Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
mass-credential-exposureunderground-data-leakbreach-disclosure-notificationcredential-stealer-activity

Instagram Data Breach Exposes Personal Information of 17.5 Million Users

Updated 3mo agoFirst seen Jan 11, 202610 sources

A significant data breach has exposed the personal information of approximately 17.5 million Instagram users, with details including usernames, email addresses, phone numbers, and physical addresses now reportedly available for sale on the dark web. The breach, identified by Malwarebytes during routine dark web monitoring, has led to a surge in password reset emails sent to affected users and raised concerns about the potential for phishing, account takeovers, and more severe real-world threats such as stalking and extortion. Security researchers note that the leaked data appears to be more comprehensive than previous incidents, with attackers possibly correlating Instagram user IDs with external data sources to link online identities to real-world addresses.

The compromised database, described as a "doxxing kit," is being sold in batches on cybercrime forums, increasing the risk of targeted attacks against those affected. While Meta has not yet issued an official statement regarding the incident, security experts warn that the exposure of physical addresses alongside digital identifiers significantly elevates the privacy and safety risks for users. The breach underscores the importance of enabling two-factor authentication and monitoring for suspicious account activity, as the stolen data is actively circulating and may be used for a range of malicious purposes beyond typical credential abuse.

Share:
Instagram Data Breach Exposes Personal Information of 17.5 Million Users
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Mar 18, 20263mo ago

Have I Been Pwned adds the Instagram scraped dataset

Have I Been Pwned published an entry for the Instagram incident, describing a January 2026 forum post containing about 17 million rows of scraped public account data. HIBP said about 6.2 million records included email addresses, some included phone numbers, and there was no evidence that passwords were exposed.

Jan 11, 20265mo ago

Researchers conclude the alleged 2026 leak is recycled old data

Follow-up reporting and researcher analysis concluded there was no evidence of a new Instagram breach in January 2026. The dataset being marketed as a fresh API leak was assessed to be a repackaged compilation of previously scraped data, likely unrelated to the password reset email activity.

Meta says no breach occurred and fixes password reset abuse issue

Instagram's parent company Meta publicly denied that Instagram had suffered a breach and said accounts remained secure. It stated that it fixed an issue that allowed an external party to mass-trigger password reset emails for some users and advised recipients to ignore those messages.

Jan 10, 20265mo ago

Users report wave of unsolicited Instagram password reset emails

Around the same time the dataset claims spread, Instagram users in multiple countries reported receiving repeated password reset emails they did not request. The surge fueled fears of account compromise, although later reporting said the reset-email issue was separate from the recycled dataset.

Malwarebytes flags 17.5M-record Instagram dataset for sale

During routine dark web monitoring, Malwarebytes identified a large Instagram-related dataset being offered for sale on cybercrime forums and warned that it affected roughly 17 to 17.5 million accounts. The company said the data included usernames and various personal details such as email addresses, phone numbers, and physical addresses.

Jan 7, 20266mo ago

Instagram dataset reposted on BreachForums as a '2024 API LEAK'

On January 7, 2026, a BreachForums user reposted the old 17 million-record Instagram dataset under the title '2024 API LEAK,' rebranding it as a fresh breach. The same data also appeared on LeakBase around the same time, helping trigger renewed attention.

Jun 1, 20233y ago

Scraped Instagram dataset was first publicly posted in June 2023

Hackread reported that the same 17,017,213-record dataset later discussed in January 2026 was first posted publicly in June 2023. The file was associated with an earlier BreachForums user and matched the records later recirculated as a supposed new leak.

Jan 1, 20224y ago

Instagram data was originally scraped in 2022

Multiple reports and researchers assessed that the 17 million-record Instagram dataset was not newly stolen in 2026 but originated from scraping activity in 2022. The data appears to have been compiled from public Instagram information and, in some cases, enriched with additional contact details from other sources.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

29 LINKEDOpen in app
Threat actors
3 linked
Affected products
6 linked
InstagramMalwarebytesOwncloudVeeam Backup & ReplicationTikaChatgpt
Organizations
19 linked
Meta PlatformsMalwarebytesHave I Been PwnedBleepingComputerLinkedinVeeam SoftwareCoinbaseVicariusTechRepublicHackread.comOx SecurityOwncloudGoogleNord StellarGulshan Management Services, Inc.EngadgetThe Cybersec GuruSchubert Jonckheer and KolbeSecurity Affairs
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.