🔥Discovery of a Huge Leak on Instagram.. Do Not Respond to the Email

This week, it was discovered that Instagram’s platform suffered one of the largest data leaks in its history. A database containing approximately 17.5 million accounts has been circulated on the dark web.

The leaks contain highly sensitive information, including email addresses, phone numbers, full usernames, and in some cases, even actual physical addresses.

Cybercriminals stole the sensitive information of 17.5 million Instagram accounts, including usernames, physical addresses, phone numbers, email addresses, and more. pic.twitter.com/LXvjjQ5VXL

— Malwarebytes (@Malwarebytes) January 9, 2026

How did the breach happen?

Contrary to popular belief, Instagram’s servers were not directly hacked in this incident. The most likely reason—according to initial analyses from cybersecurity companies like Malwarebytes and Cybernews—is that the breach occurred through the aggregation of old data from previous leaks + exploiting vulnerabilities in third-party applications and services linked to Instagram accounts (such as automated posting tools, follower analysis services, or account management software).

After collecting this data, it was prepared, organized, and effectively linked to Instagram accounts, producing a “fresh” and extremely dangerous database from the hackers’ perspective.

The real risks you face now

  1. Phishing password reset attacks
    Thousands of users have started receiving emails and notifications that appear to be from Instagram stating: “A password reset has been requested.” These are mostly sophisticated phishing attempts.
  2. Faster account theft
    Once the attacker knows your email and phone number, it becomes very easy to bypass two-factor authentication if it relies solely on text messages (SIM swapping).
  3. Extortion and harassment
    If the account contains personal photos or family information, criminals may use them for extortion or to harass the victims.
  4. Attacks on other accounts
    Most people use the same email or phone number across multiple services (Gmail, Facebook, TikTok, banks…). One leak opens the door to a series of breaches.

What to do now? (Immediate practical steps)

StepPriorityTime requiredExpected impact
Activate two-factor authentication (Authenticator app)★★★★★3 minutesReduces risk by 95–99%
Change your password to a strong, completely new one★★★★2 minutesEssential if it’s weak or repeated
Remove all suspicious connected apps★★★5–10 minutesCuts off backdoor access
Check if your data has been leaked (Have I Been Pwned)★★★2 minutesGives you a clearer picture
Use different passwords for each account (Password manager)★★★★Long-term investmentOptimal strategic solution

>Content generated from the Arabic version of Tanja7.com

Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments

Follow us

find us on social media
7PM Newsletter
Subscribe to get all the latest news
0
Would love your thoughts, please comment.x
()
x