Hackers duped Meta AI support chatbot to steal celebrity Instagram accounts



Both ZachXBT and Dark Web Informer also confirmed how hackers had targeted and resold particularly valuable Instagram accounts, including the short handles @hey and @jowo with a “combined gray-market valuation estimated above $1 million,” according to the CyberSec Guru. Such accounts can be valuable even if hackers hold them for just a few days because of “clout, resale or brand impersonation,” the security blog reported.

The wide security hole

The CyberSec Guru also described the exploit as representing the classic “confused deputy” problem from computer security, in which a program with elevated permissions is tricked into misusing those permissions on behalf of a less privileged third party. But in this case, the “deputy” was a large language model with a “probabilistic response model you can nudge with words” instead of a “deterministic program” with “hard-coded conditionals you’d need to bypass with code.”

It’s worth keeping in mind that users had simple security solutions available, even with the Meta AI support chatbot being exploited. The hackers reported their exploit failing against any accounts that had enabled multifactor authentication (MFA), including the “least robust form of MFA that Instagram offers” in the form of one-time codes sent through SMS, according to KrebsOnSecurity.

But the exploit still highlights the broader risk of tech companies and other organizations rushing to deploy AI agents with elevated permissions that allow them to modify, create, or delete critical data. Meta had launched its Meta AI support assistant in March 2026 with the promise that it could “provide reliable, 24/7 support for nearly any support issue at any time.”

The “minimum” architecture required to do this more safely, according to the CyberSec Guru, would include “out-of-band verification before any account modification… rate limiting on AI-initiated reset flows keyed to account risk signals, action logging with anomaly detection for unusual AI-driven account modifications, and a hard deterministic gate.”



Source link

  • Related Posts

    Theos: Cities Of Myth Is The Spiritual Successor To The One Of The Great City Builders Of The Early 2000s

    If you’re a PC gamer of a certain age, you may fondly remember Impressions Games. Over two years between 1998 and 2000, the studio released three games that would go…

    Do Eggs Expire? Here’s How Long They Actually Stay Fresh

    If you’ve been tossing out unused eggs as soon as the best-by date on your carton passes, you’re throwing them away too soon. In reality, that date is more of…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Pak vs Aus 2026 – Mike Hesson debunks pitches ‘myth’, says there will be ‘variety’ at ODI World Cup

    Pak vs Aus 2026 – Mike Hesson debunks pitches ‘myth’, says there will be ‘variety’ at ODI World Cup

    Delayed Again: Boeing 777X Certification Setback Puts 2027 Deliveries At Risk

    Delayed Again: Boeing 777X Certification Setback Puts 2027 Deliveries At Risk

    Canada slips slightly in top universities ranking, but experts say look carefully at the details

    Canada slips slightly in top universities ranking, but experts say look carefully at the details

    Theos: Cities Of Myth Is The Spiritual Successor To The One Of The Great City Builders Of The Early 2000s

    Theos: Cities Of Myth Is The Spiritual Successor To The One Of The Great City Builders Of The Early 2000s

    Mina The Hollower Traps You In The Bayou (To Teach You That You Can Get Out)

    Mina The Hollower Traps You In The Bayou (To Teach You That You Can Get Out)

    The New Zealand Parakeet Pair That Are Saving Their Species

    The New Zealand Parakeet Pair That Are Saving Their Species