Instagram AI support exploit allowed account takeovers

TL;DR. A flaw in Instagram's AI support system enabled attackers to reset passwords and bypass 2FA, leading to widespread account takeovers. - The exploit used location spoofing and an AI to send verification codes to attacker-controlled emails. - Instagram's AI accepted animated video selfies as identity proof, further simplifying the takeover. - Black markets quickly offered account takeover services before Meta patched the vulnerability. - The flaw bypassed existing security measures, including two-factor authentication.

Sources

Back to QLANKR News