The newest Instagram “exploit” is the goofiest I've seen

TL;DR

Hackers exploited a basic flaw in Instagram’s account recovery system, using AI support to bypass security with minimal effort. High-profile accounts were affected, but the method appears to have been patched. The incident highlights vulnerabilities in automated support systems.

Instagram’s latest account recovery exploit, which allowed attackers to hijack high-profile accounts with minimal effort, has been publicly reported and appears to have been patched by Meta. The vulnerability involves abusing the platform’s AI support system to reset account access without traditional verification steps.

According to reports from Hacker News, attackers could initiate account takeovers by simply providing the account username and convincing Instagram’s AI support system that the account was hacked. The attacker would then request a verification code to be sent to an email they control, which the AI would relay without thorough checks. This process bypassed two-factor authentication and other security measures, allowing full account control. Notably, the attack only required minimal information and was facilitated by the support AI’s leniency, making it surprisingly easy to execute. High-profile accounts, including the Obama White House account and others linked to notable figures, were targeted during this period. The method exploited a flaw in the support flow, which lacked robust verification, and was active for weeks before Meta addressed the vulnerability. Black markets on Telegram offered services to carry out these takeovers quickly and at high cost, reflecting the lucrative nature of account theft.

Why It Matters

This incident underscores significant security gaps in automated recovery systems used by major platforms like Instagram. The ease with which accounts can be hijacked raises concerns about the safety of user data, especially for high-profile accounts. It also highlights the risks of relying heavily on AI support tools that may lack sufficient verification protocols. For users and organizations, this incident emphasizes the importance of multi-layered security measures beyond simple AI-based support flows.

Amazon

two-factor authentication security key

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Background

In recent years, social media platforms have faced increasing scrutiny over account security. While two-factor authentication and other measures are standard, vulnerabilities in automated support systems have occasionally surfaced. This specific exploit was active for several weeks before being patched, demonstrating how attackers can quickly adapt and exploit weak points in platform support mechanisms. The incident follows previous reports of security flaws in automated account recovery processes across various platforms, but this case stands out for its simplicity and the high-profile accounts affected.

“This is the most unserious, ‘almost too stupid to be true’ exploit I’ve seen. All the attacker needs is the username and some social engineering to fool the AI support.”

— Hacker News user

“The vulnerability exposes a fundamental flaw in Instagram’s support AI, which can be manipulated with minimal effort and no additional verification.”

— Security researcher

Amazon

multi-factor authentication hardware token

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

What Remains Unclear

It is not yet clear whether Instagram has fully closed the vulnerability or if there are still variants of the exploit in use. Details about the scope of affected accounts and whether other platforms have similar vulnerabilities remain undisclosed. The long-term security implications are still being assessed by Meta.

Amazon

email verification security device

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

What’s Next

Meta is expected to implement more rigorous verification protocols within its support AI and account recovery processes. Monitoring for further exploits or reports of compromised accounts will continue, and affected users are advised to review their account security settings. Further updates from Meta are anticipated as they assess and address the vulnerability.

Amazon

account recovery security tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

How did attackers hijack high-profile Instagram accounts?

They exploited a flaw in Instagram’s AI support system that allowed them to reset account access by requesting verification codes without proper checks, simply by providing the username and convincing the AI the account was hacked.

Has Instagram fixed this vulnerability?

According to reports, Meta has patched the flaw, but it is unclear if all variants of the exploit are completely closed or if some accounts remain vulnerable.

Can two-factor authentication prevent this type of attack?

Normally, 2FA adds a layer of security, but in this case, the attack bypassed it entirely because the AI support process treated the recovery as a full reset, revoking existing sessions and changing email addresses without requiring 2FA verification.

Are other social media platforms vulnerable to similar exploits?

While this specific method was observed on Instagram, similar vulnerabilities could exist on other platforms that rely heavily on AI support systems for account recovery. Ongoing security reviews are necessary to identify and mitigate such risks.

What should users do to protect their accounts?

Users should review their account security settings, enable two-factor authentication where possible, and monitor account activity for suspicious access or changes.

Source: Hacker News

You May Also Like

Google workspace threatening to block Firefox access

Google Workspace is beginning to warn Firefox users they may soon lose access, prompting a shift to Chrome for Business Plus accounts.

Protocol Prying: Vulnerability Research in AirDrop and Quick Share

Researchers reveal six vulnerabilities in Apple AirDrop, Samsung Quick Share, and Google Quick Share, exposing potential zero-click attack vectors.

Meta is facing another lawsuit over scam ads on Facebook and Instagram

Santa Clara County has filed a lawsuit against Meta, alleging the company profits from scam ads that target vulnerable users, including seniors.

EY sacks graduate employee after he allegedly accessed Australian PM’s bank account

An EY employee was dismissed after allegedly accessing Australian Prime Minister Albanese’s bank account, with charges laid in court on May 6.