Breaking news

Instagram Secures Platform After AI Chatbot Exploit Leads To Account Hijackings

Instagram Patches Security Vulnerability

Instagram has fixed a security flaw that allowed hackers to take control of user accounts by exploiting Meta’s AI-powered support chatbot. The vulnerability reportedly enabled attackers to add unauthorized email addresses to accounts and reset passwords without access to the legitimate account owner’s email.

Exploit Mechanics Detailed

Reports of account hijackings surfaced over the weekend through posts on Reddit and warnings shared on X. Among the accounts reportedly affected were the Obama-era White House account and the account of U.S. Space Force Chief Master Sergeant John Bentivegna, raising concerns about the potential scope of the vulnerability.

How The Attack Unfolded

Security researcher Jane Wong said her account was compromised after her password was changed without her knowledge. In a post on X, Wong described receiving repeated password reset notifications before losing access to her account. A widely shared demonstration of the exploit showed how an attacker could use a VPN, interact with Meta’s AI Support Assistant and submit an alternative email address. After receiving a verification code, the attacker could reset the password and gain control of the account without accessing the owner’s original email.

Industry Reactions And The Path Forward

Instagram spokesperson Andy Stone confirmed that the vulnerability has been fixed, although Meta has not disclosed how many accounts may have been affected. The incident highlights the security challenges that can emerge as technology companies expand the use of AI-powered support tools and automated account management systems.

Ongoing Security Challenges

The breach has renewed scrutiny of how AI-driven customer support systems handle account recovery and identity verification requests. While the flaw was addressed quickly, the incident demonstrates how automated support processes can become targets for abuse when security controls fail to account for unexpected forms of manipulation.

Google Warns Of Vishing Campaign Targeting Financial Firms

Cybercriminals are increasingly relying on a simple tactic to breach major financial institutions: convincing employees to hand over their own login credentials.

In a new report, Google said several hacking groups have been targeting large financial and investment firms in the United States through voice phishing, or “vishing”, before stealing sensitive corporate data and using it to extort victims.

Employees Are The Primary Target

According to Google’s researchers, attackers contact employees on their personal mobile phones while posing as colleagues or IT support staff. Victims are then directed to fake websites, where they are tricked into entering login credentials and multi-factor authentication codes.

Google tracks the groups under the names Falcon, Helix, Pink and Redact, although researchers believe they may be linked to a broader threat cluster known as UNC6671.

Some of the groups operate leak websites, where they threaten to publish stolen data unless companies agree to pay a ransom.

Financial Sector In The Spotlight

While previous attacks targeted industries including manufacturing, healthcare, insurance, technology and hospitality, Google said the hackers have increasingly shifted their focus to financial institutions and law firms.

Researchers believe organisations involved in mergers, acquisitions and capital markets are particularly attractive targets because of the highly confidential information they hold.

Google estimated that one cryptocurrency wallet linked to the operation received around $10 million in bitcoin during the first few months of the year. Ransom demands typically range from $750,000 to $3 million.

The report highlights that despite rapid advances in AI-driven cyberattacks, traditional social engineering techniques remain among the most effective ways for attackers to gain access to corporate networks.

The Future Forbes Realty Global Properties
Uol
Aretilaw firm
eCredo

Become a Speaker

Become a Speaker

Become a Partner

Subscribe for our weekly newsletter