logo

Hacking Meta’s AI Chatbot

ID: c8191290-37c7-5f4d-92bc-d367ef90fffb

STIX ID: report--c8191290-37c7-5f4d-92bc-d367ef90fffb

Feed Name: Schneier on Security

Threat Score
55/100

Date Published: 2026-06-04

Date Updated: 2026-06-04

Author: Bruce Schneier

...
...

Hackers demonstrated an account-takeover technique that exploited Meta’s AI support chatbot to add an attacker-controlled email, accept a verification code, and trigger a password reset for Instagram accounts; a video showed the step-by-step process. Meta stated the issue has been fixed, but the report does not indicate how many users were affected. The incident highlights risks of delegating sensitive account-recovery actions to LLM-based chat interfaces.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.