-8 C
New York
Saturday, January 24, 2026

Instagram denies breach amid claims of 17 million account knowledge leak


Instagram denies breach amid claims of 17 million account knowledge leak

Instagram says it mounted a bug that allowed menace actors to mass-request password reset emails, amid claims that knowledge from greater than 17 million Instagram accounts was scraped and leaked on-line.

“We mounted a problem that allowed an exterior celebration to request password reset emails for some Instagram customers,” a Meta spokesperson instructed BleepingComputer.

“We need to reassure everybody there was no breach of our techniques and other people’s Instagram accounts stay safe. Individuals can disregard these emails and we apologize for any confusion this will have prompted.”

Wiz

A media frenzy over an alleged Instagram knowledge breach started after Malwarebytes warned its clients that cybercriminals had stolen knowledge from 17.5 million accounts.

This alleged Instagram knowledge was launched without spending a dime on quite a few hacking boards, with the poster claiming it was gathered by an unconfirmed 2024 Instagram API leak.

Forum post leaking alleged Instagram data
Discussion board put up leaking alleged Instagram knowledge

In complete, the shared knowledge accommodates 17,017,213 Instagram account profiles, together with telephone numbers, person names, names, bodily addresses, e-mail addresses, and Instagram IDs.

Not all of this data is current for every report, with some containing as little as simply an Instagram ID and a username.

Cybersecurity researchers on X declare [12] that the scraped knowledge is from a 2022 API scraping incident, however haven’t supplied any clear proof to substantiate this.

Moreover, Meta instructed BleepingComputer that it isn’t conscious of any API incidents in 2022 or 2024.

Nonetheless, Instagram has beforehand suffered from API scraping incidents, reminiscent of a 2017 bug that was exploited to scrape and promote the private data of an alleged 6 million accounts.

It isn’t clear whether or not the newly leaked Instagram knowledge is a compilation of the 2017 leak and extra data from the previous couple of years.

BleepingComputer contacted the one who leaked the Instagram data to substantiate when it was stolen, however didn’t obtain a response.

Instagram denies a breach

There may be at the moment no proof that this incident represents a brand new Instagram knowledge breach. Meta says it isn’t conscious of any API compromises in 2022 or 2024 and that there has not been a brand new breach.

Moreover, researchers haven’t supplied proof that the leaked dataset was obtained by a current vulnerability.

As a substitute, the data suggests the information could also be a compilation of beforehand scraped data from a number of sources over a number of years.

The excellent news is that this leaked knowledge doesn’t comprise passwords, so there isn’t a want to vary them.

Nonetheless, folks do want to remain vigilant towards focused phishing, smishing (textual content phishing), and social engineering assaults that make the most of this data.

It is not uncommon for menace actors to make use of leaked knowledge to attempt to steal further data, reminiscent of a person’s password.

In the event you obtain an Instagram password reset e-mail or textual content codes to your telephone quantity and didn’t provoke an account restoration, then merely ignore and delete them.

In the event you wouldn’t have two-factor authentication enabled in your account, it’s strongly beneficial that you simply flip it on to extend your safety.

It is finances season! Over 300 CISOs and safety leaders have shared how they’re planning, spending, and prioritizing for the 12 months forward. This report compiles their insights, permitting readers to benchmark methods, establish rising tendencies, and examine their priorities as they head into 2026.

Learn the way prime leaders are turning funding into measurable affect.



Related Articles

Latest Articles