Indonesian Political, Business & Finance News

Beware of New Fraud Method: Social Media Accounts Vanish Instantly

| Source: CNBC Translated from Indonesian | Technology
Beware of New Fraud Method: Social Media Accounts Vanish Instantly
Image: CNBC

Amidst the rapid development of AI by global giants, the technology has become a new tool for fraud, capable of making social media accounts disappear instantly. This scam targets Meta’s AI support chatbot, with cybersecurity experts stating that perpetrators have found loopholes to hack numerous Instagram accounts.

The attack, known as ‘prompt injection’, is carried out by providing manipulative instructions. Subsequently, the AI chatbot grants access to the criminals, according to Reuters. The AI tool is deemed unable to distinguish between the actual account owner and the fraudster, as it can be persuaded to reset account credentials without performing independent identity verification.

As a result, malicious actors can easily exploit users’ social media accounts or even delete them permanently. This case highlights vulnerabilities in AI systems, particularly when companies grant extensive authority to AI for tasks such as account recovery.

These findings emerge as Meta focuses heavily on AI. To meet its ambitions, the company has increased AI investment, conducted layoffs of thousands of workers, and pledged US$145 billion towards AI infrastructure. Meta has since ensured that the issue has been resolved and is working to secure the affected accounts.

Brian Westnedge, Vice President of Alliances and Partnerships at cybersecurity firm Red Sift, offered sharp criticism regarding the incident. He noted that the case represents a fundamental architectural failure, where AI models are granted special privileges without the same access controls.

“Meta faces ongoing criticism due to a lack of human support, massive layoffs, and spending billions of dollars on AI. This incident occurs amidst all three,” he explained.

One of the hacking victims, Jane Wong, a former Meta employee and security researcher, stated it took 5 to 10 minutes to reactivate her account. Wong explained that her account password was suddenly changed without her knowledge, and simultaneously, she received several password reset requests.

View JSON | Print