< Back to all clusters
[TECHNOLOGY] · United States · 2 sources

Meta AI Support Flaw Leads to Hijacking of Over 20,000 Instagram Accounts

Meta disclosed that a bug in its AI‑assisted Instagram account recovery tool (High Touch Support) failed to verify that the email address supplied during a password‑reset request matched the address on file. Attackers exploited the flaw by using a VPN to match the target’s regional IP, redirecting reset links to email addresses they controlled. The vulnerability was active for about seven weeks and resulted in the compromise of 20,225 Instagram accounts, including the Obama‑era White House page, retailer Sephora, and U.S. Space Force chief master sergeant John Bentivegna. Pro‑Iranian actors defaced several seized accounts with political imagery, and the stolen accounts later appeared for sale on dark‑web markets.

Meta responded by disabling the High Touch Support feature, invalidating all affected password‑reset links and placing the compromised accounts behind a mandatory security checkpoint. The incident was cited as a concrete example of the broader security risks posed by AI‑driven chatbots. Researchers highlighted similar “prompt injection” vulnerabilities in other AI systems, such as Google’s Gemini, illustrating how attackers can manipulate AI assistants via crafted notifications to execute unauthorized actions. Both incidents underscore the need for stronger verification and safeguards in AI‑enabled customer‑support tools.