By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Urgent warning as Instagram users targeted by surge in ‘password reset’ attacks
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > Urgent warning as Instagram users targeted by surge in ‘password reset’ attacks
News

Urgent warning as Instagram users targeted by surge in ‘password reset’ attacks

News Room
Last updated: 2026/01/10 at 3:14 PM
News Room Published 10 January 2026
Share
Urgent warning as Instagram users targeted by surge in ‘password reset’ attacks
SHARE

A MASSIVE data breach has exposed the personal information of about 17.5 million Instagram users.

The breach has triggered a global surge in suspicious password reset attacks and put millions at risk of cybercrime.

Sign up for The Sun newsletter

Thank you!

A huge data breached has exposed the personal information of 17.5 million Instagram usersCredit: Alamy
The breach has put millions of Instagram users at risk of cybercrimeCredit: AFP

The leak was first uncovered by cybersecurity researchers at Malwarebytes and later verified through listing circulating on dark web forums, where sensitive user data is being actively traded.

According to researchers, the compromised data reset appeared earlier this week  on a notorious hacking forum, posted by a threat actor using the alias “Solonik.”

The listing, titled “INSTAGRAM.COM 17M GLOBAL USERS — 2024 API LEAK,” claims to contain 17.5 million Instagram user records available in both JSON and TXT formats.

The hacker alleges the data was harvested in late 2024 through an “API Leak,” allowing them to bypass standard security protections and scrape user profiles from across the globe.

Cyber security experts say the scale of the breach suggests serious failures in Instagram’s rate-limiting or privacy safeguards, enabling millions of automated data requests to go undetected.

Unlike previous social media leaks that only exposed usernames, this dataset contains a deeply detailed profile of each victim.

The leaked information includes full names, usernames, verified email addresses, phone numbers, user IDs, country information, and partial location data.

Screenshots shared on hacking forums appear to confirm the authenticity of the data, showing neatly structured records that allow criminals to build comprehensive profiles of potential targets.

Experts warn the breach has already moved from a passive data leak to active exploitation.

In the hours following the data dump, Instagram users across multiple countries reported a sharp spike in unsolicited password reset emails landing in their inboxes.

While the leaked database does not appear to contain account passwords, cybersecurity specialists warn that the exposed emails and phone numbers are more than enough to fuel serious attacks.

Criminals can use the information to carry out SIM-swapping attacks, impersonate Instagram support staff, or launch highly targeted phishing campaigns.

By using personal details pulled from the leak, scammers can establish trust and trick victims into handing over login credentials or two-factor authentication codes.

The incident has been classified as “scraping,” meaning data was harvested through public-facing interfaces rather than a direct breach of Instagram’s core servers.

However, experts stress that the sheer volume of data points to a significant “API Leak” that should never have been possible at this scale.

As of January 10, 2026, Meta has not issued a formal statement addressing the specific 17.5 million-record data dump.

Cybersecurity experts are urging Instagram users to take immediate action to secure their accounts.

They recommend enabling multi-factor authentication using an authenticator app rather than SMS, which is more vulnerable to SIM-swapping attacks.

Users are also being warned to ignore any unprompted password reset emails and to avoid clicking links unless they personally initiated the request.

Instagram users worldwide are now reporting unexpected password reset notifications, with experts warning that panic-clicking is exactly what hackers are counting on.

Davey Winder, a senior contributor to Forbes and a veteran cybersecurity writer, hacker, and analyst, said he was among those targeted.

He revealed that he received a legitimate-looking email on Friday that appeared to be from Instagram, claiming a password reset had been requested for his account.

The email included a large blue Reset Password button alongside the message, “If you ignore this message, your password will not be changed. If you didn’t request a password reset, let us know.”

According to Forbes, hackers are relying on users to panic and click the button or the “let us know” hyperlink without thinking.

Experts say that even if a user clicks the link, attackers would still need additional information to successfully take over an account.

Instagram users across multiple countries reported a sharp spike in unsolicited password reset emailsCredit: Alamy
Sensitive user data is being actively tradedCredit: Alamy

Instagram has stressed that receiving a password reset email does not automatically mean an account has been breached.

The company says such emails can be triggered by simple user error, such as someone mistyping an email address when trying to log in.

According to Instagram’s Help Center, legitimate emails are only sent from addresses ending in @mail.instagram.com, and messages from other domains may be phishing attempts.

However, Forbes reports that the timing of the password reset surge closely matches the appearance of the 17.5 million-user database on BreachForums.

The alleged breach database was published just hours before users began reporting the wave of password reset notifications.

The Independent has contacted Meta representatives for comment.

To protect accounts, Instagram strongly recommends enabling two-factor authentication, which requires a security code when logging in from an unrecognized device.

The platform automatically enables 2FA for creator accounts, but all users are urged to check that the feature has not been turned off.

Instagram also offers a recovery process for users who believe their accounts have been compromised.

Full instructions for checking and managing two-factor authentication are available in the company’s Help Center.

If users are locked out of their accounts, Instagram advises visiting instagram.com/hacked to begin the recovery process.

Security experts also warn users to secure their email accounts with unique passwords that are different from their social media logins.

This prevents hackers from gaining access to multiple platforms if one account is compromised.

With more than two billion monthly active users, Instagram has become a prime target for cybercriminals worldwide.

Hackers can launch account takeover attacks using methods ranging from malicious browser extensions to sophisticated phishing schemes.

Experts warn that large-scale data leaks like this make such attacks far easier by handing criminals a ready-made list of targets.

“If you get this message from Instagram and were not expecting it, you have found yourself in the crosshairs of an ongoing account attack,” Winder warned.

He added that he had personally received a dozen password reset emails in just 48 hours.

Winder said it now appears “likely that the surge in password reset attack attempts… is related to a breaking story about a leak of 17.5 million Instagram user accounts by a threat actor on BreachForums.”

The good news, experts say, is that these attacks are unlikely to succeed if users have one critical safeguard in place.

“Two-factor authentication will help you protect your account so no one has access to it,” Instagram confirms, requiring a code in addition to the password “if there’s a login attempt from a device that we don’t recognise.”

Instagram also noted, “To provide the highest security possible, we turned on two-factor authentication for creator accounts by default.”

The company urged users to “check to make sure that you didn’t turn it off!”

Cybersecurity specialists warn that users should stay vigilant, think twice before clicking any unexpected emails, and take immediate steps to secure their accounts as the fallout from the leak continues to unfold.

Experts warn the breach has already moved from a passive data leak to active exploitationCredit: Alamy
With more than two billion monthly active users, Instagram has become a prime target for cybercriminals worldwideCredit: Getty

What is a password reset attack?

A password reset attack is when hackers try to break into an account by abusing the “forgot password” feature or tricking users into handing over access.

Instead of guessing passwords, criminals rely on panic, deception or security loopholes.

How it works:

• Hackers trigger password reset emails to flood a victim’s inbox.

• Fake emails or messages may impersonate Instagram or tech support.

• Victims are pressured into clicking links or sharing security codes.

• Once a reset link or code is captured, attackers can lock users out and take control.

Why it’s dangerous:

• It doesn’t require stealing passwords first.

• Attackers can use leaked emails and phone numbers to appear legitimate.

• Repeated reset requests can overwhelm users and hide scam messages.

How to stay safe:

• Ignore password reset emails you didn’t request.

• Never click links unless you started the reset yourself.

• Turn on two-factor authentication using an authenticator app. • Always check the sender’s email address and website URL carefully.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article CES 2026: This Motorized Dock Turns Your iPhone Into a Tracking AI Robot · TechNode CES 2026: This Motorized Dock Turns Your iPhone Into a Tracking AI Robot · TechNode
Next Article MPs and contractors urge UK government to U-turn on ‘manifestly unfair’ Loan Charge settlement terms | Computer Weekly MPs and contractors urge UK government to U-turn on ‘manifestly unfair’ Loan Charge settlement terms | Computer Weekly
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Seeking the Holy Grail: Why AI performance is now a systems problem –  News
Seeking the Holy Grail: Why AI performance is now a systems problem – News
News
Beyond Google: How LLM Search Engines Are Reshaping SEO Strategy in 2025
Beyond Google: How LLM Search Engines Are Reshaping SEO Strategy in 2025
Gadget
Google Maps’ audio navigation quirks make it difficult to trust
Google Maps’ audio navigation quirks make it difficult to trust
News
US-China tariffs likely to impact Apple prices, iPhone 17 adjustments expected · TechNode
US-China tariffs likely to impact Apple prices, iPhone 17 adjustments expected · TechNode
Computing

You Might also Like

Seeking the Holy Grail: Why AI performance is now a systems problem –  News
News

Seeking the Holy Grail: Why AI performance is now a systems problem – News

13 Min Read
Google Maps’ audio navigation quirks make it difficult to trust
News

Google Maps’ audio navigation quirks make it difficult to trust

11 Min Read
AWS Introduces VPC Encryption Controls to Enforce Encryption in Transit
News

AWS Introduces VPC Encryption Controls to Enforce Encryption in Transit

4 Min Read
Livestream FA Cup Soccer: Watch Man United vs. Brighton From Anywhere
News

Livestream FA Cup Soccer: Watch Man United vs. Brighton From Anywhere

5 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?