Live data from Hacker News

Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

this.weekinsecurity.com

91–100 of 287 posts

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#92

Earlier quoted context omitted.

Lazy can be a good thing. Since time and attention are finite and not fungible, it allows you to do something else. There's a reason we're all too lazy to do long arithmetic with pen and paper, instead relieving the burden of using our minds by outsourcing to spreadsheets and calculators. Not only does it allow us to think at a higher level of abstraction, but it also means we can take our kids to the park more often…

https://thethreevirtues.com paraphrases something Larry Wall wrote in Programming Perl : > If we’re going to talk about good software design, we have to talk about Laziness, Impatience, and Hubris, the basis of good software design. sourced from https://bcantrill.dtrace.org/2026/04/12/the-peril-of-lazines... , where Bryan Cantrill makes the point that: > The problem is that LLMs inherently lack the virtue of laziness…

I don't believe this is true.

Remember the "ChatGPT lazy winter" 2 years ago? (https://hn.algolia.com/?dateRange=all&page=1&prefix=true&que... )

That was truly "lazy", as in "yo... I'm not interested in doing this so I'll half-ass it or just tell someone else to do it".

The kind of "lazy" that is mentioned in your quote is "I don't want to add work to future me's life". I don't think "lazy" is the right word for it.

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#93
post #29

Meanwhile an account I created for a new product was permanently disabled by an automated system with no path for me to appeal to a human. (If anyone at Meta/Instagram sees this I wrote a brief blog post with the details. Please help! https://addisonwebb.com/blog/2026-06-05-Can%20Someone%20at%2... )

I tried creating an entirely separate account for a meetup group and had the same problem. Nothing I tried worked.

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#94
Yet another reminder that most of these chatbots get shipped way before they're ready. Loud marketing, security treated as an afterthought, all to ride the AI hype. LLMs open up a whole new attack surface and a lot of teams still treat prompt injection like a fun edge case. This is what happens when you ship the demo instead of the product.

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#96
post #57

By "abusing" they mean "using"

No, it's still abuse. Just like it's still stealing even if I left my front door unlocked.

The appropriate metaphor would rather be your landlord deciding to renovate the entire back wall of your apartment/house to make it an open-air design.

People coming in from the street to hang out and rifle through your belongings would still be "abusing" the system according to the law, but it's hard to not consider the landlord somewhat responsible.

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#97
post #3

> "The tool itself worked properly and functioned as intended; however due to a bug in a separate code path, the system did not properly verify that the email address provided by the individual requesting a password reset matched the email address associated with that user’s Instagram account," said Meta in its breach notice. I'm not sure "worked properly" and "as intended" accurately describe this situation.

> The tool itself worked properly and functioned as intended

The author of the post is close to the author of the AI code on the org chart

> however due to a bug in a separate code path, the system did not properly verify

The author of the post is far from the author of this "code path" on the org chart

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#98

"abusing" by using it's built in insecurity to do insecure things. It's like, people abusing an open door. "Guys, just because we left the door open to your bedroom doesn't mean we're responsible". God can only hope this is a business ending lawsuit.

> God can only hope this is a business ending lawsuit.

You realize this is the company that enabled a genocide and got away with it? Not to mention accelerating teenager suicides with full knowledge.

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#99
post #3

> "The tool itself worked properly and functioned as intended; however due to a bug in a separate code path, the system did not properly verify that the email address provided by the individual requesting a password reset matched the email address associated with that user’s Instagram account," said Meta in its breach notice. I'm not sure "worked properly" and "as intended" accurately describe this situation.

Read that as "worked as written" and "we disclaim any consequential or incidental damages and do not warrant this software." I continue to believe we could fix a lot of things in the US if we updated the UCC[1] to disallow 'disclaiming liability on software used in a product.' [1] Universal Commercial Code -- https://www.law.cornell.edu/ucc

I've always wanted to expose myself to unlimited legal liability by distributing open source software.

Re: Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot

#100
post #5

Earlier quoted context omitted.

> Date(s) Breach Occured: 04/17/2026 > Date Breach Discovered: 05-31-2026

I’m guessing they have no functional human support for the people who had their accounts stolen. I get the impression Meta didn’t know this was happening until they were contacted by the media.

> no functional human support

I've seen some reporting saying exactly that. [0]

It might be a "first-world problem", but having an account lost without appeal can justly be labeled "traumatic", especially if post-COVID it represents a majority of your social (or para-social) life.

[0] https://www.404media.co/hackers-simply-asked-meta-ai-to-give...

Post reply on HN