Massive Data Leak Surfaces on Dark Web
More than 17.5 million Instagram users’ personal details have reportedly been exposed and are now circulating among cybercriminals. According to a report by cybersecurity company Malwarebytes, the leaked database includes usernames, home addresses, phone numbers and email IDs.
The company has warned that this data is being sold on the dark web, increasing the risk of phishing attacks, identity theft and account hacking.
Breach Linked to 2024 API Security Flaw
Malwarebytes said it detected the leak during its routine dark web monitoring. Preliminary analysis suggests the data exposure is linked to a security loophole in Instagram’s API in 2024. APIs are tools that allow apps and services to communicate with each other, and vulnerabilities in them can sometimes be exploited by attackers.
Security experts believe hackers can misuse this information to target users with highly convincing scams.
India Could Be Among the Most Affected
India is Instagram’s largest user market, with around 480 million users as of late 2025, according to Statista. Since Meta also has over 500 million Facebook and WhatsApp users in the country, cybersecurity experts fear that a significant number of Indian users could be impacted if their data is part of the leaked set.
How Hackers Can Exploit This Data
Experts warn that cybercriminals can use the leaked information for:
- Phishing: Sending fake emails or messages that look real to steal passwords or money
- Account takeover: Hijacking Instagram accounts using leaked details
- Credential stuffing: Trying the same passwords on other services like Facebook, Netflix or even banking apps if users reuse passwords
Meta Denies Data Breach
Meta has rejected claims of a data breach. A company spokesperson said:
“We fixed an issue that allowed an external party to request password reset emails for some Instagram users. There has been no data breach and users’ accounts remain secure.”
However, cybersecurity researchers continue to investigate the origin and authenticity of the leaked dataset.
What Users Should Do Now
Experts advise users to:
- Change passwords immediately
- Enable two-factor authentication (2FA)
- Avoid clicking suspicious links
- Use different passwords for different platforms

