Breach report
Social MediaInstagram (Meta)
Instagram denies breach amid claims of 17 million account data leak
A dataset of roughly 17 million Instagram profiles, including millions of emails and phone numbers, surfaced in January 2026 alongside a wave of unsolicited password reset emails. Meta fixed a reset flaw but denied any breach.
Reported by BleepingComputer
Records exposed
17M
About 17 million profiles
Scale vs. largest on file
- When
- 2026 (data possibly scraped 2022–2024)
- How they got in
- Alleged API scraping; separate flaw allowing mass password reset emails
- Sector
- Social Media
In January 2026, a dataset described as containing information on about 17.5 million Instagram accounts began circulating on a hacking forum. Security firm Malwarebytes flagged the leak to its customers, and analysis of the files found about 17 million profiles with varying levels of detail: more than 16.5 million usernames, around 6.2 million email addresses, roughly 3.5 million phone numbers, and about 1.3 million physical addresses. The dataset did not contain passwords.
The leak surfaced at the same time many Instagram users reported receiving unexpected password reset emails. Meta acknowledged that it had fixed an issue that let an external party request password reset emails for some Instagram users, but insisted there had been no breach of its systems and that accounts remained secure. The company said it was not aware of any API compromise in 2022 or 2024.
The seller claimed the records were collected through an Instagram API exposure in 2024, while some researchers suggested the data could date back to earlier scraping around 2022. Whatever its origin, the pairing of usernames with private contact details points to scraping or enumeration rather than a straightforward intrusion, a pattern seen repeatedly at Meta properties, including the 2021 Facebook phone-number leak that drew a €265 million fine in Europe.
The concurrent flood of reset emails raised concern that attackers were combining the leaked data with the reset flaw, either to probe which accounts existed or to condition users to click on reset messages. Security experts warned that phishing emails imitating Instagram's reset notices were likely to follow, and recommended that users ignore unsolicited reset requests, avoid clicking links in such emails, and enable two-factor authentication through an authenticator app rather than SMS.
The episode reflects an ongoing gap between how platforms and the public define a breach. Meta's position, that scraped or aggregated data is not a breach of its systems, is legally significant but offers little comfort to users whose private emails and phone numbers end up in criminal hands. For regulators, particularly in Europe, the case adds to pressure on large platforms to show that their APIs and lookup features are hardened against mass harvesting.