logo

Instagram Confirms no System Breach and Fixed External Party Password Reset Issue

ID: dedf26a6-753c-5bfd-836f-89dc17663faa

STIX ID: report--dedf26a6-753c-5bfd-836f-89dc17663faa

Feed Name: cybersecurityNews.com

Threat Score
55/100

Date Published: 2026-01-11

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Instagram confirmed that a now-fixed flaw allowed external parties to trigger legitimate password reset emails for some users, but said there was no breach of its systems; this occurred alongside the appearance of an advertised dataset of roughly 17.5 million accounts (usernames, emails, phone numbers, partial locations) on cybercrime forums. Although Instagram says accounts remain secure, the combination of large-scale scraping and the reset-email abuse raises the risk of targeted phishing and social-engineering attacks; users are advised to enable two-factor authentication, use unique passwords, and ignore unsolicited reset emails.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.