and videos circulating on social media, attackers manipulated the AI chatbot by spoofing their location using a virtual private network (VPN). They then requested the bot to update the email address linked to a targeted account, allowing them to trigger password resets.

One demonstration, shared by cybersecurity researcher Dark Web Informer on X, showed a hacker entering a username during Instagram's account recovery process. After faking the account holder's location, the attacker messaged Meta's AI assistant to link a new email and send a verification code. The bot complied, enabling the hacker to reset the password and seize control.

Scope and impact

Meta spokesperson Andy Stone confirmed the issue had been resolved and said the company was securing affected accounts. However, the total number of compromised accounts remains unclear.

Among those targeted was security researcher and former Meta employee Jane Manchun Wong. In a post on X, Wong reported unauthorized password changes and repeated reset attempts on her account, calling the incident "quite concerning."

Tech outlet 404 Media noted the exploit coincided with high-profile account takeovers, including one involving a verified Instagram account previously used by former U.S. President Barack Obama. The account briefly posted pro-Iran content before being recovered.

"This issue has been resolved and we are securing impacted accounts."

Andy Stone, Meta spokesperson

Stone later dismissed claims that the vulnerability was used to hack accounts belonging to world leaders as "totally false."

Broader concerns over AI-driven support

The incident highlights growing unease about the security risks of AI-powered customer service tools. Marijus Briedis, chief technology officer at NordVPN, warned that chatbots with excessive authority and insufficient verification pose serious threats.

"Account recovery is one of the most sensitive parts of any platform. It should never prioritize convenience over security, because the person requesting access may not be the rightful owner."

Marijus Briedis, NordVPN

Users have also criticized Meta for lacking human support options. One X user, whose account was hacked, complained about the absence of direct assistance, writing: "We're at the point where one AI stole it and another can't fix it-zero humans in the loop anywhere."

Meta's response and ongoing scrutiny

The BBC has contacted Meta to clarify whether human support workers are available for users whose accounts are compromised. The company has faced repeated criticism for its handling of hacked or wrongfully suspended accounts.

Last week, an independent EU body overseeing social media disputes reported that Meta rarely responds to cases involving users who claim they were unjustly banned. The company has also recently reduced its workforce amid significant investments in AI development.

Related posts

Report a Problem

Help us improve by reporting any issues with this response.

Problem Reported

Thank you for your feedback

Ed