Hackers Conned a Chatbot to Hijack 20,000 Instagram Accounts


Just over a week ago, Meta’s AI-powered chat assistant unwittingly gave hackers access to thousands of Instagram accounts, including high-profile ones such as makeup retailer Sephora and the top noncommissioned officer of the US Space Force, as well as Barack Obama’s White House account.

The exact number was later revealed in a regulatory filing with the Maine attorney general’s office. The total stands at 20,225 compromised accounts (30 of whom were Maine residents).

The hack, reported by 404 Media last week, was easy to pull off against account holders who had not enabled two-factor authentication. Hackers simply asked the AI-powered bot to change the email address for a targeted account to their own. Once that was granted, the hackers requested a password reset, prompting the AI to send a code to their personal email address. After hackers verified the password reset, they were able to take control of the account. 

An edited step-by-step video of the process even appeared on X, showing how the hackers used a VPN to make it seem they were in the target’s location. At no point did the hackers even need the user’s email address or original password. 

In an incident notification letter to Maine Attorney General Aaron Frey, dated June 5, Meta acknowledged “a vulnerability in the AI-assisted account recovery system for Instagram … that was exploited by unauthorized third parties to perform password resets on Instagram user accounts.” 

After the exploit was made public, many Instagram users reported on Reddit and X that their accounts had been hacked, though the breadth of the hack wasn’t clear at the time. A Meta spokesperson posted on X that the exploit was fixed as of June 1, shortly after initial reports. 

How did AI let the hack happen? 

The problem is almost entirely due to Meta’s customer support now being run by AI. The tech giant made the switch back in March, saying it would enable “24/7 help for account issues like updating your password and settings for your profile.” 

CNET AI Atlas badge; click to see more

But with the AI chatbot handling the whole process, humans couldn’t step in when suspicious activity began. That allowed hackers to carry out the social engineering-style attack and pull it off multiple times before anyone noticed.

Affected accounts were forcibly logged out for all users and email addresses were restored. Users were then told to reset their passwords and reauthenticate their logins. Meta says that once the accounts are secured, a second notice will be sent to remind people to turn on two-factor authentication to prevent future attacks. 

Meta has not yet responded to a request for comment. 

How to protect yourself from similar attacks

The social engineering exploit had one major limitation: It did not work on accounts with multifactor authentication. Those accounts either already had the code in their authentication app of choice or received it by text. Without the MFA setting, the one-time reset code appears to be sent to an email address of choice, thereby letting hackers just, well, have it. 

The best way to protect yourself is to enable multifactor authentication, which is available on all of Meta’s platforms. It won’t protect you 100% of the time, but it’s a lot better than a password by itself, and it would’ve protected against this particular exploit entirely. 

There are other things you can do to beef up account security, including using passkeys where available and a private email address to make your account credentials harder to find.





Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


When to watch Chelsea vs. Tottenham

  • Tuesday at 3:15 p.m. ET (12:15 p.m. PT).

Where to watch

  • Chelsea vs. Tottenham will air in the US on NBC Sports Network and Peacock Premium.

73% off with 2yr plan (+4 free months). Now only $3.49/month


See more details

See at Fubo

Fubo

Watch the Premier League in Canada

Fubo Canada

Chelsea will look to deal a major blow to Tottenham’s Premier League survival hopes on Tuesday as these two fierce London rivals clash in a mouthwatering derby. 

With relegation rivals West Ham United suffering a heavy defeat away to Newcastle on Sunday, Spurs now need just one point from its final two matches to secure its top-flight status. Despite its hosts’ recent poor form, earning any kind of result at Stamford Bridge will require Roberto De Zerbi’s men to defy recent history; Tottenham’s last win at this ground was more than eight years ago. 

Having suffered a narrow defeat to Manchester City in Saturday’s FA Cup final, Chelsea will meanwhile be determined to bounce back in its final home game of the season. A win here against its neighbors would keep the Blues’ hopes of European qualification alive, but pushing its bitter local rivals closer to relegation may prove an even sweeter reward for the Chelsea faithful.

Chelsea takes on Tottenham Hotspur on Tuesday at Stamford Bridge in west London, with kickoff set for 8:15 p.m. BST. That makes it a 3:15 p.m. ET or 12:15 p.m. PT start in the US and Canada, and a 5:15 a.m. AEST kickoff in Australian Wednesday morning. 

Calum McFarlane, Interim Manager of Chelsea, looking onwards.

Interim boss Calum McFarlane will take charge of Chelsea for the final time at Stamford Bridge today, with former Real Madrid boss Xabi Alonso set to take over the Blues in the summer. 

Alex Pantling/Getty Images

How to watch Chelsea vs. Tottenham in the US without cable

Tuesday’s clash at Stamford Bridge will be broadcast on NBC and streaming service Peacock. To catch the game live on Peacock, you’ll need a Peacock Premium or Premium Plus subscription. NBC Sports Network is available on platforms like YouTube TV.

Peacock offers two Premium plans, and after recent price increases, the ad-supported Premium plan costs $11 a month and the ad-free Premium Plus plan costs $17 a month.

How to watch the Premier League 2025-26 with a VPN

If you’re traveling abroad and want to keep up with English Premier League action while away from home, a VPN can help enhance your privacy and security when streaming.

It encrypts your traffic and prevents your internet service provider from throttling your speeds, and can also be helpful when connecting to public Wi-Fi networks while traveling, adding an extra layer of protection for your devices and logins. VPNs are legal in many countries, including the US and Canada, and can be used for legitimate purposes such as improving online privacy and security. 

However, some streaming services may have policies that restrict VPN use to access region-specific content. If you’re considering a VPN for streaming, check the platform’s terms of service to ensure compliance.

If you choose to use a VPN, follow the provider’s installation instructions to ensure you’re connected securely and in compliance with applicable laws and service agreements. Some streaming platforms may block access when a VPN is detected, so verify whether your streaming subscription allows VPN use.

James Martin/CNET

Price $78 for two yearsLatest Tests No DNS leaks detected, 18% speed loss in 2025 testsJurisdiction British Virgin IslandsNetwork 3,000 plus servers in 105 countries

ExpressVPN is our current best VPN pick for people who want a reliable and safe VPN, and it works on a variety of devices. It’s normally $120 a year for its most popular plan (Advanced), but if you sign up for an annual subscription for $90, you’ll get three months free. That’s the equivalent of $6 a month.

Note that ExpressVPN offers a 30-day money-back guarantee.

73% off with 2yr plan (+4 free months). Now only $3.49/month

Livestream Chelsea vs. Tottenham in the UK 

This Tuesday evening clash is exclusive to Sky Sports and will be shown on its Sky Sports Premier League channel. If you already have Sky Sports as part of your TV package, you can stream the game via its Sky Go app. Cord-cutters will want to set up a Now account and a Now Sports membership to stream the game. 

Now TV

Sky’s standalone streaming service Now offers access to Sky Sports channels with a Now Sports membership. You can get a day of access for £15 or sign up to a monthly plan from £35 a month right now.

Livestream Chelsea vs. Tottenham in Canada 

If you want to livestream EPL games in Canada this season, you’ll need to subscribe to Fubo. The service has secured exclusive rights to the Premier League and is broadcasting all 380 matches live. 

Fubo

Fubo is the go-to destination for Canadians looking to watch the EPL, with exclusive streaming rights to every match. It currently costs CA$27 for the first month, then CA$31.50 per month thereafter.

Livestream Chelsea vs. Tottenham in Australia 

Livestreaming rights for the EPL are now with Stan Sport, which is showing all 380 matches live, including this game.

Stan

Stan Sport will set you back AU$20 a month (on top of a Stan subscription, which starts at AU$12). It’s also worth noting that the streaming service is currently offering a seven-day free trial.

A subscription will also give you access to Premier League, Champions League and Europa League action, as well as international rugby and Formula E.





Source link