17.5 million Instagram accounts exposed in major data breach
A significant data incident involving Instagram has raised alarm among millions of users worldwide, with reports that sensitive information from approximately 17.5 million accounts is circulating on the dark web, cybersecurity experts say.
Security firm Malwarebytes first flagged the issue after detecting the dataset during routine dark-web monitoring. According to the company, the compromised information includes usernames, full names, email addresses, phone numbers and partial physical addresses, all of which could be misused by cybercriminals for phishing, identity theft and other scams.
The dataset appears to originate from what researchers describe as an API scraping incident in late 2024, in which a threat actor using the alias “Solonik” published the data on hacking forums. The leak has since been shared widely and is now available for download or purchase on underground platforms.
In the wake of the exposure, millions of Instagram users have reported receiving unexpected password reset emails — some legitimate notifications from Instagram’s own servers, others suspected to be part of criminal attempts to exploit the leaked data. Experts warn that automated password reset emails may be used to confuse users into clicking malicious links or revealing authentication details.
Meta, Instagram’s parent company, has not officially confirmed that a breach occurred, but some tech industry reports indicate the company is aware of “unusual activity” and is investigating. As of January 11, Meta has not issued a comprehensive public statement on the underlying leak or its scope.
Cybersecurity specialists are urging all Instagram users to take immediate precautions, including enabling two-factor authentication (2FA) preferably through an authenticator app rather than SMS, ignoring unsolicited password reset emails and avoiding clicking on any suspicious links, and regularly reviewing logged-in devices and security settings within the Instagram app to ensure account safety.
Even if passwords were not directly exposed, the combination of contact details and identifiers in the leaked dataset greatly increases the risk of phishing campaigns, social engineering attacks and account takeovers.
The situation remains under active analysis by security researchers and will likely prompt further guidance from Meta in the coming days. (ILKHA)
LEGAL WARNING: All rights of the published news, photos and videos are reserved by İlke Haber Ajansı Basın Yayın San. Trade A.Ş. Under no circumstances can all or part of the news, photos and videos be used without a written contract or subscription.
Internet usage in Türkiye continued to expand in 2026, with more than nine out of every 10 people aged 16 to 74 now using the internet, according to the latest data released by the Turkish Statistical Institute (TurkStat) on Wednesday.
A cyberattack has compromised data belonging to approximately 31,000 individuals listed in Liechtenstein's register of beneficial owners of companies, foundations and trusteeships, the government of the principality announced.
OpenAI has confirmed that an autonomous artificial intelligence cyberattack involving one of its experimental ChatGPT agents extended beyond AI platform Hugging Face, revealing that multiple publicly accessible online services were affected during the incident.
The European Union has accused TikTok of failing to provide sufficient safeguards for children on its platform, warning that the company could face hefty financial penalties if it does not address shortcomings in its protection of minor users.