Home Cyber Security News 17.5 Million Instagram Accounts Exposed in Major Data Leak

17.5 Million Instagram Accounts Exposed in Major Data Leak

0
17.5 Million Instagram Accounts Exposed in Major Data Leak

A massive data breach has compromised the personal information of approximately 17.5 million Instagram users, with sensitive details now circulating on dark web forums.

The leak, first highlighted by cybersecurity researchers at Malwarebytes and verified through dark web listings, exposes a treasure trove of contact information that leaves millions vulnerable to identity theft and targeted phishing attacks.

Dark Web Listing Reveals “API Leak”

The compromised dataset appeared on a notorious hacking forum earlier this week, posted by a threat actor operating under the alias “Solonik.” The listing, titled “INSTAGRAM.COM 17M GLOBAL USERS — 2024 API LEAK,” claims to contain 17.5 million records formatted in JSON and TXT files.

According to the forum post, the data was harvested in late 2024 through an “API Leak,” bypassing standard security measures to scrape user profiles globally.

The leaked database is particularly damaging due to the depth of personal information it contains. Unlike simple username dumps, this breach includes:

  • Full Names and Usernames
  • verified Email Addresses
  • Phone Numbers
  • User IDs
  • Country and Partial Location Data

Screenshots of the data samples confirm the validity of these fields, showing a structured list of personal details that allow cybercriminals to build comprehensive profiles of their targets.

Active Exploitation and Risks

The breach has already transitioned from a passive threat to active exploitation. Following the data release, numerous Instagram users reported receiving a surge of unsolicited password reset notifications.

While the leak does not appear to include passwords, the combination of emails and phone numbers is sufficient for “SIM swapping” attacks and sophisticated social engineering.

By posing as Instagram support or using the exposed personal details to establish trust, scammers can trick victims into handing over two-factor authentication (2FA) codes or login credentials.

The incident is classified as “scraping”—the automated harvesting of data via public interfaces—rather than a direct intrusion into Instagram’s core servers. However, the scale of the “API Leak” suggests a failure in rate-limiting or privacy safeguards, allowing actors to query millions of accounts without detection.

As of January 10, 2026, Meta has not issued a formal statement regarding the specific 17.5 million record dump. Cybersecurity experts urge all Instagram users to immediately enable multi-factor authentication (MFA) using an authenticator app rather than SMS, and to disregard any unprompted password reset emails .

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here