Data linked to roughly 17.5 million Instagram accounts has resurfaced on the dark web, reviving a privacy and security issue that originally traces back to 2024. According to a security notice from cybersecurity firm Malwarebytes, the dataset was reposted in early January 2026 on Breachforums by a threat actor using the alias “Solonik.” The exposed records were reportedly collected through a misconfigured Instagram API in late 2024, which enabled large-scale scraping of user profile information rather than a fresh platform compromise.
Not a new breach, but a renewed threat
Malwarebytes said the recycled dataset includes usernames, email addresses, phone numbers, physical addresses, and account metadata. Even though the information is not from a newly disclosed incident, its reappearance significantly raises current risk levels. As the data circulates more widely, it can be used by scammers, identity thieves, and phishing operators. The report added that as of Jan. 10, Meta had not issued a public statement, while reports of unsolicited Instagram password reset emails were increasing.
Attackers are abusing legitimate reset flows
A key concern is that bad actors are not limited to fake messages. They may also trigger Instagram’s real password reset process, causing genuine emails from the platform’s actual security domain to land in users’ inboxes. That makes the attack far more convincing. With enough personal information, attackers can move beyond basic phishing into SIM-swapping attempts, targeted fraud, and account takeover efforts, especially for users who reuse passwords across multiple services.
Basic defenses remain the best response
Malwarebytes said the issue was identified during routine dark web monitoring, underscoring how old leaked data can still power very current attacks. While confirmed impact has been reported in parts of Europe, the broader risk is global. For affected users, the recommended response is straightforward: reset passwords immediately, use strong and unique credentials, enable two-factor authentication, and treat urgent email prompts with caution. The leak may be old, but the damage it can enable is very real today.

