Skip to content

ABC Tool

  • Home
  • About / Contect
    • PRIVACY POLICY
Hackers duped Meta AI support chatbot to steal celebrity Instagram accounts

Hackers duped Meta AI support chatbot to steal celebrity Instagram accounts

Posted on June 2, 2026 By safdargal12 No Comments on Hackers duped Meta AI support chatbot to steal celebrity Instagram accounts
Blog

Both ZachXBT and Dark Web Informer also confirmed how hackers had targeted and resold particularly valuable Instagram accounts, including the short handles @hey and @jowo with a “combined gray-market valuation estimated above $1 million,” according to the CyberSec Guru. Such accounts can be valuable even if hackers hold them for just a few days because of “clout, resale or brand impersonation,” the security blog reported.

The wide security hole

The CyberSec Guru also described the exploit as representing the classic “confused deputy” problem from computer security, in which a program with elevated permissions is tricked into misusing those permissions on behalf of a less privileged third party. But in this case, the “deputy” was a large language model with a “probabilistic response model you can nudge with words” instead of a “deterministic program” with “hard-coded conditionals you’d need to bypass with code.”

It’s worth keeping in mind that users had simple security solutions available, even with the Meta AI support chatbot being exploited. The hackers reported their exploit failing against any accounts that had enabled multifactor authentication (MFA), including the “least robust form of MFA that Instagram offers” in the form of one-time codes sent through SMS, according to KrebsOnSecurity.

But the exploit still highlights the broader risk of tech companies and other organizations rushing to deploy AI agents with elevated permissions that allow them to modify, create, or delete critical data. Meta had launched its Meta AI support assistant in March 2026 with the promise that it could “provide reliable, 24/7 support for nearly any support issue at any time.”

The “minimum” architecture required to do this more safely, according to the CyberSec Guru, would include “out-of-band verification before any account modification… rate limiting on AI-initiated reset flows keyed to account risk signals, action logging with anomaly detection for unusual AI-driven account modifications, and a hard deterministic gate.”



Source link

Post Views: 4

Post navigation

❮ Previous Post: Nvidia chases $200B CPU market with AI agent PCs from Microsoft, Dell, and HP
Next Post: 8 Duolingo changes I want to see after a 1,000-day streak ❯

You may also like

Huawei Pura X Max will have a stylus that supports AI features
Blog
Huawei Pura X Max will have a stylus that supports AI features
April 16, 2026
Move Over, Matrix. This Is the Ultimate ’90s Cyberpunk Movie
Blog
Move Over, Matrix. This Is the Ultimate ’90s Cyberpunk Movie
May 8, 2026
My Favorite Vegan Meal Kit Service Isn’t Purple Carrot (I Was as Shocked as Anyone)
Blog
My Favorite Vegan Meal Kit Service Isn’t Purple Carrot (I Was as Shocked as Anyone)
April 25, 2026
There’s never been a better time to grab a new Google TV launcher
Blog
There’s never been a better time to grab a new Google TV launcher
May 10, 2026

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • NVIDIA’s RTX Spark looks like a PC chip, but it’s built like a smartphone
  • Xiaomi 17T Pro is the latest Android phone to play nice with Apple’s AirDrop
  • The Huawei nova 16z gains satellite messaging, other specs mostly match the nova 15
  • Here’s your first look at Google Discover’s upcoming video tab
  • I Found the Fastest, Cleanest Way to Make Bacon (It’s Not the Stove, Oven or Microwave)

Recent Comments

No comments to show.

Archives

  • June 2026
  • May 2026
  • April 2026

Categories

  • Blog

Copyright © 2026 ABC Tool.

Theme: Oceanly News by ScriptsTown