- By Alex David
- Sun, 11 Jan 2026 07:55 PM (IST)
- Source:JND
A massive trove of Instagram user data has been found in the wild, reportedly on dark web databases and marketplaces. Information associated with almost 17.5 million Instagram accounts was found being auctioned and traded on the internet, as stated in a recent warning by cybersecurity firm Malwarebytes.
The exposed dataset reportedly includes:
- Usernames
- Email addresses
- Phone numbers
- Partial location details
Security professionals warn that the combination of data leaves users at significantly more risk for phishing, identity theft and account takeover.
What Hackers Are Doing With the Data
According to Malwarebytes, the data is already being abused. Some users have already reported receiving Instagram password reset emails they didn’t ask for, indicating that attackers are already attempting to access accounts using this leaked data.
Listings on the dark web seen by researchers state that the data was scraped in late 2024 using public APIs and sources from specific regions. The Seller, going by the online moniker “Subkek,” is promoting the dataset as new. Sample records are said to contain complete contact information and reveal only minimal location data.
Once attackers have validated email and phone information, they can construct scam messages that look a lot like they are coming from Instagram or Meta, so it’s hard for users to tell whether they’re fake, experts say.
Instagram Responds to Password Reset Abuse
Instagram made a backhanded acknowledgment of some of the problem at 9:39 AM on January 11, 2026, in this post on X. The company confirmed that it has resolved a vulnerability where an external actor could initiate password reset emails for certain users.
Instagram stated that:
- The issue has now been resolved.
- Users should ignore any unexpected password reset emails.
- No action is required unless an account shows unusual activity.
Instagram and Meta, however, have yet had not officially confirmed whether the 17.5 million-account dataset was derived from their systems internally or from third parties. Investigations are ongoing.
How to Check If Your Account Is Affected
To see if your email or phone number is part of known breaches, go to:
haveibeenpwned.com
Other warning signs include:
- Password reset emails you did not request
- Unknown devices in Instagram’s Login Activity section
- Sudden logouts or failed login attempts
ALSO READ: CES 2026: Dell Pushes Back Against The ‘AI PC’ Hype
What You Should Do Right Now
To protect your account:
1. Change your Instagram password immediately.
2. Enable Two-Factor Authentication (2FA).
3. Review Login Activity and remove unknown devices.
4. Disconnect unnecessary third-party apps.
5. Ignore suspicious emails, even if they look official.
Why This Matters
While Instagram may have corrected the password reset abuse, the fact that millions of records could be available for sale or free download shows how vulnerable our personal data can be. Once data makes its way to the dark web, it frequently gets rinsed and repeated in scams, impersonation attempts and automated hacking tools.
For the time being, it’s best to assume that your data may be included in the leak and take precautions before hand. If it just waits for official confirmation to arrive, the information may have been out long enough for attackers to get their hands on it.
