Meta Fixes AI Support Flaw Linked to Instagram Account Takeovers
Meta said it has fixed a flaw in its AI-powered support system after users reported that Instagram accounts had been compromised through the company's automated assistance tools. The issue drew attention after several users on Reddit and X said their accounts had been taken over. Those reportedly affected included a former White House account, an account belonging to a senior U.S. Space Force official and security researcher Jane Wong.
Videos circulating online appeared to show attackers using a virtual private network (VPN) to mask their location before contacting Meta's AI support chatbot. The chatbot then allegedly allowed a new email address to be added to a targeted account, enabling password resets through verification codes.
Security Concerns Raised
According to reports, the method did not require access to a victim's original email account, raising concerns about weaknesses in automated account recovery systems. A Meta spokesperson said the issue had been resolved but did not disclose how many users may have been affected. Security experts said the incident highlights potential risks in AI-driven support systems, warning that insufficient human oversight could leave similar services vulnerable to abuse.