Meta recovery tool abused for account takeover
Meta disclosed that 20,225 Instagram accounts may have been compromised after attackers abused a vulnerability in an AI-assisted Instagram account recovery support tool. The issue allowed an attacker-supplied email address to receive password reset links for accounts the attacker did not own, and accounts without two-factor authentication could then be taken over. BleepingComputer reports that Meta discovered the exploitation on 31 May, disabled the affected support system, regenerated reset links, forced potentially affected accounts through a security checkpoint, and said it would review similar recovery flows across Meta platforms.
What this means for your organisation
The case shows that the recovery flow is often the weakest part of the login. An organisation can have strong password requirements and sound access management and still lose an account through a support process designed to help locked-out users. For organisations with corporate social media accounts, the consequence is loss of control over a communication channel, with reputational risk and possible fraud aimed at customers.
Berigo recommends
- Enable two-factor authentication on all corporate social media accounts, with no exception for shared accounts.
- Review which email addresses and phone numbers are registered as recovery channels, and remove private addresses belonging to former employees.
- Assess the recovery processes in your own customer-facing services with the same scrutiny as the login itself.
- Have a predefined plan for who notifies customers and media if an official channel is taken over.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch