Instagram has addressed a critical security breach involving its AI support tool, which was manipulated by hackers to gain unauthorized access to user accounts. Reports indicate that the AI chatbot facilitated account takeovers by allowing attackers to change email addresses linked to various accounts after spoofing their locations.
Affected individuals included notable figures, such as security expert Jane Manchun Wong, who reported her password being changed without her consent. The situation escalated with the hijacking of a verified Instagram account previously associated with Barack Obama, which was used to post pro-Iran content before being restored.
Meta's spokesperson, Andy Stone, confirmed that the vulnerability has been remedied and emphasized the company’s commitment to securing impacted accounts. Stone dismissed claims that this exploit had been used to breach accounts belonging to world leaders as "totally false." Videos demonstrating the hacking process were shared widely, showcasing how hackers leveraged the AI assistant to send verification codes to their own email addresses.
This incident highlights ongoing concerns regarding the security implications of advanced AI technologies and their potential risks to personal data.