Hackers took control of Instagram accounts by requesting password resets from Meta's AI chatbot.

Hackers took control of Instagram accounts by requesting password resets from Meta's AI chatbot.

      TL;DR Hackers deceived Meta’s AI support chatbot into adding their email to victims' Instagram accounts and resetting passwords without needing access to the victims' emails.

      Over the weekend, hackers breached Instagram accounts by manipulating Meta’s AI-powered support chatbot. This attack did not require email access from the victims, nor did it involve phishing or malware. The hacker simply instructed the chatbot to add a new email address to an account.

      A video shared on X detailed the process. The hacker used a VPN to disguise their location, evading Instagram’s automated safeguards. They then initiated a chat with the Meta AI Support Assistant and requested the addition of a new email to the targeted account.

      The chatbot dispatched a verification code to the hacker’s email, which the hacker relayed back to the bot. Following this, the chatbot presented a “Reset Password” button. The hacker entered a new password and gained control of the account.

      Notably, no access to the actual email address linked to the victim’s account was needed by the hacker. TechCrunch confirmed that the hacker’s public email, shown in the video, received the verification code. This incident exploited a critical flaw: the AI chatbot accepted the identity of the user it interacted with as the account owner without authenticating it.

      The affected accounts included the White House Instagram handle from the Obama era, inactive since 2017, and the account of US Space Force Chief Master Sergeant John Bentivegna. Security researcher Jane Wong reported that her account was also hijacked.

      “The password was changed without my consent, and I received numerous password reset notifications yesterday,” Wong said. “It’s quite alarming.” Multiple users on Reddit and X reported similar account takeovers that same weekend.

      Instagram spokesperson Andy Stone stated on Monday that the issue has been resolved. It remains uncertain how many accounts were compromised. Meta did not provide a comment to TechCrunch.

      This attack exemplifies the dangers of employing AI chatbots with account-level permissions. Customers of Salesforce’s Agentforce have hesitated to allow AI agents to perform significant financial actions due to this very risk. Analyst Rebecca Wettemann noted the concern as "the AI running off in the middle of the night and refunding a bunch of transactions." Meta allowed its AI to reset passwords, which it executed as instructed, but for the wrong individual.

      The security landscape for AI agents is generating new vulnerabilities faster than companies can manage them. The Claw Chain exploit from OpenClaw leveraged an agent’s sandbox privileges, while this Instagram attack exploited the privileges associated with an AI support bot’s account management. The common issue here is that the security of the system hinges on whether the AI can authenticate the requestor's identity before acting.

      The Meta AI Support Assistant was intended to lower the cost of human customer service, achieving that goal but simultaneously creating vulnerabilities that human support representatives wouldn't have. A human agent would have verified the caller's identity before updating an account's email, something the chatbot failed to do.

      This marks the third significant AI deployment failure in just one week. Starbucks abandoned its AI inventory system after several months of inaccuracies, and Waymo's recent recall failed within two weeks. The issue with Meta’s AI chatbot granting hackers access to Instagram accounts mirrors a troubling trend: AI systems implemented at scale often fail in unforeseen ways, with consequences that outweigh the efficiencies they were designed to provide.

Other articles

Apple prepares a receipt-scanning bill splitter for iOS 27. Apple prepares a receipt-scanning bill splitter for iOS 27. Apple is set to introduce a bill-splitting feature in iOS 27 that takes photos of receipts, allocates items to friends, and creates requests for Apple Cash, marking a challenge to Splitwise and Venmo. GoPro cautioned that it might not endure. The AI memory crisis is harming companies that produce tangible items. Memory prices increased by 80-115%. Revenue decreased by 26%. GoPro indicated "substantial doubt" regarding its continued viability. The company is considering a sale or a shift to the defense sector. Salesforce's investment in Anthropic reaches $5 billion in preparation for the IPO filing. Salesforce's investment in Anthropic reaches $5 billion in preparation for the IPO filing. Salesforce transformed an initial $50 million investment in Anthropic into a $5 billion stake, which now constitutes two-thirds of its entire strategic portfolio, as the creator of Claude prepares for an IPO with a $965 billion valuation. Apple prepares receipt-scanning bill splitter for iOS 27. Apple prepares receipt-scanning bill splitter for iOS 27. Apple is introducing a bill-splitting feature in iOS 27 that takes photos of receipts, allocates items to friends, and creates Apple Cash requests, posing a challenge to Splitwise and Venmo. The Asus ROG Ally X receives a unique redesign featuring an OLED screen and elegant gold accents that appear refined rather than flashy. The Asus ROG Ally X receives a unique redesign featuring an OLED screen and elegant gold accents that appear refined rather than flashy. The anniversary edition introduces OLED to the Ally series for the first time, featuring a 7.4-inch 120Hz 1,400-nit display, AMD Ryzen AI Z2 Extreme, and TMR joysticks. Tencent allows PayPal users to make payments using WeChat QR codes in China. Tencent allows PayPal users to make payments using WeChat QR codes in China. PayPal users can now scan WeChat Pay QR codes while shopping at merchants throughout China, eliminating the main barrier for foreign tourists in a country where cash is no longer prevalent.

Hackers took control of Instagram accounts by requesting password resets from Meta's AI chatbot.

The AI support bot included a hacker's email, dispatched a verification code, and provided a button for resetting the password. Access to the victim's email was not required.