Skip to content
Malwarebytes Confirms 17.5 Million Instagram Accounts Data Leak | Ukraine news - Межа

Malwarebytes Confirms 17.5 Million Instagram Accounts Data Leak | Ukraine news - Межа

Mezha January 11, 2026

Security company Malwarebytes confirmed a data breach involving 17.5 million Instagram accounts. Malicious actors are already exchanging this information on hacker forums.

In Malwarebytes’ user advisory, sent earlier today, it states that the breach was detected while monitoring the dark web. The leak contains various sensitive user data, including:

Malwarebytes warns that the attackers are likely to use this data for impersonation attacks, phishing, and credential theft, including by abusing the Instagram password reset mechanism.

Stolen data, it appears, originate from an Instagram API leak that occurred in 2024. A threat actor using the alias “Solonik” published the dataset on BreachForums on January 7, 2026, offering it for free. The post claims the dataset contains over 17 million records in JSON and TXT formats, aimed at instagram.com and, allegedly, affecting users worldwide. A large number of sample records cited in the post contain raw data, such as usernames, email addresses, international phone numbers, and user identifiers, which corroborates Malwarebytes’ conclusions.

Meta, the company that owns Instagram, has not yet confirmed the breach. Inquiries from CyberInsider to Meta have not yet received a response, and there is no official statement or public acknowledgment of the incident on Meta’s security pages or on its social networks at this time.

It is unclear whether the data were obtained via an open API, a vulnerability in a third-party integrator, or an internal misconfiguration. However, the leak includes records with JSON-structured fields, typical of API responses. Some records may indicate data collection from profile metadata, possibly through unsecured endpoints dating back to 2025.

Users whose details were exposed may receive legitimate-looking emails or messages asking them to reset their password or verify their identity. Malwarebytes notes that some victims are already receiving Instagram password reset notifications, which may be legitimate or part of malicious activity.

Malwarebytes offers a free digital footprint scan through its portal, which allows you to check whether your email address appears in the leak.

It is recommended to change your Instagram passwords and enable two-factor authentication (2FA) for enhanced security.

To determine whether your address is included in the leak, use Malwarebytes’ Digital Footprint tool on their portal.

It is also worth reviewing the security settings of your Instagram accounts and staying vigilant for suspicious password-reset notifications.

Extracted Entities

Attack Types (1)

Companies (1)

MITRE ATT&CK (1)