Meta’s Chatbot Hijack Offers Warning To Enterprise IT
A recent security incident at Meta may look like just another social media hack. It’s not.
Earlier this week, reports surfaced that attackers took over Instagram accounts by exploiting Meta’s AI-powered support chatbot—not by stealing passwords, but by manipulating its automated account recovery process.
Meta has since patched the flaw, but the incident exposes a broader issue: AI-driven automation is increasingly being embedded in sensitive operational workflows without always inheriting the security rigor those workflows require.
As Sumsub’s Mick Amelishko put it in an email to MES Computing, “Account recovery and credential changes are effectively ownership transfers. If they can be triggered without robust identity verification, they become a direct attack surface.”
That’s the takeaway for midmarket IT leaders.
This wasn’t a breach of infrastructure or a malware campaign. It was a failure in design, where an AI system handling identity-related requests did not enforce strong verification controls. In some cases, the chatbot acted on user prompts without adequately confirming account ownership, as MacRumors.com reported.
For organizations deploying AI in help desks, customer support or IT operations, the implications are immediate. AI systems are no longer limited to answering questions—they are increasingly executing actions, including password resets, account changes and other sensitive tasks.
“Any AI that can modify account ownership or recovery details must treat those requests as high-risk events,” Amelishko said, pointing to the need for stronger identity checks and behavioral validation.
MES Computing has previously reported on the rapid expansion of AI across IT operations and customer-facing systems, often prioritizing speed and efficiency. This incident underscores the downside of that trade-off.
The risk isn’t social media account hijacking. It’s giving automated systems authority without the controls to match.