Instagram data leak said to affect 17.5M users
Instagram data leak said to affect 17.5M users

Instagram data leak said to affect 17.5M users

lucadelladora – A major data leak has reportedly exposed personal information linked to millions of Instagram users, triggering fresh concerns over online privacy and account security. Cybersecurity firm Malwarebytes revealed details of the incident after identifying the dataset during routine monitoring activity. The exposed information is now circulating in underground forums, increasing the risk of misuse by cybercriminals. Users are being urged to take immediate steps to protect their accounts.

Read More : MLS left-back Wagner joins Birmingham City

Malwarebytes Reports Leak Affecting 17.5 Million Instagram Accounts

Malwarebytes has confirmed that it discovered a large-scale data leak involving information from approximately 17.5 million Instagram accounts. According to Malwarebytes, a hacker using the alias “Solonik” posted the dataset on BreachForums on January 7, 2026. Malwarebytes researchers identified the leak while conducting a routine dark web scan.

In an email sent to users, Malwarebytes stated that its investigation uncovered large, well-structured JSON and TXT files. The files appear to originate from a possible Instagram API exposure dating back to 2024. The volume and organization of the data suggest a significant breach rather than a limited or isolated incident. Researchers said the scope of the leak raised immediate red flags due to the number of affected users.

The leaked dataset reportedly contains a wide range of personal information. It includes Instagram usernames, full names, email addresses, international phone numbers, partial physical addresses, user IDs, and other contact-related details. Although the leak does not appear to include passwords, security experts still consider the exposed information highly sensitive. Experts warn that attackers can exploit this data effectively for phishing, identity fraud, and other targeted scams.

The scale of the incident has intensified concerns over how organizations access and protect user data. Malwarebytes emphasized that attackers can still combine the leaked information with social engineering techniques, even without passwords. This combination significantly increases the likelihood that attackers will successfully target and exploit unsuspecting users.

Phishing and Account Takeover Risks Prompt User Warnings

Malwarebytes has warned that attackers are likely to exploit the leaked data for several malicious purposes. Common threats include impersonation scams, targeted phishing campaigns, and credential harvesting attempts. One specific concern involves abuse of Instagram’s password reset process. With access to associated emails and phone numbers, attackers could attempt to trick users into surrendering account access.

At the time of writing, Meta has not publicly confirmed the breach involving Instagram. The company has not provided an official explanation about how the data was exposed or clarified whether it will notify affected users directly. This lack of confirmation has increased uncertainty among users and security professionals.

Until the company provides further clarification, security experts advise users to remain vigilant. Users should treat suspicious emails or text messages claiming to come from Instagram or Meta with caution. Messages that urge immediate password resets or account verification often appear convincing and commonly feature in phishing schemes.

Read More : Next PlayStation Portal refresh rumored to add OLED

Security experts recommend several precautionary steps. Users should enable two-factor authentication using an authenticator app or SMS where available. Changing Instagram passwords to strong, unique combinations is also advised. Avoiding unfamiliar links and monitoring account activity closely can help reduce risk.

The incident highlights the growing threat posed by large-scale data leaks and the long-term consequences of exposed personal information. As investigations continue, users are encouraged to prioritize account security. Further updates are expected once Meta or Instagram provides an official response.