Live data from Hacker News

Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

this.weekinsecurity.com

171–180 of 287 posts

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#172

"Meta notified at least 20,225 people that their accounts had been compromised. [...] The compromises allowed the hackers to take over the person's entire Instagram and any linked accounts, including obtaining contact information, dates of birth, and profile information, as well as the ability to access the person's posts, direct messages, and account activity [...] the hacks began around April 17 and lasted until th…

No fan of Meta, but I think "staggering" is properly determined by the percent of users affected rather than the absolute number. It's staggering to an SMB with 100k customers; it's bad, but not "staggering" to an internet juggernaught with 3B MAU.

No. Percentages allow them to hide in the law of averages. Go tell those twenty thousand people that it's banal that Meta fucked up like this.

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#173
Has the data surfaced somewhere? A lot of IG accounts are private by choice, and this kind of data, if surfaced publicly, could have devastating privacy violations. People share all kinds of stuff on there, a lot of it not meant for public consumption. I'm not wanting a debate on "well you shouldn't put anything private on Facebook's servers or the internet blah blah blah". I'm just curious if the actual contents of the hack have been surfaced.

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#174

Earlier quoted context omitted.

Well, these hacks targeted large influencer accounts. It could have more severe impact than 20k randomly selected accounts.

Large influencer accounts without two factor authentication... The only useful reaction to this is to point and laugh.

No. Meta's account recovery flow disables 2FA. It's idiotic. 2FA for Meta accounts serves no beneficial purpose.

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#175

This was on hacker news a few days ago ( https://news.ycombinator.com/item?id=48359102 ) - description of the “hack”, not the cockamamie confirmation by Meta.

This is wild. How did anyone approve this architecture. You should never give your LLM privileged access the current user doesn't have access to. Even if you're not logged in the LLM's tool calls should only be able to access the same flow you would, as in: be able to send a password reset email to your own email! This is like if you had a password reset page for your profile and had a email field you could fill in to have it sent to any email LOL.

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#176

Earlier quoted context omitted.

Over forty _thousand_ people die every year in the US from car accidents. Plenty of other preventable injustices happen in all areas of life. I wonder how many fathers are unjustly taken away from their children by a corrupt family court system, how many people die of treatable diseases denied treatment by insurance companies, how many kids lose interest in school because of bad teachers, how many customer service wo…

The US car deaths stat is also completely insane and way higher than other countries. I can recognize that at scale, securing every account is a very difficult task, but with scale comes responsibility. Meta plays fast and loose rushing in unsupervised vibeslop agents to save a penny. They should be significantly penalized for such a massive failure, particularly for how long this exploit was live and for how the vic…

way higher than other countries

You must live in Monaco.

Wikipedia has the United States #80.

https://en.wikipedia.org/wiki/List_of_countries_by_traffic-r...

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#177
post #3

> "The tool itself worked properly and functioned as intended; however due to a bug in a separate code path, the system did not properly verify that the email address provided by the individual requesting a password reset matched the email address associated with that user’s Instagram account," said Meta in its breach notice. I'm not sure "worked properly" and "as intended" accurately describe this situation.

Having had my 2FA Facebook account banned 3 years ago because a bot signed up under my email for Instagram (which I did not have), I can confidently say the email verification issue has been a problem for a long time at Meta.

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#178
post #29

Meanwhile an account I created for a new product was permanently disabled by an automated system with no path for me to appeal to a human. (If anyone at Meta/Instagram sees this I wrote a brief blog post with the details. Please help! https://addisonwebb.com/blog/2026-06-05-Can%20Someone%20at%2... )

> Meanwhile an account I created for a new product Meta requires the main account to be created for a person, not a product, business, or non-human entity. That's why you got hit with the "Please confirm you are a human" confirmation and then the account was locked for violating community standards, which require primary accounts to be people. The community standards page in the links they sent you are pretty dense a…

> Sorry you didn't know this before going through the process, but it's important to read the proper channels for setting up business pages on all of the social media platforms these days.

This is exactly why Meta and other large companies need to be regulated with anti-trust regulations really soon. This whole "whoops sorry you didn't know, but it's a private company" thing only works if there are 5-6 other competitors you can go to that will take your business.

Meta is a de facto monopoly for a lot of small businesses; and should either be broken up or be subject to a ton of utility-style regulation.

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#179

Earlier quoted context omitted.

Software can be copied infinitely, so even $1 of liability is effectively infinite since an unlimited number of people can potentially use it and sue you when it blows up. Nobody's going to be distributing software on the internet for free if the cost of insurance alone precludes that.

This is not how liability works, anywhere. So I write a piece of code that "makes your screen do cool things" and it causes the power supply to fail on those screens. Someone reports that bug to me and I check it out and say "Oh, shit it does break power supplies." Then I immediately put a notice on and in the code that says "WARNING: This code will break the power supply of your montitor." And I put that warning in…

I broadly agree with you but TBF to the earlier comment consider what would happen if a FOSS author did something wrong and was found to be liable. How about curl for example? That sees use in car infotainment systems among other things and cars can be pretty expensive and there sure are an awful lot of them. The point is that we should be able to accommodate someone pushing a hobby project to github under a permissive license while also imposing liability against developers in instances where money changes hands or where someone's work involves interacting with the physical world.

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#180

Earlier quoted context omitted.

Well, these hacks targeted large influencer accounts. It could have more severe impact than 20k randomly selected accounts.

Large influencer accounts without two factor authentication... The only useful reaction to this is to point and laugh.

I think the hack bypassed 2FA. If you can call “asking for account access” a hack lmao
Post reply on HN