Live data from Hacker News

Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

this.weekinsecurity.com

161–170 of 287 posts

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#161

Earlier quoted context omitted.

No fan of Meta, but I think "staggering" is properly determined by the percent of users affected rather than the absolute number. It's staggering to an SMB with 100k customers; it's bad, but not "staggering" to an internet juggernaught with 3B MAU.

Twenty _thousand_ people had their personal data stolen, many of them relied on these accounts to run their business, many put at risk of hackers impersonating them. Meta in a fair world should be forced to financially compensate these people. They built a world where many people basically have to use their products for their jobs and then failed to look after the data because they wanted to replace customer support…

[flagged]

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#162
post #3

> "The tool itself worked properly and functioned as intended; however due to a bug in a separate code path, the system did not properly verify that the email address provided by the individual requesting a password reset matched the email address associated with that user’s Instagram account," said Meta in its breach notice. I'm not sure "worked properly" and "as intended" accurately describe this situation.

Our autonomous client-assistance system is managed by a teenager that usually makes good decisions but sometimes makes bad decisions and so all the teenager’s decisions are checked by a minder before being implemented. Unfortunately the minder wasn’t paying attention, so, here we are. However, our teenager is a great kid and did nothing wrong! It’s all the minder’s fault.

P.S. Would you like to have our teenager manage your system too? Terms are reasonable! Of course you accept all liability, so better get a good minder - and no, don’t use an AI as the minder, that just introduces a new failure mode.

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#163
post #29

Meanwhile an account I created for a new product was permanently disabled by an automated system with no path for me to appeal to a human. (If anyone at Meta/Instagram sees this I wrote a brief blog post with the details. Please help! https://addisonwebb.com/blog/2026-06-05-Can%20Someone%20at%2... )

> Meanwhile an account I created for a new product Meta requires the main account to be created for a person, not a product, business, or non-human entity. That's why you got hit with the "Please confirm you are a human" confirmation and then the account was locked for violating community standards, which require primary accounts to be people. The community standards page in the links they sent you are pretty dense a…

I’m sorry, but this should have been made clear in the registration process by Meta and not have entered this dead path at all. Tell me it looks like bad engineering and that together with poor customer support is a reputational damage in the long-term. Not that they have good reputation but it’ll only get worse

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#164
post #129

Earlier quoted context omitted.

Incidents like this show how unenforceable GDPR is, and how it's been a net negative for users since its inception. It's idealogical back-patting, toothless when it matters.

After the GDPR every website added an option to export your personal data and to delete your account. Something most were missing at the time. It was an immediate and massive win.

Right, but nothing stops companies from refusing SARs on baloney grounds. Complain to a DPA? They tell you to go through ADR or outright ignore you. Complain to Ombudsman? They'll tell you the same. (In my experience, the Dutch do this)

Company ignores ADR? Sure, now you can go through the legal route and spend copious amounts of money all because a multi billion dollar company knows the game and how to navigate the bureaucratic mess better than you.

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#166

Earlier quoted context omitted.

Well, these hacks targeted large influencer accounts. It could have more severe impact than 20k randomly selected accounts.

Large influencer accounts without two factor authentication... The only useful reaction to this is to point and laugh.

Also large influencers who cannot influence much without Meta's platforms... they will simply not complain too much about it if they like their "job".

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#167
post #99

Earlier quoted context omitted.

Read that as "worked as written" and "we disclaim any consequential or incidental damages and do not warrant this software." I continue to believe we could fix a lot of things in the US if we updated the UCC[1] to disallow 'disclaiming liability on software used in a product.' [1] Universal Commercial Code -- https://www.law.cornell.edu/ucc

I've always wanted to expose myself to unlimited legal liability by distributing open source software.

Ensuring Meta is responsible for its products would not need to assign liability to someone offering open source software.

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#168

Earlier quoted context omitted.

Exactly this. (and it is a false dichotomy to argue infinite liability). To Terr_'s point, if you were publishing open source you would also publish exactly the things you intended it to be used for and anything else would violate your warranty (possibly implied) that it does what the documentation says it does. There is a huge amount of tort law that covers exactly when it becomes a problem for you the creator vs yo…

Software can be copied infinitely, so even $1 of liability is effectively infinite since an unlimited number of people can potentially use it and sue you when it blows up. Nobody's going to be distributing software on the internet for free if the cost of insurance alone precludes that.

[flagged]

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#169
post #3

> "The tool itself worked properly and functioned as intended; however due to a bug in a separate code path, the system did not properly verify that the email address provided by the individual requesting a password reset matched the email address associated with that user’s Instagram account," said Meta in its breach notice. I'm not sure "worked properly" and "as intended" accurately describe this situation.

‘Hey Claude, write me a PR statement’

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#170
post #60

Earlier quoted context omitted.

Both this and what Meta said reminds me of "Clarke and Dawe - The Front Fell Off" ( https://www.youtube.com/watch?v=3m5qxZm_JqM ) I also can't believe the people who were involved with writing this response from Meta, didn't realize how obviously bad it sounds. It's like there is no humans working and writing there anymore.

> It's like there is no humans working and writing there anymore. Don't know if AI is to blame, but I've used to see these kinds of nonsense post-mortems even in the pre-llm era, and it's always due to some internal fighting ongoing between various departments.

Where do you think the LLMs learned it from...
Post reply on HN