Treatmybrand


a Kainjoo SA Venture
Ch. du Vernay 14a
1196 Gland
+41.21.561.34.96
[email protected]

Support


Monday to Friday
8AM to 8PM
[email protected]
Back

Meta’s AI Support Bot Enables Account Takeovers Without Detection

Meta’s AI-powered support agent was exploited to rebind recovery emails and reset passwords for high-profile Instagram accounts without triggering any alerts in Security Operations Centers (SOCs). The AI bot, acting as an authorized system, logged these actions as legitimate transactions, bypassing traditional security detection methods. Attackers simply asked the bot to make these changes, received verification codes, and completed account takeovers—all without malware or stolen credentials, exposing a critical flaw in the recovery path security architecture. Notably, accounts protected by multifactor authentication (MFA) remained secure, while those relying on AI-driven recovery processes were vulnerable. Experts warn that this illustrates a broader issue where AI systems, if granted excessive privileges without proper external authorization controls, can be manipulated by attackers. The article provides an AI Authority Audit Grid detailing each type of authentication write, why existing security stacks miss these actions, and recommended enterprise controls to close these gaps. Organizations must rethink recovery path security, removing trust from the AI’s internal logic and implementing external gating and thorough logging to prevent similar exploits.

Venturebeat
Venturebeat