A significant data breach has exposed the personal information of approximately 17.5 million Instagram users, with details including usernames, email addresses, phone numbers, and physical addresses now reportedly available for sale on the dark web. The breach, identified by Malwarebytes during routine dark web monitoring, has led to a surge in password reset emails sent to affected users and raised concerns about the potential for phishing, account takeovers, and more severe real-world threats such as stalking and extortion. Security researchers note that the leaked data appears to be more comprehensive than previous incidents, with attackers possibly correlating Instagram user IDs with external data sources to link online identities to real-world addresses.
The compromised database, described as a "doxxing kit," is being sold in batches on cybercrime forums, increasing the risk of targeted attacks against those affected. While Meta has not yet issued an official statement regarding the incident, security experts warn that the exposure of physical addresses alongside digital identifiers significantly elevates the privacy and safety risks for users. The breach underscores the importance of enabling two-factor authentication and monitoring for suspicious account activity, as the stolen data is actively circulating and may be used for a range of malicious purposes beyond typical credential abuse.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Have I Been Pwned published an entry for the Instagram incident, describing a January 2026 forum post containing about 17 million rows of scraped public account data. HIBP said about 6.2 million records included email addresses, some included phone numbers, and there was no evidence that passwords were exposed.
Follow-up reporting and researcher analysis concluded there was no evidence of a new Instagram breach in January 2026. The dataset being marketed as a fresh API leak was assessed to be a repackaged compilation of previously scraped data, likely unrelated to the password reset email activity.
Instagram's parent company Meta publicly denied that Instagram had suffered a breach and said accounts remained secure. It stated that it fixed an issue that allowed an external party to mass-trigger password reset emails for some users and advised recipients to ignore those messages.
Around the same time the dataset claims spread, Instagram users in multiple countries reported receiving repeated password reset emails they did not request. The surge fueled fears of account compromise, although later reporting said the reset-email issue was separate from the recycled dataset.
During routine dark web monitoring, Malwarebytes identified a large Instagram-related dataset being offered for sale on cybercrime forums and warned that it affected roughly 17 to 17.5 million accounts. The company said the data included usernames and various personal details such as email addresses, phone numbers, and physical addresses.
On January 7, 2026, a BreachForums user reposted the old 17 million-record Instagram dataset under the title '2024 API LEAK,' rebranding it as a fresh breach. The same data also appeared on LeakBase around the same time, helping trigger renewed attention.
Hackread reported that the same 17,017,213-record dataset later discussed in January 2026 was first posted publicly in June 2023. The file was associated with an earlier BreachForums user and matched the records later recirculated as a supposed new leak.
Multiple reports and researchers assessed that the 17 million-record Instagram dataset was not newly stolen in 2026 but originated from scraping activity in 2022. The data appears to have been compiled from public Instagram information and, in some cases, enriched with additional contact details from other sources.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcetechrepublic.com
Open sourcescworld.com
Open sourcehelpnetsecurity.com
Open sourcehackread.com
Open sourcebleepingcomputer.com
Open sourceengadget.com
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.