
The cybersecurity firm Malwarebytes simply seen one thing disagreeable taking place over on the darkish internet:
Cybercriminals stole the delicate data of 17.5 million Instagram accounts, together with usernames, bodily addresses, telephone numbers, e mail addresses, and extra. This knowledge is offered on the market on the darkish internet and may be abused by cybercriminals.
— Malwarebytes (@malwarebytes.com) January 9, 2026 at 8:34 AM
Did you obtain any sudden password reset emails from Instagram currently? If the feedback on a Reddit put up about this breach from just a few hours in the past are any indication, you’re not alone.
Evidently the bodily addresses, telephone numbers, e mail addresses and different data hooked up to the accounts of 17.5 million Instagram customers is offered on the market within the sketchier elements of the web.
Apparently Malwarebytes performs sweeps of the darkish internet for objects like this, and surmised that this cache of private particulars is tied a 2024 API breach that seemingly allowed an attacker to pry the data out of Instagram.
Some steps you possibly can take to make sure that your data is protected embody:
- Resetting your password proper now
- Turning on two-factor authentication for those who haven’t already
- Completely deleting all social media accounts from all platforms
Up to now Instagram doesn’t seem to have revealed an announcement about this subject. Gizmodo reached out to Meta for remark, and can replace if we hear again.Â
