"Meta notified at least 20,225 people that their accounts had been compromised. [...] The compromises allowed the hackers to take over the person's entire Instagram and any linked accounts, including obtaining contact information, dates of birth, and profile information, as well as the ability to access the person's posts, direct messages, and account activity [...] the hacks began around April 17 and lasted until th…
Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot
131–140 of 287 posts
Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot
#132Earlier quoted context omitted.
I’m guessing they have no functional human support for the people who had their accounts stolen. I get the impression Meta didn’t know this was happening until they were contacted by the media.
> no functional human support I've seen some reporting saying exactly that. [0] It might be a "first-world problem", but having an account lost without appeal can justly be labeled "traumatic", especially if post-COVID it represents a majority of your social (or para-social) life. [0] https://www.404media.co/hackers-simply-asked-meta-ai-to-give...
Also possibly illegal under GDPR section 22.
Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot
#133"Meta notified at least 20,225 people that their accounts had been compromised. [...] The compromises allowed the hackers to take over the person's entire Instagram and any linked accounts, including obtaining contact information, dates of birth, and profile information, as well as the ability to access the person's posts, direct messages, and account activity [...] the hacks began around April 17 and lasted until th…
No fan of Meta, but I think "staggering" is properly determined by the percent of users affected rather than the absolute number. It's staggering to an SMB with 100k customers; it's bad, but not "staggering" to an internet juggernaught with 3B MAU.
Meta in a fair world should be forced to financially compensate these people. They built a world where many people basically have to use their products for their jobs and then failed to look after the data because they wanted to replace customer support with a vibe coded AI tool.
Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot
#134Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot
#135Earlier quoted context omitted.
One can only hope EU gives them a GDPR fine very close to the limit of 4% of global turnover. But when EU is actually need to protect customer I think they will fail.
Incidents like this show how unenforceable GDPR is, and how it's been a net negative for users since its inception. It's idealogical back-patting, toothless when it matters.
Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot
#136Earlier quoted context omitted.
That seems like a false-dichotomy between two extremes when there's all sorts of space in the middle... It's also assuming developer-to-developer tools would have the same rules and exposure as in service-to-consumer. If I sell a physical motor (let alone plans for one) I'll have some liability for things like it Not Exploding. If someone buys a dozen of those motors to assemble a tragically unsafe "rollercoaster" of…
Exactly this. (and it is a false dichotomy to argue infinite liability). To Terr_'s point, if you were publishing open source you would also publish exactly the things you intended it to be used for and anything else would violate your warranty (possibly implied) that it does what the documentation says it does. There is a huge amount of tort law that covers exactly when it becomes a problem for you the creator vs yo…
Nobody's going to be distributing software on the internet for free if the cost of insurance alone precludes that.
Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot
#137Earlier quoted context omitted.
Exactly this. (and it is a false dichotomy to argue infinite liability). To Terr_'s point, if you were publishing open source you would also publish exactly the things you intended it to be used for and anything else would violate your warranty (possibly implied) that it does what the documentation says it does. There is a huge amount of tort law that covers exactly when it becomes a problem for you the creator vs yo…
Software can be copied infinitely, so even $1 of liability is effectively infinite since an unlimited number of people can potentially use it and sue you when it blows up. Nobody's going to be distributing software on the internet for free if the cost of insurance alone precludes that.
Guess what, I'm not liable for the damage. Why? Because I immediately responded once I knew that it could, I made a good effort to warn people who might already have the code of the risk, and I made it clear in the code that this risk is there.
Ever wonder why you get a booklet of warnings when you buy a product with even really stupid things like "Don't clean with gasoline" warnings? That's because once you have discharged your duty to warn you are not longer liable in what happens if someone ignores your warning.
The flip side is also true, you cannot say in your product both "Hey this product does these cool things" and "We don't warrant the product to actually do anything." This is especially true if there is money involved (like your user paid your some $ for the product.) There is always an implied warranty that the thing will do what you says it will do, which exists as long as the user has heeded all your warnings.
Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot
#138Meanwhile an account I created for a new product was permanently disabled by an automated system with no path for me to appeal to a human. (If anyone at Meta/Instagram sees this I wrote a brief blog post with the details. Please help! https://addisonwebb.com/blog/2026-06-05-Can%20Someone%20at%2... )
This is extremely common, unfortunately, to a point where it's a known/expected outcome when you're first creating a brand or product page among those in the biz. If this doesn't work, I'd encourage you to reach out to a brand/ad agency and pay them $100 to ask their meta contact to help you get unblocked. You pretty much have to know someone who knows someone at meta in order to create these. Tip: Do not post about…
Can also try here:
Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot
#139Earlier quoted context omitted.
Both this and what Meta said reminds me of "Clarke and Dawe - The Front Fell Off" ( https://www.youtube.com/watch?v=3m5qxZm_JqM ) I also can't believe the people who were involved with writing this response from Meta, didn't realize how obviously bad it sounds. It's like there is no humans working and writing there anymore.
I was reminded of the Murray Walker quote. “There's nothing wrong with the car except it's on fire”
Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot
#140Earlier quoted context omitted.
The tool worked correctly and as intended, but due to a bug it did not work correctly nor as intended.
Sounds like they are saying the agent did not malfunction, and this vuln could have been triggered by a human support agent too.
But it’s irrelevant, outside of PR. We know at least THREE bad components to this process and they were constituent parts.