Skip to content

ABC Tool

  • Home
  • About / Contect
    • PRIVACY POLICY
Hackers duped Meta AI support chatbot to steal celebrity Instagram accounts

Hackers duped Meta AI support chatbot to steal celebrity Instagram accounts

Posted on June 2, 2026 By safdargal12 No Comments on Hackers duped Meta AI support chatbot to steal celebrity Instagram accounts
Blog

Both ZachXBT and Dark Web Informer also confirmed how hackers had targeted and resold particularly valuable Instagram accounts, including the short handles @hey and @jowo with a “combined gray-market valuation estimated above $1 million,” according to the CyberSec Guru. Such accounts can be valuable even if hackers hold them for just a few days because of “clout, resale or brand impersonation,” the security blog reported.

The wide security hole

The CyberSec Guru also described the exploit as representing the classic “confused deputy” problem from computer security, in which a program with elevated permissions is tricked into misusing those permissions on behalf of a less privileged third party. But in this case, the “deputy” was a large language model with a “probabilistic response model you can nudge with words” instead of a “deterministic program” with “hard-coded conditionals you’d need to bypass with code.”

It’s worth keeping in mind that users had simple security solutions available, even with the Meta AI support chatbot being exploited. The hackers reported their exploit failing against any accounts that had enabled multifactor authentication (MFA), including the “least robust form of MFA that Instagram offers” in the form of one-time codes sent through SMS, according to KrebsOnSecurity.

But the exploit still highlights the broader risk of tech companies and other organizations rushing to deploy AI agents with elevated permissions that allow them to modify, create, or delete critical data. Meta had launched its Meta AI support assistant in March 2026 with the promise that it could “provide reliable, 24/7 support for nearly any support issue at any time.”

The “minimum” architecture required to do this more safely, according to the CyberSec Guru, would include “out-of-band verification before any account modification… rate limiting on AI-initiated reset flows keyed to account risk signals, action logging with anomaly detection for unusual AI-driven account modifications, and a hard deterministic gate.”



Source link

Post Views: 5

Post navigation

❮ Previous Post: Nvidia chases $200B CPU market with AI agent PCs from Microsoft, Dell, and HP
Next Post: 8 Duolingo changes I want to see after a 1,000-day streak ❯

You may also like

CEO Melanie Perkins on Canva’s big pivot to AI enterprise software
Blog
CEO Melanie Perkins on Canva’s big pivot to AI enterprise software
April 20, 2026
Trump administration cites national security in stalling 165 wind farms
Blog
Trump administration cites national security in stalling 165 wind farms
May 4, 2026
Today’s NYT Connections Hints, Answers for April 25 #1049
Blog
Today’s NYT Connections Hints, Answers for April 25 #1049
April 25, 2026
EU advises member states against using Chinese networking equipment
Blog
EU advises member states against using Chinese networking equipment
May 5, 2026

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Xiaomi launches a new Bold Yellow color for the Poco X8 Pro
  • iPhone Fold/Ultra dummy unit leaks in white color
  • ‘Dungeons & Dragons: Honor Among Thieves,’ ‘Challengers’ and More Movies You Can Stream for Free in June 2026
  • How to watch Microsoft’s Build 2026 conference
  • Utils | CSS-native parallax effect

Recent Comments

No comments to show.

Archives

  • June 2026
  • May 2026
  • April 2026

Categories

  • Blog

Copyright © 2026 ABC Tool.

Theme: Oceanly News by ScriptsTown