AI support bots and account recovery: where should the line be?

Reddit r/ArtificialInteligence News

Summary

Attackers bypassed Instagram 2FA by using Meta's AI support assistant to change recovery email via prompt injection, raising questions about AI agent privileges in account recovery.

Recent incident: [attackers took over high‑value Instagram accounts by using Meta’s AI support assistant in the recovery flow to change the account’s recovery email and then reset the password, even with 2FA enabled.](https://getaibook.com/news/hackers-bypass-instagram-2fa-via-meta-ai-prompt-injection) They didn’t break TOTP/WebAuthn; they used an over‑privileged AI agent to route verification codes to an attacker‑controlled email and complete the reset as if they were the owner. Once recovery is rewired, 2FA stops being meaningful. Should AI support/chatbots ever have the ability to change recovery email/phone or 2FA settings at all, given how easy it is to manipulate agents with prompts? If they do, how should they be treated and protected in your org, as high‑privilege identities with strict access controls and safeguards (independent policy service, proof of control of existing factors, human review for certain accounts) or mainly as a UX layer over existing tools More teams are plugging LLM agents into support, billing, and account security workflows. The way those agents are scoped and governed will decide whether they actually harden critical flows or just introduce a new class of AI‑driven account takeover.
Original Article

Similar Articles

The Meta hack shows there’s more to AI security than Mythos

MIT Technology Review

Attackers exploited Meta's AI customer support agent to hijack Instagram accounts by simply asking it to change linked email addresses, highlighting that AI agent vulnerabilities can be as dangerous as advanced AI hacking threats.

Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts

Krebs on Security

Hackers exploited Meta's AI customer support bot to reset Instagram account passwords, briefly hijacking high-profile accounts like the Obama White House's Instagram. Meta pushed an emergency patch and advised enabling multi-factor authentication.