A large-scale data exposure known as “The Solonik Leak” has revealed information belonging to approximately 17.5 million Instagram user profiles, which has been circulated on dark web forums. The dataset, shared by a threat actor operating under the alias Solonik, contains user-related details such as usernames, email addresses, phone numbers, and other profile metadata. While there is no evidence that Instagram passwords were directly compromised, the availability of this data significantly increases the risk of phishing, impersonation, and account takeover attempts. The leak has drawn widespread attention due to the volume of affected users and the ease with which the data can be misused by cybercriminals. Investigations suggest that the exposed data was likely collected through an API-related data scraping incident rather than a direct breach of Meta’s internal systems. Inadequate access controls and rate-limiting mechanisms may have allowed attackers to harvest large volumes of publicly accessible or improperly protected data over time. Once aggregated, the information was packaged into structured files and later advertised and distributed on underground forums. Such incidents highlight ongoing risks associated with misconfigured APIs and excessive data exposure through third-party or public endpoints. Instagram users are strongly advised to enable two-factor authentication, preferably using authenticator apps, and to update passwords to strong, unique combinations not reused elsewhere. Users should remain cautious of unsolicited emails, messages, or password reset requests that may be phishing attempts. Regularly reviewing account activity and connected applications can help identify suspicious behavior early. From an organizational perspective, platforms should enforce stricter API security controls, continuous monitoring, and data minimization practices to reduce the risk of similar leaks in the future.
Cisco has announced the discovery of two significant security flaws in its Snort 3 intrusion detection engine that impact a wide range of enterprise security solutions, including f...
GitLab has released an urgent security update for both its Community Edition (CE) and Enterprise Edition (EE), addressing multiple vulnerabilities that pose significant risks to us...
The Illinois Department of Human Services (IDHS) has confirmed a major data exposure incident affecting nearly 700,000 residents, caused by incorrect privacy settings on an online ...