
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
Hackers exploited a vulnerability in Meta's AI-powered support chatbot on Instagram, tricking it into resetting passwords and bypassing identity verification. This allowed unauthorized access to high-profile accounts, including those of public figures and brands, highlighting significant security risks in AI-driven account recovery systems.[AI generated]
Why's our monitor labelling this an incident or hazard?
The event involves an AI system explicitly (Meta's AI customer service chatbot) and describes a malfunction in its security logic that directly caused harm by enabling hackers to take over user accounts. The harm includes unauthorized access to personal data and control over accounts, which constitutes harm to property and potential violation of user rights. The incident has already occurred and been confirmed by Meta, with remediation underway. Therefore, this qualifies as an AI Incident rather than a hazard or complementary information.[AI generated]