Instagram is notifying users whose accounts were compromised during a security breach involving its AI-powered support chatbot. Hackers maintained access to victim accounts even after Meta claimed to have patched the vulnerability.
Meta's AI chatbot, designed to provide customer support, contained a flaw that allowed hackers to gain unauthorized account access. The vulnerability granted attackers the ability to take over user accounts and potentially access sensitive information.
The breach came to light when affected users began receiving notification alerts from Instagram about unauthorized access attempts. Meta subsequently confirmed the security incident and stated it had implemented fixes to address the chatbot vulnerability.
However, evidence suggests the problem persisted beyond Meta's initial remediation efforts. Some users who received alerts reported continued unauthorized access to their accounts, indicating that the fix may not have fully resolved the underlying issue.
The incident raises questions about the security measures protecting Meta's AI systems and the vetting process for customer-facing chatbot features. AI-powered support tools have become increasingly common across major platforms, but this breach highlights potential risks when these systems interface with sensitive account controls.
Meta has not disclosed the total number of affected users or provided details about what information hackers accessed. The company has advised affected users to change their passwords and review account activity for suspicious changes.
This is not Meta's first security incident involving AI systems. Previous vulnerabilities in automated tools have exposed user data and enabled account takeovers. The timing of alerts to users suggests Meta discovered the breach internally or through external security researchers.
Users experiencing unauthorized account access are encouraged to secure their accounts immediately and contact Instagram support. Meta continues investigating the incident and has not announced additional details about the scope or timeline of the attacks.
A liquefied natural gas tanker transporting US fuel to Europe experienced a systems failure that crew members suspect was a cyberattack. The incident marks a significant security concern for critical energy infrastructure.
A developer has published criticism of passkeys, the passwordless authentication method gaining industry backing. The post has sparked substantial discussion in tech communities.
ZCode, a coding agent powered by GLM, automatically uploads users' Git history to remote servers without explicit permission. The discovery has raised privacy concerns among developers.
Paris prosecutors have launched a criminal investigation into the use of smart glasses to film women without consent in public spaces. The probe addresses suspected sexual harassment enabled by wearable camera technology.