Instagram Password Reset Request Surge Sparks 17.5M Account Breach Controversy
Instagram denies a major security breach despite Malwarebytes claiming 17.5M accounts were compromised. Learn about the Instagram password reset request surge in 2026.
"The emails are real, but the breach isn't."Instagram is pushing back against claims of a massive data heist following a mysterious surge in password reset requests sent to users worldwide. While the company admits to a technical flaw, it's maintaining that user data remains secure.
Investigating the Instagram Password Reset Request Anomaly
On January 11, 2026, Instagram officially stated that it had not been breached, despite reports from the antivirus firm Malwarebytes suggesting otherwise. According to Malwarebytes, sensitive information from 17.5 million accounts—including usernames, physical addresses, and phone numbers—was reportedly listed for sale on the dark web. Instagram countered this by explaining it had simply fixed a bug that allowed an "external party" to trigger these automated emails for some users.
Conflicting Claims: Meta vs. Security Experts
The discrepancy between Meta's official stance and the findings of external security firms has left many users uneasy. Malwarebytes shared screenshots of official-looking emails that were supposedly part of a larger credential-harvesting operation. While Instagram hasn't provided details on who this "external party" was, they've reassured the public that the loophole is now closed. Critics, however, are calling for more transparency regarding how millions of reset requests could be triggered without a deeper security compromise.
This content is AI-generated based on source articles. While we strive for accuracy, errors may occur. We recommend verifying with the original source.
Related Articles
Booking.com confirmed a data breach exposing names, emails, addresses, phone numbers, and booking details. Hackers are already using the data for phishing attacks.
Two court losses in two days mark a turning point for Meta's legal exposure on child safety. The tobacco playbook is working — and thousands more cases are waiting.
Two US juries held Meta liable for hundreds of millions in damages for harming minors. The verdicts challenge Big Tech's long-standing legal shields—and could redraw the rules for every platform on earth.
P3 Global Intel, which powers anonymous crime tip systems for law enforcement worldwide, suffered a major breach. The implications go far beyond a typical data leak.
Thoughts
Share your thoughts on this article
Sign in to join the conversation