17.5 Million Instagram Users’ Personal Data Exposed on Dark Web
Millions of Instagram users are at risk following the revelation that personal data from approximately 17.5 million accounts has been leaked and is now available on dark web forums. This alarming discovery was made by cybersecurity firm Malwarebytes during their routine monitoring of underground platforms. The leaked information raises significant concerns about potential misuse, as it includes sensitive details that could facilitate various cybercrimes.
Details of the Data Leak
The data breach involves a vast array of personal information, including usernames, full names, email addresses, phone numbers, and partial physical addresses. Although account passwords do not appear to be part of the leaked data, the information that has been exposed is still highly valuable to cybercriminals. Malwarebytes warns that this data can be exploited for impersonation, phishing attacks, and unauthorized account recovery attempts. Attackers could potentially initiate password reset requests to gain control of user accounts by leveraging the information obtained from the leak.
The breach is believed to be connected to an incident involving Instagram’s application programming interface (API) that occurred in 2024. On January 7, a user known as “Solonik” shared the dataset on BreachForums, claiming it contained over 17 million records in JSON and TXT formats. The sample files posted online corroborated the findings of Malwarebytes, revealing usernames, email addresses, phone numbers, user IDs, and profile details. The structure of the records suggests that the data may have been collected through scraping, an exposed interface, or a configuration error, although the exact method of acquisition remains unverified.
Meta’s Position on the Breach
As of now, Meta, the parent company of Instagram, has not publicly acknowledged the breach. The lack of a statement leaves many users uncertain about the implications of the data leak and the company’s response to the situation. Without official confirmation or denial from Meta, users are left to navigate the potential risks associated with their compromised information.
Advisories for Instagram Users
In the wake of the data leak, some Instagram users have reported receiving unsolicited password reset emails. Malwarebytes indicates that while some of these messages may be legitimate, others could be part of a scheme to exploit the leaked contact information. The firm emphasizes that even without passwords, the exposed email addresses and phone numbers can facilitate phishing attempts, SIM swap attacks, and account takeovers.
To protect themselves, users are urged to take immediate action. This includes updating their Instagram passwords, enabling two-factor authentication through an authentication app, and refraining from clicking on links in unexpected messages. Additionally, users can utilize available scanning tools to check if their email addresses are part of the leaked dataset. Receiving unrequested password reset emails may signal an attempt to access an account, prompting users to act swiftly to secure their information.
Observer Voice is the one stop site for National, International news, Sports, Editor’s Choice, Art/culture contents, Quotes and much more. We also cover historical contents. Historical contents includes World History, Indian History, and what happened today. The website also covers Entertainment across the India and World.