Monday, April 28, 2025
HomeCyber Security NewsInstagram Hack - How Hacking Group Steals Popular Instagram Profiles

Instagram Hack – How Hacking Group Steals Popular Instagram Profiles

Published on

SIEM as a Service

Follow Us on Google News

Hackers gain targets high-profile or social media influencers Instagram accounts with phishing links and gain access to the accounts before the influencers even know what’s happening.

Based on the Trend Micro’s report the hackers target the Instagram profiles that have followers between 15,000 and 70,000 were hacked and targets range from famous actors and singers to owners of startup businesses like photoshoot equipment rentals.

Instagram Hack – Attack Chain

The attack starts with the Phishing Email that appears to be from Instagram asking the victim to verify the account to get the Verified badge on the Instagram profile.

- Advertisement - Google News

If the victim clicks on the Verify Account button then it takes the victim to the phishing page that asks for the following user details such as date of birth, email, and credentials.

Instagram Hack

“Once submitted, a badge notification appears, but for only four seconds. This is a trick to give users the impression that their profile has been verified”, reads Trend Micro blog post. But the reality is that the hackers exfiltrate the credentials.

Instagram Hack

As the user enters the credentials in the phishing page attackers get access to the credentials and by using the stolen credentials they gain access to the Instagram profiles and modify the information that requires to recover the stolen account.

Attackers use to change the username of the stolen address to indicate it is hacked and use to change the email address, again and again, to trick victim’s with security emails asking the changes were legitimate.

Researcher spotted a specific instant in which the hacker, “threatening to delete the account or never return the stolen profile unless the victim pays a ransom or sends nude photos or videos.”

Also, a hacking forum was found that tells how to manage stolen account’s so that the owners cannot get it back with the Instagram account retrieval process.

How to stay safe With Phishing

  1. Have a unique Email address.
  2. Do not open any attachments without proper validation.
  3. Don’t open emails voluntary emails.
  4. Use Spam filters & Antispam gateways.
  5. Never respond to any spam emails.
  6. Check for Grammar and font styles.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Master in Wireshark Network Analysis to keep your self-updated.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

RansomHub Ransomware Deploys Malware to Breach Corporate Networks

The eSentire’s Threat Response Unit (TRU) in early March 2025, a sophisticated cyberattack leveraging...

19 APT Hackers Target Asia-based Company Servers Using Exploited Vulnerabilities and Spear Phishing Email

The NSFOCUS Fuying Laboratory’s global threat hunting system identified 19 sophisticated Advanced Persistent Threat...

FBI Reports ₹1.38 Lakh Crore Loss in 2024, a 33% Surge from 2023

The FBI’s Internet Crime Complaint Center (IC3) has reported a record-breaking loss of $16.6...

Fog Ransomware Reveals Active Directory Exploitation Tools and Scripts

Cybersecurity researchers from The DFIR Report’s Threat Intel Group uncovered an open directory hosted...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

RansomHub Ransomware Deploys Malware to Breach Corporate Networks

The eSentire’s Threat Response Unit (TRU) in early March 2025, a sophisticated cyberattack leveraging...

19 APT Hackers Target Asia-based Company Servers Using Exploited Vulnerabilities and Spear Phishing Email

The NSFOCUS Fuying Laboratory’s global threat hunting system identified 19 sophisticated Advanced Persistent Threat...

FBI Reports ₹1.38 Lakh Crore Loss in 2024, a 33% Surge from 2023

The FBI’s Internet Crime Complaint Center (IC3) has reported a record-breaking loss of $16.6...