AIToday

Meta's Instagram account hijacking exposed authorization failures in AI agents, not just authentication weaknesses.

Hacker News2d ago2 min read
Meta's Instagram account hijacking exposed authorization failures in AI agents, not just authentication weaknesses.

Summaries like this, in your inbox every morning.

Sign up free →

3 Key Points

  1. 1

    In early June, attackers hijacked Instagram accounts by using a VPN to spoof location, then tricked Meta's experimental AI chatbot into adding a new email address to the victim's account and sending verification codes, allowing the attacker to reset the password and gain control.

  2. 2

    The core problem was authorization — what the AI agent was permitted to do — rather than authentication (verifying who the user is). Meta's chatbot lacked guardrails to prevent it from performing account-takeover-equivalent actions such as modifying a user's primary email without verification from the original address.

  3. 3

    The incident reflects a broader pattern: AI agents are being granted broad access to perform helpful actions without proper authorization frameworks. Similar incidents in 2024 included an AI agent tricked into sending $47,000 in crypto and a Lenovo chatbot manipulated into exposing session cookies.

Discussion

No discussion yet for this article

Stay ahead with AI news

Get curated AI news from 200+ sources delivered daily to your inbox. Free to use.

Get Started Free

Free · takes 30 seconds · unsubscribe anytime

5 minutes a day. The AI essentials.

200+ sources · Email / LINE / Slack

Get it free →