Instagram Fixes Flaw That Let Hackers Steal Accounts Through Its AI Chatbot
Instagram has patched a security loophole that allowed hackers to take over user accounts by manipulating the platform’s AI-powered support chatbot. The exploit, which surfaced over the weekend, didn’t require attackers to break into a victim’s email—just a clever conversation with the bot.
Reports of hijacked accounts flooded Reddit and X over the weekend. Among the compromised profiles: the Obama-era White House Instagram handle (dormant since 2017) and the account of U.S. Space Force Chief Master Sergeant John Bentinvegna. Security researcher Jane Wong also lost control of her account. “The password changed without my knowledge, and I kept getting reset attempts,” she said. “Very unsettling.”
A video circulating on X laid out the attack step by step. First, the hacker used a VPN to mimic the target’s location and avoid Instagram’s automated safeguards. Then they opened a chat with Meta AI Support Assistant and asked it to add a new email to the victim’s account. The bot sent a verification code to that email—which the hacker controlled. The hacker fed the code back to the chatbot, which then displayed a “Reset Password” button. A few clicks later, the account was theirs.
TechCrunch confirmed that the hacker’s public email inbox, visible in the video, did receive the verification code. The trick worked because the attacker never needed access to the original email on file.
On Monday, Instagram spokesperson Andy Stone acknowledged the issue in replies to Wong and others, saying it had been fixed. Meta hasn’t disclosed how many accounts were affected or responded to requests for comment.
Source: TechCrunch
dArt Studio installs AI for local businesses in Broward & Palm Beach County, FL. We reply within 1 business hour.