Instagram has addressed recent concerns surrounding an alleged large-scale data leak by confirming that no breach of its internal systems occurred. According to the company, a technical issue was identified and resolved that allowed an external actor to repeatedly trigger password reset emails for certain users. This behavior led to confusion and alarm among users who received unexpected account recovery messages. Instagram emphasized that these emails did not indicate account compromise and advised users to safely ignore them if they did not initiate a reset. The company reiterated that account security remains intact and apologized for the uncertainty caused by the incident. The controversy gained momentum after security firm warnings claimed that data from more than 17 million Instagram accounts had been leaked online. The dataset was shared freely across multiple hacking forums, with claims that it originated from an Instagram API vulnerability allegedly exploited in 2024. The exposed data reportedly includes a mixture of usernames, email addresses, phone numbers, physical addresses, and account IDs, though not every record contains all data fields. In some cases, only basic identifiers such as usernames and IDs were present. Analysis of the dataset shows millions of unique entries across different data categories, raising concerns about potential misuse despite the absence of passwords. However, there is currently no concrete evidence linking the dataset to a recent breach or API vulnerability. Cybersecurity researchers suggest the information may be a compilation of previously scraped data from older incidents, possibly dating back several years. Instagram has stated it is unaware of any API compromises in recent years and maintains that no new breach has occurred. While passwords were not exposed, users are advised to remain cautious, as such datasets can be leveraged for phishing, smishing, and social engineering attacks. Enabling two-factor authentication and ignoring unsolicited password reset messages remain key steps to enhancing account security.
Cisco has announced the discovery of two significant security flaws in its Snort 3 intrusion detection engine that impact a wide range of enterprise security solutions, including f...
GitLab has released an urgent security update for both its Community Edition (CE) and Enterprise Edition (EE), addressing multiple vulnerabilities that pose significant risks to us...
The Illinois Department of Human Services (IDHS) has confirmed a major data exposure incident affecting nearly 700,000 residents, caused by incorrect privacy settings on an online ...