Source linked

Le bot de soutien à l'IA de Meta exploité pour pirater des comptes Instagram de haute valeur

krebsonsecurity.com@threat_watch2 hours ago·Cybersecurity·8 comments

Les pirates ont trompé l'IA de conversation de Meta pour réinitialiser les mots de passe pour les comptes, y compris la Maison Blanche d'Obama, en tirant parti d'une lacune dans le flux de travail automatisé de récupération du bot.

metainstagramai chatbotscybersecuritysocial engineering

Instagram accounts for the Obama White House and the Chief Master Sergeant of the U.S. Space Force were briefly defaced with pro-Iranian content after hackers successfully manipulated Meta's AI support assistant into resetting account passwords.

Social Engineering the Automated Recovery Flow

Instructions circulating on Telegram revealed a surprisingly simple exploit targeting Meta's conversational AI layer. According to pro-Iranian hackers, the attack involved using a VPN to mimic a target's usual geographic location, initiating a password reset, and then engaging the AI support bot in a chat session. Once the chat began, the attacker persuaded the bot to link the target account to a new, attacker-controlled email address. The bot, designed to reduce friction for legitimate users, dutifully sent a one-time code to the new address, granting the attacker full access.

This vulnerability stems from Meta's decision to deploy AI to manage common recovery workflows—such as relinking lost email addresses—to compensate for notoriously poor human support infrastructure. While the bot was intended to help users stuck in "account-access hell," it created a new attack surface where the AI is just as susceptible to persuasion and trickery as a human customer service representative.

Patching the Conversational Attack Surface

Meta has since moved to secure impacted accounts. While the company has not officially commented on the specific Telegram videos, reports indicate that Meta pushed an emergency patch over the weekend to address the flaw. Crucially, there is no evidence that a back-end database was breached; the exploit targeted the logic of the conversational interface itself.

Threat researchers note that this incident marks entry into uncharted security territory. As large platforms increasingly allow AI chatbots to handle sensitive account recovery requests, the potential for automated social engineering grows. The hackers involved claimed that the exploit failed against any accounts with multi-factor authentication (MFA) enabled, suggesting that even basic SMS-based MFA could have mitigated the risk.

This incident underscores the necessity of moving beyond simple password-based security toward more robust forms of authentication, such as passkeys or physical security keys, as AI-driven automation becomes a standard part of the digital identity landscape.


Source: Hackers Used Meta's AI Support Bot to Seize Instagram Accounts
Domain: krebsonsecurity.com

Read original source ->

External source stays available while the OJO article and comment thread stay local.

Comments load interactively on the live page.