Monday, August 3, 2026

Apps & Consumer

Instagram denies data breach despite security claims

Instagram denies a data breach occurred, stating it only fixed a bug allowing unauthorized password reset requests, contradicting claims that 17.5 million accounts were compromised.

Instagram denies data breach despite security claims

Instagram has officially denied that a data breach occurred on its platform. The denial directly contradicts a report from the antivirus software company Malwarebytes, which alleged that a security compromise had taken place. On Friday, Malwarebytes, an antivirus software company, posted about the alleged breach on Bluesky, claiming, “Cybercriminals stole the sensitive information of 17.5 million Instagram accounts, including usernames, physical addresses, phone numbers, email addresses, and more.” To support its claim, the antivirus firm shared a screenshot of an email sent by Instagram to its users, which informed them of a request to reset their account passwords. This email, which was sent directly to users, served as the basis for the security firm’s public warning.

According to Malwarebytes, the stolen data is available for sale on the dark web and can be abused by cybercriminals. Instagram, however, disputed this claim, maintaining that no database breach had occurred. Instead, the company clarified that it fixed an issue that let an external party request password reset emails for some people. While Instagram did not offer details about the external party involved or the specific issue that allowed the requests, it sought to reassure users who received the notifications. In its public statement, the company wrote that users can ignore those emails and apologized for any confusion. By framing the incident as a resolved password-reset issue rather than a system compromise, Instagram addressed the security firm’s allegations.

The dispute and the resulting communications played out across several competing social media platforms. While Malwarebytes chose to post its allegations on Bluesky, a decentralized social network, Instagram chose to address the security concerns on X, the platform formerly known as Twitter. The company did not utilize its own network or Threads, the social media platform owned by Meta, for the response. This reliance on external channels for security updates underscores the dynamics of public relations and communication between social media platforms and independent cybersecurity researchers. The choice of platforms also highlights how tech companies navigate communication during security incidents, bypassing their own networks to reach audiences on third-party services.

Why it matters

This incident highlights the ongoing tension between third-party security researchers and platform transparency, leaving users to navigate conflicting reports regarding the safety of their personal data.