Instagram is notifying users whose accounts were compromised during a security breach involving its AI-powered support chatbot. Hackers maintained access to victim accounts even after Meta claimed to have patched the vulnerability.
Meta's AI chatbot, designed to provide customer support, contained a flaw that allowed hackers to gain unauthorized account access. The vulnerability granted attackers the ability to take over user accounts and potentially access sensitive information.
The breach came to light when affected users began receiving notification alerts from Instagram about unauthorized access attempts. Meta subsequently confirmed the security incident and stated it had implemented fixes to address the chatbot vulnerability.
However, evidence suggests the problem persisted beyond Meta's initial remediation efforts. Some users who received alerts reported continued unauthorized access to their accounts, indicating that the fix may not have fully resolved the underlying issue.
The incident raises questions about the security measures protecting Meta's AI systems and the vetting process for customer-facing chatbot features. AI-powered support tools have become increasingly common across major platforms, but this breach highlights potential risks when these systems interface with sensitive account controls.
Meta has not disclosed the total number of affected users or provided details about what information hackers accessed. The company has advised affected users to change their passwords and review account activity for suspicious changes.
This is not Meta's first security incident involving AI systems. Previous vulnerabilities in automated tools have exposed user data and enabled account takeovers. The timing of alerts to users suggests Meta discovered the breach internally or through external security researchers.
Users experiencing unauthorized account access are encouraged to secure their accounts immediately and contact Instagram support. Meta continues investigating the incident and has not announced additional details about the scope or timeline of the attacks.
F5 has released security updates to address a critical zero-day vulnerability in BIG-IP APM that attackers are actively exploiting to achieve remote code execution.
Obscura has launched a VPN service architected to make user activity logging technically impossible. The service uses a no-log-by-design approach rather than relying on policy promises alone.
Hackers claim to have compromised the Federal Bureau of Investigation and obtained personal data on all FBI employees. The breach's scope and authenticity have not yet been independently verified.
Researchers at Cisco Talos developed a new framework to detect malware and hacking tools powered by AI chatbots. The discovery revealed an unusual threat: autonomous malware operating without human handlers.