Instagram Data Leak Update

 


Instagram Data Leak


What Happened?

  • Cybersecurity firm Malwarebytes discovered a dataset containing personal information from approximately 17.5 million Instagram accounts circulating on dark web forums.
  • The leaked data reportedly includes:
    • Usernames
    • Email addresses
    • Phone numbers
    • Partial physical addresses
    • In some cases, location details

How Did It Occur?

  • The data appears to have been scraped via Instagram’s API, likely exploiting weaknesses in rate-limiting or privacy safeguards.
  • A threat actor using the alias “Solonik” posted the dataset on BreachForums, claiming it originated from a 2024 API leak.
  • Meta (Instagram’s parent company) denies any breach of internal systems, stating that the surge in password reset emails was due to a bug that allowed external parties to trigger reset requests, not unauthorized access.

Risks to Users

  • Phishing & Social Engineering: Attackers can craft convincing messages using real account details.
  • SIM-Swapping & Account Takeover: Exposed phone numbers and emails make these attacks easier.
  • Credential Stuffing: If passwords are reused across platforms, attackers may exploit other accounts.
  • Identity Theft: Combining leaked data points enables detailed profiling for fraud. 

What Meta Says

  • Meta insists no passwords were leaked and accounts remain secure.
  • The company fixed the bug causing mass password reset emails and advises users to ignore unsolicited reset requests.

What Should You Do?

  1. Enable Two-Factor Authentication (2FA) via an authenticator app (not SMS).
  2. Change your password if you suspect unusual activity.
  3. Ignore suspicious password reset emails—navigate directly to Instagram settings if concerned.
  4. Review login activity in Instagram’s security settings.
  5. Stay alert for phishing attempts via email, SMS, or DMs.



Popular posts from this blog

WSUS CVE-2025-59287 Mitigation

CVE-2025-58034 Fortinet Warnings and Mitigation

Cloud Infrastructures are Having a Bad Week