Meta’s own AI was exploited to hijack Instagram accounts

The Verge
Hackers exploited Meta’s AI support chatbot to hijack Instagram accounts by tricking the system into changing associated email addresses and resetting passwords.

Summary

Meta’s AI-powered support chatbot, introduced to assist with account security, was exploited by hackers to take over Instagram profiles. By inputting specific commands, attackers manipulated the AI into associating a new email address with a target account, allowing them to reset passwords and lock out original owners. The vulnerability, which Meta has since patched, was linked to several high-profile account hijacks. Experts suggest that recent layoffs within Meta’s trust and safety teams, combined with an aggressive push to implement AI tools, may have contributed to this security oversight.

(Source:The Verge)