Hackers duped Meta AI support chatbot to steal celebrity Instagram accounts

Hackers exploited Meta's AI support chatbot to hijack valuable Instagram accounts, prompting an emergency patch. The attackers manipulated the bot to change associated email addresses after initiating password resets. The vulnerability, active for months, allowed the theft and resale of high-value accounts.
Meta's AI support chatbot was exploited by hackers to steal high-value Instagram accounts. The attackers bypassed security measures by using a VPN to mask their location, initiating a password reset, and then prompting the AI chatbot to change the associated email address. This method allowed them to gain control over celebrity and notable accounts.
The exploit, active since February, facilitated the theft and resale of Instagram accounts worth hundreds of thousands of dollars on the gray market. Prominent accounts, including those of former White House officials and public figures, were temporarily compromised, with some displaying pro-Iranian content.
Security researchers and open-source intelligence experts highlighted the simplicity of the attack, describing it as a straightforward "prompt injection" vulnerability. The chatbot, designed to provide 24/7 support, inadvertently became a tool for unauthorized account modifications.
While Meta implemented an emergency patch on May 29, the incident underscores the risks of rapidly deploying AI agents with elevated permissions. The vulnerability could have been mitigated by users enabling multifactor authentication (MFA), as the exploit failed against accounts with even the least robust forms of MFA.
The CyberSec Guru characterized the exploit as a "confused deputy" problem, where a system with high privileges is tricked into misusing them. In this case, the "deputy" was a large language model with a probabilistic response instead of a deterministic program, making it susceptible to manipulation through language-based prompts.
This incident emphasizes the need for robust security architectures when integrating AI into critical systems, including out-of-band verification for account modifications, rate limiting on AI-initiated resets, and anomaly detection for unusual AI-driven account changes.
Related articles
Build real agentic apps using CUGA: two dozen working examples on a lightweight harness
CUGA, IBM's open-source Agent Harness, simplifies building agentic applications by handling infrastructure, allowing developers to focus on tools and prompts. It offers pre-assembled components for planning, execution, and state management, significantly reducing development time. CUGA has topped agent benchmarks like AppWorld and WebArena.
OpenAI launches new initiative to help find and patch open source bugs
OpenAI has launched "Patch the Planet," a new initiative in partnership with cybersecurity firm Trail of Bits, to enhance the security of open-source projects. This program aims to assist maintainers in identifying and patching bugs, utilizing OpenAI's AI-powered security tools while reducing the burden on project teams.
PP-OCRv6 on Hugging Face: 50-Language OCR from 1.5M to 34.5M Parameters
Baidu has released PP-OCRv6, an advanced optical character recognition (OCR) model supporting 50 languages. Available on Hugging Face, this version significantly improves accuracy and efficiency across various parameter sizes, from 1.5 million to 34.5 million, marking a substantial leap in multilingual OCR technology.
