logo

Instagram Fixes Password Reset Flaw That Exposes User Emails and Phone Numbers

ID: bb2f6758-4750-5606-8481-3a0775dd10d8

STIX ID: report--bb2f6758-4750-5606-8481-3a0775dd10d8

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-06-07

Date Updated: 2026-06-07

Author: Guru Baran

...
...

On June 6, 2026 a logic bug in Instagram’s web password-reset interface caused account recovery responses to display fully unredacted email addresses and phone numbers tied to usernames, with proof-of-concept screenshots circulating publicly (including for high-profile accounts). Meta rolled out an emergency hotfix within hours and stated there was no breach, but the brief exposure of PII elevated risk of phishing, SIM-swapping, and targeted account takeover and highlights systemic risks from automating sensitive account functions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.