This Meta AI Support Assistant account takeover flow is so out of control. Allowing an AI Support Assistant to process IG account recovery flows and bypass 2FA?! Wish I played with it before it was patched today.
Attackers claim ATO flow is:
- Forgot password >
- Click "Account is Hacked" >
- VPN match victim location (OSINTable/on IG itself) >
- Some claim verification with AI-created video injectable selfie >
- Change account to attacker controlled email >
- Password reset link goes to attacker controlled email >
2FA is bypassed, attacker now owns IG account. System overloaded and hard to recover as true account owner.
Actually mind boggling.
Today Instagram had this massive exploit where hackers were just stealing rare handles left and right. Hundreds of accounts gone.
People losing handles theyāve owned since 2010, some worth hundreds of thousands.
I own a few rare ones so I was actually stressed watching this happen in real time, which I havenāt been in years.
Obama White House account got hit.
These arenāt some random new accounts, these are verified, locked down accounts and they still got compromised.
The thing is the exploit is so simple itās almost funny. Attacker goes to Forgot Password, says their account is hacked, turns on a VPN to match the targetās location (which now you can find on the about section of the page).
Instagramās AI support flow asks them to verify with a selfie.
They grab a photo from the targetās profile, run it through an AI video generator to make an animation of the personās face moving around, upload that to Metaās AI as proof.
And Metaās AI just accepts it because it canāt tell the difference between a real selfie and an AI-generated video of someoneās face
.
Once verified they change the email to theirs. Password reset link goes to their email. They own it now. 2FA gets bypassed somehow in the process but honestly I donāt know exactly how, just that it did.
Point is even locked down accounts went down.
Then you try to recover your account and youāre talking to a chatbot that has zero ability to help.
You canāt escalate to a human. Youāre just stuck. Your asset is gone and thereās no one to call.
The whole thing just highlighted how stupid it is to automate account security without any human in the loop.
One AI fooling another AI while thereās literally no person anywhere to catch it.
Meta took hours to even acknowledge it while accounts were getting stolen every minute.
Now thankfully itās patched but I donāt think it will be the last one. Stay safe!