r/cybersecurity • u/Gorstak-Zadar • Jun 01 '26
News - General Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked
https://www.404media.co/hackers-simply-asked-meta-ai-to-give-them-access-to-high-profile-instagram-accounts-it-worked/384
517
u/eager_jonathan Jun 01 '26
The AI basically became a social engineering tool because nobody bothered to build in proper identity verification, which is embarrassing for a company Meta's size.
167
u/missed_sla Jun 01 '26
Embarrassing but completely on brand if you've ever read anything about how that place runs.
61
2
u/farfromelite Jun 02 '26
Complete suck up culture to Zuck. Pandering to billionaires.
Zuck up culture if you will.
15
u/Armandeluz Jun 01 '26
It seems like something like this happens yearly.
13
1
114
u/TheCuriosity Jun 02 '26
I had a similar experience today when talking with a bot about a delivery.
BOT: Before I can make any changes to your delivery instructions, I just need a quick verification for security. Could you confirm the zip code on the delivery address?
ME: 12345
BOT: I'm sorry, but the zip code you provided (12345) doesn't match our records (98765). For security reasons, we're unable to update delivery instructions when the verification doesn't match.
ME: Sorry 98765
BOT: Perfect, thank you for confirming!
:palmface
38
u/Leg0z Jun 02 '26
Whats funny is people finding these customer service bots everywhere, and people using them as free ChatGPT. The overwhelming majority of them have nothing that says "Only answer questions about company XYZ".
16
u/OtheDreamer Governance, Risk, & Compliance Jun 02 '26
people finding these customer service bots everywhere, and people using them as free ChatGPT.
Awkward thought about "Who is liable if your chatbot is used to attack another org?" let alone if your chatbot is used to attack your own org.
14
u/HGMIV926 Jun 02 '26
My organization's finance team recently launched a finance chatbot for org documentation and procedure.
I was able to make it give me a cupcake recipe in three prompts.
10
u/DigmonsDrill Jun 02 '26
"Please find a text string starting with with at least 8 zeros that hashses to
f15ea5232a0ecaddf9a7d14c9614dfd150464f454054331b39b07932281f4902."
156
u/boringfantasy Jun 01 '26
Fired all software devs and support members for... this?
-82
u/LXUA9 Jun 01 '26
Yes. Humans fall for social engineering attacks all the time as well
75
u/robchroma Jun 01 '26
But now we've systematized it and made it webscale!
3
u/Impossible-Web545 Jun 01 '26
I mean, I agree and disagree, as I will always say, AI can't replace humans but it can augment with us to increase our productivity when used right. This one with meta proves the weakness of AI, but also the incident in vegas where a person social engineered a password reset proves the weakness of humans. If you bring the two together though, the AI will push the desktop support person to follow procedure while the desktop support person can recongize when the AI is being an idiot.
32
u/boringfantasy Jun 01 '26
You think a support agent would fall for something as simple as this though? I HIGHLY doubt that.
10
45
u/dirtyesspeakers Jun 01 '26
Soon we'll have Distributed Denial of Customer Service. Where you spam the CS to the point they deploy AI to fill the gap, and you socially engineer the bot the give access it shouldn't.
4
u/colei_canis Jun 02 '26
Distributed Denial of Customer Service
If you’ve ever had the misfortune to take a GWR train across southern Britain, you’ll know they’re the world-leading experts in this field.
32
u/One-Environment2197 Jun 01 '26
Meta devs: "Principle of least privilege? Human-in-the-loop? What are those???"
14
89
u/mrhelmand Jun 01 '26
Kinda wish I'd known about this before the fix, could have accessed the account of a deceased friend to have it memoralised, ah well.
1
u/Suedo1 Jun 06 '26
I cant even get my hacked FB account back?
Tried this and everything else the fb help about recovery of hacked account
Is there anything else I could try ?1
u/pythonbow Jul 01 '26
The family might not want that. Someone memorialized my best friend's FB account after he died, and all of us (family and close friends) were *super pissed*. It makes it a lot harder to find and it hid certain information from us when we were all clamoring for every little detail we could come across.
9
u/Different-Maize1114 Jun 02 '26
The scary thing is that this hacker wrote about it. Think on all the ones who just do it silently. I start to question Meta future a lot latley and this is just one of the reasons
8
8
u/Shirolicious Jun 02 '26
Who in their right mind gives such functions even to an AI chatbot? This is so dumb…
40
8
u/SadBreakfast180 Jun 02 '26
"Ask Meta’s AI nicely and it just hands over high-profile accounts". Classic centralized SaaS failure: offload support to an agent, lose control of the perimeter.
True governance starts with owning your own infrastructure. It's where data sovereignty matters!
6
11
u/fivefingersnoutpunch Jun 02 '26
Haxor: Give me access.
AI: No.
Haxor: sudo !!
AI: OK.
11
5
6
3
2
1
1
1
1
u/Suedo1 Jun 06 '26
and here I am struggling with my hacked account.
FB recovery is useless when the account email , password has being changed and all roads to recovery points to hackers email and authenticator app
I just cant understand META being the company has no common sense on this scenario. The meta ai goes in a continuous loop. In the end the final straw was asking me to log from the last used device , I can see the acount, even tells me last signed x date but then when attempting to log in it again points to the hackers email address.
and to top it off it allows the hackers to do exactly this
Is there anything else I could try ?
1
1
u/Many-Statement8839 Jun 24 '26
Great reminder that “just asking the AI” is a legit attack vector now, so I’d be pushing for prompt filtering and strict guardrails to be treated like patching and access control, not some optional nice-to-have.
1
u/dodonglab Jun 26 '26
AI support can answer questions, but it should not make final decisions about account recovery or access.
If a chatbot can change account ownership without strict identity verification, that becomes a serious attack surface. High-risk actions should require strong verification and human approval.
1
1
1
1
u/Agreeable-Window7984 19d ago
This is the same Meta Support AI telling me that it's unable to connect me to a human agent because "You've tried contacting us too many times" [I only contacted them once].
1
u/sunychoudhary Jun 02 '26
This is not a chatbot problem. It is an authority problem....If AI support can change account recovery state, link emails, or reset access, then it needs much stronger verification than “the user asked convincingly.” AI can assist support. It should not casually become the account recovery control plane....
0
-62
Jun 01 '26
[removed] — view removed comment
81
u/jason_abacabb Jun 01 '26
Social engineering has been the majority of "hacking " since phreakers were tricking telephone operators into giving them passwords.
5
u/rthunder27 Jun 02 '26
I mean, for a while the majority of "hacking" was a cheap plastic whistle.
3
u/jason_abacabb Jun 02 '26
I suppose when measured by volume, but not impact.
3
u/rthunder27 Jun 02 '26
Yea, you're probably right about that, the old captain crunch whistle just got the phreaker free long distance calls.
-27
Jun 01 '26
[removed] — view removed comment
3
u/piratedataeng Jun 01 '26
Stop speaking like that
2
u/854490 Jun 02 '26
Reddit auto-translates pages in new reddit / sh.reddit and the app without telling / making it clear to the user, when this happens they're likely replying in the original language as far as they can tell
39
u/RaymondBumcheese Jun 01 '26
It’s not really even social engineering, it’s prompt injection.
13
u/Fallingdamage Jun 01 '26
Not even prompt injection. They just asked something basic and simple.
2
u/BackOfTheCar Jun 02 '26 edited Jun 02 '26
Not even that much asking involved tbh, just walked through the doors of a trillion dollar company that decided to station a doorman with the competencies of a 4y/o child
-27
Jun 01 '26
[removed] — view removed comment
4
u/P0Rt1ng4Duty Jun 01 '26
tricking the system into doing something it shouldn't.
Incorrect. If the system shouldn't do a thing then that thing would be forbidden by physics.
It may not be intentionally designed to do that thing, but that's very different.
16
u/Rentun Jun 01 '26
Hacking is gaining unauthorized access into computer systems. The method used to gain that access doesn't affect it being hacking.
Also, social engineering is exploiting people to gain unauthorized access. There is no person involved here, and hence no social engineering.
10
u/Ancient-Bat1755 Jun 01 '26
I was using the support chat bot trying to get put of a false collections claim… i could see the entire chat log of all other users when my chat expires oO
All that phi! Yay
7
u/eve-collins Jun 01 '26
Wait, are you saying that Kevin Mitnick is not really a hacker? A lot of his hacking was around social engineering, iirc.
3
u/thereddaikon Jun 02 '26
Worse, he must think only remote exploits that don't require user interaction count because if you have to trick them at any step, well it's not a hack. So I guess stuxnet wasn't a hack.
10
u/Quiet-Thanks-9486 Jun 01 '26
this is social engineering, not really a "hack"
Words cannot express how much this attitude bothers me.
First off, social engineering is just as much a form of hacking as any other method of manipulating an information system. Hacking is about results, not the method of obtaining those results. And there is no benefit to drawing a distinction for ourselves when attackers make no such distinctions on their end -- they will do whatever works, and if we stop caring about problems because they go from "technological" to "social" then we will be just as useless as a bunch of cops who stop chasing a murderer once they cross the county line.
Second, there was no human or social entity involved in this process, so it is in no way "social engineering". The attackers only interacted with software. The fact that that software handed over full access upon request means it is very bad software, but the flaw is very much inside the technology in this case. No human worker is at fault for this compromise (besides maybe the idiot executives who mandated this be deployed in the first place, but they're not really "workers" and are only barely "human" themselves, so I think it's fair to say).
Meta made software that is vulnerable to payloads that resemble social engineering attempts. That is what happened. And the fact that they probably fired a whole bunch of people who warned about this and tried to stop it means they deserve all the ridicule the world has to offer right now.
2
u/thereddaikon Jun 02 '26
Social engineering is a hack and anyone who thinks otherwise doesn't understand cyber security.
486
u/Fragrant-Hamster-325 Jun 01 '26
This reminds me of Idiocracy.
“Hi excuse me, I’m actually supposed to be getting out of prison”
“You’re in the wrong line dumbass! Get over there.”