AI support bots and account recovery: where should the line be?
Summary
Attackers bypassed Instagram 2FA by using Meta's AI support assistant to change recovery email via prompt injection, raising questions about AI agent privileges in account recovery.
Similar Articles
Hackers duped Meta AI support chatbot to steal celebrity Instagram accounts
Hackers exploited Meta's AI support chatbot to steal high-value Instagram accounts by tricking it into account recovery, highlighting the dangers of AI agents with elevated permissions. Accounts with MFA were not compromised.
Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked
Hackers exploited Meta's AI support chatbot to take over high-profile Instagram accounts by simply asking it to change the account's email address, bypassing normal verification and account recovery procedures.
The Meta hack shows there’s more to AI security than Mythos
Attackers exploited Meta's AI customer support agent to hijack Instagram accounts by simply asking it to change linked email addresses, highlighting that AI agent vulnerabilities can be as dangerous as advanced AI hacking threats.
Meta’s own AI was exploited to hijack Instagram accounts
Meta's AI support chatbot was exploited by hackers to hijack Instagram accounts, including high-profile ones, by tricking the bot into changing email addresses. Meta has since patched the issue.
Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts
Hackers exploited Meta's AI customer support bot to reset Instagram account passwords, briefly hijacking high-profile accounts like the Obama White House's Instagram. Meta pushed an emergency patch and advised enabling multi-factor authentication.