SEPHORA A.I CyberSecurity Scoring
SEPHORA
Company Information
Website:http://www.inside-sephora.com/
Employees number:49,309
Number of followers:2,599,126
NAICS:43
Industry Type:Retail
Homepage:inside-sephora.com
SEPHORA Risk Score (AI oriented)
Between 750 and 799
SEPHORARetail
Updated:
08/06/2026
08/06/2026
761/1000
Fair
Baa
SEPHORA Global Score (TPRM)
xxxx
SEPHORARetail
Score locked

SEPHORAFair
Current Score
761Baa (FAIR)
01000
3 incidents
-33.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
772
Cyber Attack
01 Jun 2026 • SEPHORA
Sephora and Obama White House: High-profile Instagram AI chatbot breach spotlights security risks of automation
Meta’s Instagram Hack Exposes Critical AI Security Flaw
760
CRITICAL-12
SEPTHE1780490835
Meta’s Instagram Hack Exposes Critical AI Security Flaw
On June 3, a sophisticated Instagram hack exploited a vulnerability in Meta’s AI-powered support chatbot, allowing attackers to hijack high-profile accounts including the dormant Obama White House page, beauty retailer Sephora, and a senior U.S. Space Force official. The breach occurred over the weekend, with hackers manipulating the chatbot into resetting account credentials without proper identity verification, a tactic known as "prompt injection."
Cybersecurity experts described the incident as a "foundational architecture failure," noting that Meta’s AI system was granted privileged actions without adequate access controls. The attack underscored broader risks as tech companies automate sensitive functions, such as account recovery, while AI systems remain vulnerable to manipulation. Former Meta employee and security researcher Jane Wong, whose own accounts were compromised, reported unauthorized password changes and multiple reset attempts before regaining access.
Meta confirmed the issue was resolved and stated it was securing affected accounts, though details about the hackers remain unknown. The incident rattled investors, contributing to a more than 5% drop in Meta’s shares as concerns grew over the company’s aggressive AI integration amid workforce reductions and massive infrastructure spending up to $145 billion.
The hack follows previous AI-related missteps, including a Reuters investigation revealing Meta’s chatbots lacked safeguards against inappropriate interactions with minors or spreading misinformation. While Meta has since introduced parental controls, experts warn that such exploits are not unique to the company. As AI agents handle increasingly complex tasks, hackers are targeting them with scams, raising questions about the readiness of automated systems to manage security-critical functions.
The attack highlights the growing challenge of balancing AI-driven efficiency with robust safeguards, as prompt injection and similar techniques become more prevalent across the tech industry.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
MAY 2026
771
APRIL 2026
826
Breach
17 Apr 2026 • SEPHORA
Sephora: Meta Says Thousands of Instagram Accounts Were Breached Through Its AI Support Assistant
Meta Confirms 20,000 Instagram Accounts Breached via AI Support Assistant Flaw
771
CRITICAL-55
SEP1780946094
Meta Confirms 20,000 Instagram Accounts Breached via AI Support Assistant Flaw
Meta disclosed a security breach affecting over 20,000 Instagram accounts after hackers exploited a vulnerability in its AI-powered support assistant. The incident, which began on April 17 and was discovered on May 31, allowed attackers to bypass email verification during password resets, gaining unauthorized access to accounts.
The flaw stemmed from a bug in a secondary code path that failed to confirm whether the email address provided for a password reset matched the account owner’s. Hackers used VPNs to appear in the same country as their targets, then tricked Meta’s AI assistant into linking their own email addresses to the victims’ accounts. Once linked, the attackers received password reset links, enabling full account takeovers. The attack only succeeded on accounts without two-factor authentication (2FA) enabled.
Among the high-profile accounts compromised were those belonging to the Barack Obama White House, the Chief Master Sergeant of the U.S. Space Force, and Sephora. While Meta stated it is unaware of any personal data being accessed, the breach could have exposed contact details, dates of birth, profile information, direct messages, account history, and linked service data.
Meta responded by disabling the AI support tool, removing the vulnerable code, and invalidating existing password reset links on the day the breach was identified. The company also notified regulators and filed a breach notice with Maine’s attorney general, confirming 20,225 affected individuals. Additionally, Meta is reviewing similar account recovery processes across its platforms to prevent future vulnerabilities.
The incident highlights growing concerns about AI’s role in cyberattacks, as hackers increasingly leverage automated tools to exploit security gaps with minimal human intervention. Meta’s AI support assistant, introduced in March 2024 to streamline account recovery, became an unintended vector for the breach.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
826
FEBRUARY 2026
826
JANUARY 2026
826
DECEMBER 2025
824
NOVEMBER 2025
824
OCTOBER 2025
824
SEPTEMBER 2025
823
AUGUST 2025
823
JULY 2025
823
JULY 2019
832
Breach
01 Jul 2019 • SEPHORA
SEPHORA
Sephora Data Breach
781
CRITICAL-51
SEP2372423
International beauty retailer Sephora has admitted to a breach of its online users' data, affecting customers in Singapore as well as in other countries including Malaysia, Indonesia, Thailand, Philippines.
Some personal information has been exposed to unauthorized third parties, including first and last name, date of birth, gender, e-mail address, and encrypted password.
Determining that no credit card information was accessed and that the company had no reason to believe that any personal data has been misused.
The security incident was limited to a database serving our Southeast Asia, Hong Kong SAR, and Australia/New Zealand customers who used their online services.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for SEPHORA ??
What was SEPHORA's A.I Rankiteo Cyber Score in May 2026 ??
What was SEPHORA's A.I Rankiteo Cyber Score in April 2026 ??
What was SEPHORA's A.I Rankiteo Cyber Score in March 2026 ??
What was SEPHORA's A.I Rankiteo Cyber Score in February 2026 ??
What was SEPHORA's A.I Rankiteo Cyber Score in January 2026 ??
What was SEPHORA's A.I Rankiteo Cyber Score in December 2025 ??
What was SEPHORA's A.I Rankiteo Cyber Score in November 2025 ??
What was SEPHORA's A.I Rankiteo Cyber Score in October 2025 ??
What was SEPHORA's A.I Rankiteo Cyber Score in September 2025 ??
What was SEPHORA's A.I Rankiteo Cyber Score in August 2025 ??
What was SEPHORA's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on SEPHORA's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with SEPHORA ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view SEPHORA's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?