logo

Threat Intelligence: Instagram Exposes Passwords in Plaintext

ID: 325154e3-7499-5907-acae-3c14353460fb

STIX ID: report--325154e3-7499-5907-acae-3c14353460fb

Feed Name: Binary Defense Blog

Threat Score
35/100

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

Instagram patched a bug in its "Download Your Data" feature that accidentally included some users' passwords in plaintext within URLs which were stored on Facebook's servers; Facebook deleted the stored data and Instagram notified the small number of affected users. The report recommends affected users change passwords (including reused/similar passwords), clear browsing history, and enable two-factor authentication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.