Hackers bypassed security via support chatbot to hijack official accounts.
Meta fixes a major AI support vulnerability that allowed hackers to seize prominent Instagram accounts.
Meta recently fixed a major security flaw in its AI support assistant. This vulnerability allowed unauthorised access to several Instagram accounts. Cyber criminals manipulated the chatbot to link new email addresses with target profiles. They subsequently used the bot for password resets.
Consequently, hackers gained full control without needing the victim’s original email. This technique bypassed traditional security measures entirely. High-profile victims included the Obama-era White House account. Additionally, the US Space Force’s Chief Master Sergeant reported a breach.
Jane Wong also witnessed the hijacking of her personal profile. Reports of these hijackings initially surfaced on Reddit & X. A video demonstrated the methodical process for seizing these accounts. Attackers utilised VPN services to mask their true locations effectively.
They requested email changes through the AI assistant after appearing local. The bot then issued verification codes to the attacker’s email. Independent verifications confirmed that certain exploit attempts were successful. However, the chatbot did not always respond as intended initially.
Security experts expressed significant concerns regarding AI-powered customer support. They emphasised that robust identity verification remains vital for safety. Automatic programmes currently hold the power to impact entire accounts. Therefore, these systems require stringent oversight to prevent future abuse.
Andy Stone confirmed that Meta has now fixed the issue. The platform continues working to protect further accounts from compromise.
(Source: The Indian Express)
Read more on Technological News by heading to the 🔗 link.





