Skip to main content
Breach Signal

Breach report

Social Media

Instagram (Meta)

Instagram denies breach amid claims of 17 million account data leak

A dataset of roughly 17 million Instagram profiles, including millions of emails and phone numbers, surfaced in January 2026 alongside a wave of unsolicited password reset emails. Meta fixed a reset flaw but denied any breach.

Reported by BleepingComputer

Records exposed

17M

About 17 million profiles

Scale vs. largest on file

When
2026 (data possibly scraped 2022–2024)
How they got in
Alleged API scraping; separate flaw allowing mass password reset emails
Sector
Social Media

In January 2026, a dataset described as containing information on about 17.5 million Instagram accounts began circulating on a hacking forum. Security firm Malwarebytes flagged the leak to its customers, and analysis of the files found about 17 million profiles with varying levels of detail: more than 16.5 million usernames, around 6.2 million email addresses, roughly 3.5 million phone numbers, and about 1.3 million physical addresses. The dataset did not contain passwords.

The leak surfaced at the same time many Instagram users reported receiving unexpected password reset emails. Meta acknowledged that it had fixed an issue that let an external party request password reset emails for some Instagram users, but insisted there had been no breach of its systems and that accounts remained secure. The company said it was not aware of any API compromise in 2022 or 2024.

The seller claimed the records were collected through an Instagram API exposure in 2024, while some researchers suggested the data could date back to earlier scraping around 2022. Whatever its origin, the pairing of usernames with private contact details points to scraping or enumeration rather than a straightforward intrusion, a pattern seen repeatedly at Meta properties, including the 2021 Facebook phone-number leak that drew a €265 million fine in Europe.

The concurrent flood of reset emails raised concern that attackers were combining the leaked data with the reset flaw, either to probe which accounts existed or to condition users to click on reset messages. Security experts warned that phishing emails imitating Instagram's reset notices were likely to follow, and recommended that users ignore unsolicited reset requests, avoid clicking links in such emails, and enable two-factor authentication through an authenticator app rather than SMS.

The episode reflects an ongoing gap between how platforms and the public define a breach. Meta's position, that scraped or aggregated data is not a breach of its systems, is legally significant but offers little comfort to users whose private emails and phone numbers end up in criminal hands. For regulators, particularly in Europe, the case adds to pressure on large platforms to show that their APIs and lookup features are hardened against mass harvesting.

More from the wire

More in Social Media.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.