Skip to main content
Breach Signal

Breach report

Social Media

Instagram (Meta)

Hackers claim to have personal info of millions of Instagram accounts, including celebs

Hackers abused an Instagram API bug to pull contact details from what they claimed were 6 million accounts, including celebrities, then sold lookups for $10 each through a site called Doxagram.

Reported by TechCrunch

Records exposed

6M

Up to 6 million accounts (claimed)

Scale vs. largest on file

When
2017
How they got in
API bug in password reset flow exploited to extract contact details
Sector
Social Media

At the end of August 2017, Instagram warned that a bug in one of its application programming interfaces had allowed attackers to obtain the email addresses and phone numbers of high-profile users. Days later, a group of hackers claimed to have used the same weakness to scrape contact details from about 6 million accounts and set up a searchable service called Doxagram, where buyers could look up a given account's private information for $10 per search, paid in bitcoin.

The flaw was in a mobile API tied to Instagram's password reset process. By sending crafted requests, attackers could make the system return contact information that was supposed to stay private. The group said it had focused on verified and celebrity accounts and circulated a sample list of prominent names from entertainment, sports and media to prove its claims. The breach drew extra attention because singer Selena Gomez's account, then the most-followed on the platform, had been hijacked around the same time and used to post explicit images.

Instagram, owned by Facebook, initially described the issue as affecting high-profile users. Co-founder and chief technology officer Mike Krieger later wrote that the company could not determine precisely which accounts had been affected, while maintaining that it believed the number was a low percentage of users. Instagram said it had fixed the bug, encouraged users to watch for suspicious calls, texts and emails, and was working with law enforcement. Doxagram went offline shortly after the scheme became public.

Even if the true number was lower than 6 million, the exposure of celebrities' private phone numbers and email addresses created clear risks: targeted phishing, SIM-swap attempts, harassment, and extortion. Security researchers noted that verified accounts are especially attractive because they can be resold or used to spread scams to large audiences.

The incident was one of several in which Facebook-owned properties exposed data through APIs rather than through server intrusions. It underscored how password recovery systems, designed to help users regain access, are often among the most sensitive and least scrutinized parts of an application. It also showed that bug bounty programs and responsible disclosure do not stop determined attackers who discover a flaw first and choose to monetize it.

More from the wire

More in Social Media.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.