Instagram denies breach amid claims of 17 million account data leak
Instagram修复了允许威胁行为者大量请求密码重置邮件的漏洞,并否认系统被入侵或数据泄露。媒体称超1700万账户信息被泄露,但无证据显示为新事件。建议用户忽略异常邮件并启用双重认证。 2026-1-11 19:15:16 Author: www.bleepingcomputer.com(查看原文) 阅读量:9 收藏

Instagram

Instagram says it fixed a bug that allowed threat actors to mass-request password reset emails, amid claims that data from more than 17 million Instagram accounts was scraped and leaked online.

"We fixed an issue that allowed an external party to request password reset emails for some Instagram users," a Meta spokesperson told BleepingComputer.

"We want to reassure everyone there was no breach of our systems and people's Instagram accounts remain secure. People can disregard these emails and we apologize for any confusion this may have caused."

Wiz

A media frenzy over an alleged Instagram data breach began after Malwarebytes warned its customers that cybercriminals had stolen data from 17.5 million accounts.

This alleged Instagram data was released for free on numerous hacking forums, with the poster claiming it was gathered through an unconfirmed 2024 Instagram API leak.

Forum post leaking alleged Instagram data
Forum post leaking alleged Instagram data

In total, the shared data contains 17,017,213 Instagram account profiles, including phone numbers, user names, names, physical addresses, email addresses, and Instagram IDs.

Not all of this information is present for each record, with some containing as little as just an Instagram ID and a username.

Cybersecurity researchers on X claim [12] that the scraped data is from a 2022 API scraping incident, but have not provided any clear evidence to confirm this.

Furthermore, Meta told BleepingComputer that it is not aware of any API incidents in 2022 or 2024.

However, Instagram has previously suffered from API scraping incidents, such as a 2017 bug that was exploited to scrape and sell the personal information of an alleged 6 million accounts.

It is not clear whether the newly leaked Instagram data is a compilation of the 2017 leak and additional information from the past couple of years.

BleepingComputer contacted the person who leaked the Instagram information to confirm when it was stolen, but did not receive a response.

Instagram denies a breach

There is currently no evidence that this incident represents a new Instagram data breach. Meta says it is not aware of any API compromises in 2022 or 2024 and that there has not been a new breach.

Furthermore, researchers have not provided proof that the leaked dataset was obtained through a recent vulnerability.

Instead, the information suggests the data may be a compilation of previously scraped information from multiple sources over several years.

The good news is that this leaked data does not contain passwords, so there is no need to change them.

However, people do need to stay vigilant against targeted phishing, smishing (text phishing), and social engineering attacks that utilize this information.

It is common for threat actors to use leaked data to try to steal additional information, such as a user's password.

If you receive an Instagram password reset email or text codes to your phone number and did not initiate an account recovery, then simply ignore and delete them.

If you do not have two-factor authentication enabled on your account, it is strongly recommended that you turn it on to increase your security.

Wiz

The 2026 CISO Budget Benchmark

It's budget season! Over 300 CISOs and security leaders have shared how they're planning, spending, and prioritizing for the year ahead. This report compiles their insights, allowing readers to benchmark strategies, identify emerging trends, and compare their priorities as they head into 2026.

Learn how top leaders are turning investment into measurable impact.


文章来源: https://www.bleepingcomputer.com/news/security/instagram-denies-breach-amid-claims-of-17-million-account-data-leak/
如有侵权请联系:admin#unsafe.sh