Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In 2017, hackers claimed to sell Instagram users’ email addresses and phone numbers after exploiting an API flaw. Instagram said passwords were not exposed and that it had fixed the bug. Journalists verified that some records in a sample were associated with Instagram accounts, but the reports did not establish the total number of affected users or authenticate the full alleged database.

What information was exposed?

The information described in contemporaneous reports was contact details: email addresses and phone numbers. Instagram said an API bug had allowed unlawful access to contact details for some high-profile users. The company stated, “No account passwords were exposed,” according to The Daily Beast’s August 31, 2017 report.

Instagram also said it had fixed the bug and was investigating. SecurityWeek reported that law enforcement had been notified. These were statements about the company’s response at the time, not evidence that every affected account or record had been identified.

What did DoxAGram claim, and what was verified?

The operators’ database claims

A site called DoxAGram appeared in August 2017 offering contact information it claimed came from Instagram accounts. SecurityWeek reported the operators’ claim that the data covered more than 200 million users. The Daily Beast separately reported that the operators claimed to have more than six million accounts in their database and that the publication had not seen the complete alleged list. These are distinct claims reported by different outlets, not confirmed breach totals.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The sample journalists checked

The Daily Beast said DoxAGram supplied a sample of 1,000 alleged accounts. The publication tested a random selection of email addresses by attempting to create Instagram accounts with them; each was already associated with an Instagram account. It also checked selected contact details and account associations. Those checks support the authenticity of some sample records, but they do not verify the full database or establish how many accounts were affected.

Figure What it describes Evidence and qualification
More than 200 million users DoxAGram operators’ claimed reach Reported by SecurityWeek in 2017; not an independently verified total.
More than six million accounts DoxAGram operators’ separate database claim Reported by The Daily Beast in 2017, which said it had not seen the full alleged list.
1,000 alleged accounts Sample provided to The Daily Beast Reported sample size, not a count of affected accounts.

Neither report established a definitive number of affected accounts. The operators’ figures should not be combined: they were different claims, presented by separate reports, and neither was confirmed as the breach count.

How was the API flaw discovered and addressed?

SecurityWeek reported that Kaspersky Lab researcher Ido Naor reported the flaw and that Instagram patched it. Instagram co-founder and CTO Mike Krieger said, “Although we cannot determine which specific accounts may have been impacted, we believe it was a low percentage of Instagram accounts,” as quoted by SecurityWeek on September 5, 2017. The company’s stated inability to identify specific affected accounts is one reason the public reporting did not settle the incident’s full scope.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Was the Selena Gomez account takeover connected?

The Daily Beast noted that the incident’s timing overlapped with the takeover of Selena Gomez’s Instagram account and a post involving Justin Bieber. The reporting did not establish that the takeover used the API flaw, so a connection remains unconfirmed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When did the reports appear?

  • August 31, 2017: The Daily Beast published its investigation, including its checks of a sample and Instagram’s statement about the bug and response.
  • September 5, 2017: SecurityWeek reported on the alleged sale, the operators’ claimed database size, and the reported API flaw and patch.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.