Hackers duped Meta AI support chatbot to steal celebrity Instagram accounts



Both ZachXBT and Dark Web Informer also confirmed how hackers had targeted and resold particularly valuable Instagram accounts, including the short handles @hey and @jowo with a “combined gray-market valuation estimated above $1 million,” according to the CyberSec Guru. Such accounts can be valuable even if hackers hold them for just a few days because of “clout, resale or brand impersonation,” the security blog reported.

The wide security hole

The CyberSec Guru also described the exploit as representing the classic “confused deputy” problem from computer security, in which a program with elevated permissions is tricked into misusing those permissions on behalf of a less privileged third party. But in this case, the “deputy” was a large language model with a “probabilistic response model you can nudge with words” instead of a “deterministic program” with “hard-coded conditionals you’d need to bypass with code.”

It’s worth keeping in mind that users had simple security solutions available, even with the Meta AI support chatbot being exploited. The hackers reported their exploit failing against any accounts that had enabled multifactor authentication (MFA), including the “least robust form of MFA that Instagram offers” in the form of one-time codes sent through SMS, according to KrebsOnSecurity.

But the exploit still highlights the broader risk of tech companies and other organizations rushing to deploy AI agents with elevated permissions that allow them to modify, create, or delete critical data. Meta had launched its Meta AI support assistant in March 2026 with the promise that it could “provide reliable, 24/7 support for nearly any support issue at any time.”

The “minimum” architecture required to do this more safely, according to the CyberSec Guru, would include “out-of-band verification before any account modification… rate limiting on AI-initiated reset flows keyed to account risk signals, action logging with anomaly detection for unusual AI-driven account modifications, and a hard deterministic gate.”



Source link

  • Related Posts

    Today’s NYT Mini Crossword Answers for June 2

    Looking for the most recent Mini Crossword answer? Click here for today’s Mini Crossword hints, as well as our daily answers and hints for The New York Times Wordle, Strands, Connections and Connections:…

    Sony’s new fight stick and gaming monitor launch in August

    Sony is sharing new details about some of its upcoming gaming-focused hardware, including pricing and August launch dates for its FlexStrike fight stick and its 27-inch monitor. The FlexStrike fight…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    ‘Not the deal promised’: Labor’s Ed Husic questions Aukus pact that will deliver secondhand subs | Aukus

    ‘Not the deal promised’: Labor’s Ed Husic questions Aukus pact that will deliver secondhand subs | Aukus

    *The Republic of Love* – Marginal REVOLUTION

    *The Republic of Love* – Marginal REVOLUTION

    Today’s NYT Mini Crossword Answers for June 2

    Today’s NYT Mini Crossword Answers for June 2

    We may learn the Steam Machine launch date very soon, as Steam’s backend just got updated with a welcome tour

    We may learn the Steam Machine launch date very soon, as Steam’s backend just got updated with a welcome tour

    Moynat, Labubu Creator Kasing Lung Reunite for Dover Street Market Ginza Capsule

    Moynat, Labubu Creator Kasing Lung Reunite for Dover Street Market Ginza Capsule

    Rafael Grossi: the next Iran nuclear deal will look very different | US-Israel war on Iran

    Rafael Grossi: the next Iran nuclear deal will look very different | US-Israel war on Iran