Chatbot hackers tricked into hijacking 20,000 Instagram accounts


Just over a week ago, Meta’s AI-powered chat assistant unwittingly gave hackers access to thousands of Instagram accounts, including high-profile ones like cosmetics retailer Sephora and Instagram accounts. The highest ranking non-commissioned officer in the US Space Forcebesides White House Account of Barack Obama.

The exact number was later revealed in A Regulatory filing With the Maine Attorney General’s Office. The total is 20,225 compromised accounts (30 of whom are Maine residents).

penetration, Quoted by 404 Media Last week, it was easier to enforce against account holders who did not enable two-factor authentication. The hackers simply asked the AI ​​bot to change the target account’s email address to their own. Once approved, the hackers requested a password reset, prompting the AI ​​to send a code to their personal email address. After the hackers verified the password reset, they were able to take control of the account.

Edited step by step Video of the process He even appeared on X, showing how hackers do it You use a VPN It seemed like they were on target. At no time did the hackers need the user’s email address or original password.

in Accident notification letter To Maine Attorney General Aaron Frey on June 5, Meta admitted that there was a “vulnerability in Instagram’s AI-assisted account recovery system…which was exploited by unauthorized third parties to perform password resets on Instagram users’ accounts.”

After the exploit was announced, many Instagram users reported the matter Reddit and X Their accounts had been compromised, although the scope of the breach was not clear at the time. Meta spokesman Published on X The exploit was fixed as of June 1, shortly after initial reports.

How did AI allow the hack to happen?

The problem is almost entirely due to Meta customer support which is now run by AI. Tech giant Make the switch Back in March, saying it would enable “24/7 help for account issues like updating your password and settings for your profile.”

CNET AI Atlas badge; Click to see more

But with an AI chatbot handling the entire process, humans were unable to intervene when suspicious activity started. This allowed hackers to carry out a social engineering style attack and perform it multiple times before anyone noticed.

All users have been force logged out of affected accounts and email addresses have been restored. Users were then asked to reset their passwords and re-authenticate their logins. Meta says that once accounts are secured, a second notification will be sent reminding people to turn on two-factor authentication to prevent future attacks.

Meta has not yet responded to a request for comment.

How to protect yourself from similar attacks

The social engineering exploit had one major limitation: it did not work on accounts with multi-factor authentication. These accounts either already have the code in the authenticator app of choice or received it via text message. Without MFA set up, the one-time reset code appears to be sent to an email address of your choice, allowing hackers to obtain it.

The best way to protect yourself is to enable multi-factor authentication, available on all Meta platforms. He – she It won’t protect you 100% of the timebut it is much better than the password itself, and would have been completely protected against this particular exploit.

There are other things you can do Enhance account securityincluding the use of passkeys where available and a private email address to make finding your account credentials more difficult.



Leave a Reply

Your email address will not be published. Required fields are marked *