Data from 'six million' Instagram accounts leak online

Instagram warns users to be vigilant to scam calls and emails

The personal details of up to six million Instagram users have reportedly been leaked online after a bug in the platform made profiles' account information publicly accessible.

The flaw, which exposed the email addresses and phone numbers of both private and public accounts, was subsequently exploited by hackers, who were able to harvest the data into a dark web database, where contact details were being sold for $10 each.

Advertisement - Article continues below

While the vulnerability was initially thought to have only affected a small number of A-list celebrity accounts, including singers Selena Gomez, Taylor Swift and Harry Styles, The Daily Beast reported that hackers claimed to have the contact details of as many as six million users.

Responding to the leak, Facebook-owned Instagram said it was working with law enforcement, adding that the bug was now fixed and that no passwords were stolen.

"We encourage you to be vigilant about the security of your account, and exercise caution if you observe any suspicious activity such as unrecognised incoming calls, texts, or emails," Instagram's co-founder and CTO, Mike Krieger, said in a statement.

"Protecting the community has been important at Instagram from day one, and we're constantly working to make Instagram a safer place. We are very sorry this has happened."

A dedicated portal (with URLs redacted) advertises details for the "price of 2 cups of coffee"

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

The hackers, who remain unidentified, hosted the database on a dedicated site called Doxagram, allowing users to search for contact information for a $10 fee. A sample of 1,000 accounts was supplied to The Daily Beast, each containing an email address, phone number, or both.

Although Facebook is working to take down the domains used by the hackers, the database is still up and running at the time of writing, and is even operating a dedicated Twitter account.

Researchers at Kaspersky, who apparently discovered the flaw and reported it to Facebook, told Hacker News that the problem lay with Instagram's mobile API, and its password reset function. It was discovered that a user could request a new password on an account and intercept the details sent in response.

As well as changing passwords, the company has urged users to turn on two-factor authentication, which is available through their Instagram accounts.

Featured Resources

The case for a marketing content hub

Transform your digital marketing to deliver customer expectations

Download now

Fast, flexible and compliant e-signatures for global businesses

Be at the forefront of digital transformation with electronic signatures

Download now

Why CEOS should care about the move to SAP S/4HANA

And how they can accelerate business value

Download now

IT faces new security challenges in the wake of COVID-19

Beat the crisis by learning how to secure your network

Download now
Advertisement

Recommended

Visit/security/encryption/355820/k2view-innovates-in-data-management-with-new-encryption-patent
encryption

K2View innovates in data management with new encryption patent

28 May 2020
Visit/software/video-conferencing/355410/zoom-50-adds-256-bit-encryption-and-ui-refresh
video conferencing

Zoom 5.0 adds 256-bit encryption to address security concerns

23 Apr 2020
Visit/security/hacking/355382/whatsapps-flaw-shoulder-surfing
hacking

WhatsApp flaw leaves users open to 'shoulder surfing' attacks

21 Apr 2020
Visit/security/cyber-security/355368/microsoft-builds-ai-to-detect-security-flaws-with-99-accuracy
cyber security

Microsoft AI can detect security flaws with 99% accuracy

20 Apr 2020

Most Popular

Visit/infrastructure/server-storage/355785/dell-emc-poweredge-r7525-review-an-epyc-core-density-to-make
Server & storage

Dell EMC PowerEdge R7525 review: An EPYC core density to make Intel weep

26 May 2020
Visit/infrastructure/network-internet/355792/intel-releases-wi-fi-and-bluetooth-driver-updates-for
Network & Internet

Intel releases Wi-Fi and Bluetooth driver updates for Windows 10

26 May 2020
Visit/operating-systems/microsoft-windows/355781/microsoft-confirms-further-issues-with-troublesome
Microsoft Windows

Microsoft's latest Windows 10 update is causing yet more issues

26 May 2020