Saturday, April 5, 2025
HomeCyber Security NewsThreat Actors Allegedly Claim Leak of 489 Million Lines of Instagram Data

Threat Actors Allegedly Claim Leak of 489 Million Lines of Instagram Data

Published on

SIEM as a Service

Follow Us on Google News

A threat actor has allegedly scraped 489 million lines of Instagram user data, including sensitive information, which is now reportedly being sold on the dark web.

DarkWebInformer’s official X account revealed the alarming incident, raising concerns over the scale and potential impact of the breach.

The compromised data includes many user details, such as usernames, email addresses, follower counts, following counts, and other personal information.

Build an in-house SOC or outsource SOC-as-a-Service -> Calculate Costs

While Instagram or its parent company, Meta, have not officially confirmed this, the threat actor claims the data trove is being offered for sale, sparking fears of its potential misuse for phishing attacks, identity theft, or other malicious purposes.

According to the report, the data leak does not include passwords or direct messages, but cybercriminals could still leverage the exposed personal information for targeted attacks.

The staggering number of affected users raises concerns for individual privacy and businesses and influencers who rely heavily on Instagram for their online presence.

This incident follows a growing data scraping trend in which automated bots gather publicly available information from social media platforms on a massive scale.

While scraping does not involve direct hacking or breaching secure databases, it still poses significant security risks, especially when data is aggregated and sold for malicious use.

Experts advise Instagram users to remain vigilant, especially regarding phishing attempts that may arise from this leaked information.

Users are encouraged to enable two-factor authentication (2FA), review their privacy settings, and be cautious of unsolicited emails or messages.

As the situation unfolds, cybersecurity experts call for stricter measures to prevent similar incidents and protect user data on social media platforms.

Run private, Real-time Malware Analysis in both Windows & Linux VMs. Get a 14-day free trial with ANY.RUN!



Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Latest articles

Ivanti Fully Patched Connect Secure RCE Vulnerability That Actively Exploited in the Wild

Ivanti has issued an urgent security advisory for CVE-2025-22457, a critical vulnerability impacting Ivanti...

Beware! Weaponized Job Recruitment Emails Spreading BeaverTail and Tropidoor Malware

A concerning malware campaign was disclosed by the AhnLab Security Intelligence Center (ASEC), revealing...

EncryptHub Ransomware Uncovered Through ChatGPT Use and OPSEC Failures

EncryptHub, a rapidly evolving cybercriminal entity, has come under intense scrutiny following revelations of...

PoisonSeed Targets CRM and Bulk Email Providers in New Supply Chain Phishing Attack

A sophisticated phishing campaign, dubbed "PoisonSeed," has been identified targeting customer relationship management (CRM)...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Ivanti Fully Patched Connect Secure RCE Vulnerability That Actively Exploited in the Wild

Ivanti has issued an urgent security advisory for CVE-2025-22457, a critical vulnerability impacting Ivanti...

Beware! Weaponized Job Recruitment Emails Spreading BeaverTail and Tropidoor Malware

A concerning malware campaign was disclosed by the AhnLab Security Intelligence Center (ASEC), revealing...

EncryptHub Ransomware Uncovered Through ChatGPT Use and OPSEC Failures

EncryptHub, a rapidly evolving cybercriminal entity, has come under intense scrutiny following revelations of...