Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

Instagram fixed password reset bug, denies data leak

Instagram said it has not experienced a security breach after some users reported receiving password reset requests.

The company addressed concerns after a post by Malwarebytes, an antivirus software firm, which claimed that data from 17.5 million Instagram accounts was stolen and is being sold on the dark web.

Instagram later said on X that it resolved an issue allowing an external party to trigger password reset emails for some users.

No evidence has been presented confirming a breach or the sale of sensitive account information.

🔗 Source: TechCrunch

🧠 Food for thought

Implications, context, and why it matters.

Reports of an Instagram dataset for sale; origin remains unclear

  • Malwarebytes says a seller is offering data from 17.5 million Instagram accounts on the dark web, with emails, phone numbers, usernames, and partial locations 1. Another report ties the handle Subkek on cybercrime forums to it 1.
  • The seller says the trove came from Q4 2024 scraping (automated collection of public info) of public pages or sign-up forms, not a system breach 1.
  • Instagram fixed a quirk that let outsiders trigger password reset emails and says its systems were not breached 2.
  • The reset-email wave and the dataset surfaced around the same time, but no independent review or Meta (Instagram’s parent company) notice confirms a breach 21.

Reset-flow abuse, inbox flooding, and defense impact

  • Recent reset-email bursts come from reset-flow abuse (abusing the account recovery process to send unsolicited resets) and can mix with subscription or email bombing (mass sign-ups that flood inboxes), not the classic multi-factor authentication (MFA) push bombing 3.
  • Campaigns can ride past weak rate limiting (controls that cap how many requests can be made in a short period), and Apple users saw waves of unwanted reset prompts that researchers tie to rate-limit gaps 4.
  • Security vendors (security software companies, service providers) are rolling out tools that spot and slow email bombing, which can guide defenses for reset-flow plus credential or account-recovery abuse 3. Microsoft added MFA number matching to blunt fatigue attacks, and buyers want focused controls plus clear user alerts to mitigate account takeover 43.

Recent Instagram developments

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.