메뉴
BL
The Decoder 50일 전

메타, 인스타 AI 챗봇 해킹으로 2만 개 계정 유출

IMP
8/10
핵심 요약

메타의 인스타그램 계정 복구용 AI 지원 챗봇에서 심각한 보안 취약점이 발견되어 약 7주 동안 최대 20,225개의 계정이 해킹되었습니다. 해커들은 시스템 내 이메일 주소 확인 로직의 버그를 악용해 승인되지 않은 임의의 이메일로 비밀번호 재설정 링크를 발송하는 방식으로 계정을 탈취했습니다. 메타는 해당 챗봇을 즉시 비활성화하고 조치를 완료했으며, 모든 플랫폼의 유사 시스템 전면 감사를 진행할 계획입니다.

번역된 본문

인스타그램 AI 챗봇 해킹으로 2만 개 이상의 계정에 영향을 미쳤다고 메타가 밝혔다.

핵심 요약

  • 메타의 AI 지원 챗봇 결함으로 인해 약 7주 동안 최대 20,225개의 인스타그램 계정이 탈취되었습니다.
  • 오류가 있는 복구 도구로 인해 해커들이 확인되지 않은 임의의 이메일 주소로 비밀번호 재설정 링크를 보낼 수 있었습니다.
  • 메타는 챗봇을 비활성화하고, 조작된 링크를 무효화했으며, 영향을 받은 사용자에게 즉시 비밀번호 재설정을 강제했습니다.

공식적인 데이터 유출 알림에서 메타는 AI 지원 챗봇에서 이미 알려진 취약점의 규모에 대해 처음으로 구체적인 수치를 공개했습니다. 이 해킹 캠페인은 약 7주 동안 진행되었습니다.

메타는 미국 메인주 법무장관실에 데이터 유출 알림을 제출하며 인스타그램 계정을 표적으로 한 해킹 캠페인에 대한 첫 구체적인 피해 규모를 공개했습니다. 메인주의 30개 계정을 포함하여 최소 20,225개의 계정이 해킹된 것으로 확인되었습니다.

해커들은 수개월 동안 메타의 AI 기반 인스타그램 지원 챗봇을 악용해 타인의 계정을 탈취했습니다. '하이 터치 서비스(High Touch Support)'라는 계정 복구 도구인 이 챗봇은 잠긴 사용자가 접근 권한을 되찾도록 돕기 위해 설계되었습니다. 그러나 별도의 코드 경로에 있던 버그로 인해 시스템은 제공된 이메일 주소가 실제 해당 인스타그램 계정의 것인지 확인하는 절차를 건너뛰었습니다.

해당 알림에 따르면, 공격은 2026년 4월 17일경 시작되어 5월 31일이 되어서야 발견되었습니다. 공격자들은 AI 기반 '하이 터치 서비스' 복구 시스템에서 이미 알려진 취약점을 악용했습니다. 이 시스템은 계정과 일치하는지 여부를 확인하지 않은 채 모든 이메일 주소로 비밀번호 재설정 링크를 보냈던 것입니다.

메타는 20,225개라는 수치가 상한선이라고 밝혔습니다. 일부 접근 시도는 합법적인 계정 소유자에 의한 것일 수 있기 때문입니다. 잠재적으로 노출될 수 있었던 데이터에는 연락처 정보, 생년월일, 게시물, 다이렉트 메시지(DM), 계정 활동, 프로필 정보 및 연결된 서비스가 포함됩니다. 메타는 실제로 어떤 정보가 열람되었는지 알 수 없다고 밝혔습니다.

보안 매체 Thisweekinsecurity가 이번 데이터 유출 알림을 처음으로 보도했습니다.

메타, 챗봇 비활성화 및 모든 플랫폼 감사 착수 즉각적인 대응 조치로 메타는 AI 챗봇을 비활성화하고 오류가 있는 코드 경로를 제거했으며, 해당 시스템을 통해 생성된 모든 비밀번호 재설정 링크를 무효화했습니다. 또한 영향을 받은 사용자들에게 필수 보안 확인 절차를 거치도록 하고, 검증된 채널을 통해 비밀번호를 재설정하도록 요청했습니다.

메타는 이 도구를 재활성화하기 전에 복구 프로세스의 이메일 확인 단계를 수정하고 모든 플랫폼에서 유사한 계정 복구 시스템을 전면 감사할 계획입니다.

이번 사건은 메타가 수천 명의 직원을 해고하면서 AI에 막대한 투자를 진행하고 있는 시기에 발생했습니다. 특히 이 AI 지원 챗봇은 이전에 메타가 계정 보안 강화를 위한 성과로 마케팅했던 바가 있어 더욱 큰 파장이 예상됩니다.

원문 보기
원문 보기 (영어)
Instagram AI chatbot breach may have affected over to 20,000 accounts, Meta discloses Maximilian Schreiner View the LinkedIn Profile of Maximilian Schreiner Jun 8, 2026 Nano Banana Pro prompted by THE DECODER Key Points A flaw in Meta's AI support chatbot led to the compromise of up to 20,225 Instagram accounts over seven weeks. A buggy recovery tool let hackers send password reset links to arbitrary, unverified email addresses. Meta disabled the chatbot, invalidated the manipulated links, and forced affected users to reset their passwords immediately. Ask about this article… Search In an official data breach notification, Meta has for the first time put a number on the scope of the already-known vulnerability in its AI support chatbot. The hacking campaign ran for nearly seven weeks. Meta has released a data breach notification to the Maine Attorney General's office with the first concrete numbers on the hacking campaign targeting Instagram accounts. At least 20,225 accounts were compromised, including 30 in Maine. Hackers exploited Meta's AI-powered support chatbot for Instagram for months to take over other people's accounts. The chatbot, an account recovery tool called "High Touch Support," was designed to help locked-out users regain access. But a bug in a separate code path meant the system never checked whether the email address provided actually belonged to the Instagram account in question. Ad According to the notification , the attacks started around April 17, 2026, and weren't discovered until May 31. The attackers exploited the already-known flaw in the AI-powered "High Touch Support" recovery system, which sent password reset links to any email address without verifying it belonged to the account. Ad DEC_D_Incontent-1 Meta calls the 20,225 figure an upper bound, since some access attempts may have come from legitimate account holders. The data that was potentially accessible includes contact info, birth dates, posts, direct messages, account activity, profile information, and linked services, according to Meta. The company says it doesn't know which information was actually viewed. Thisweekinsecurity first reported on the notification. Meta disables chatbot and audits all platforms As an immediate response, Meta disabled the AI chatbot, removed the faulty code path, and invalidated all password reset links generated through the system. Affected users were placed into a mandatory security checkpoint and asked to reset their passwords through verified channels. Ad Before reactivating the tool, Meta plans to fix the email verification step in the recovery process and audit similar account recovery systems across all its platforms. The incident comes at a time when Meta has laid off thousands of employees while betting heavily on AI. The AI support chatbot had previously been marketed by Meta as a win for account security. Ad DEC_D_Incontent-2 AI News Without the Hype – Curated by Humans Subscribe to THE DECODER for ad-free reading, a weekly AI newsletter, our exclusive "AI Radar" frontier report six times a year, full archive access, and access to our comment section. Subscribe now Source: Maine AG / Data breach notification | DocumentCloud / Meta notification | Thisweekinsecurity / Instagram hack