Audio By Carbonatix
Instagram has denied it has been victim to a data breach after many users received emails prompting them to reset their password.
The firm said it had resolved a problem which allowed "an external party" to get the social media platform to send out legitimate password reset requests to users.
Instagram said there had been no breach of its systems, and told users their accounts were secure.
But some experts have questioned the statement, with cyber security firm Malwarebytes claiming the password reset emails had in fact been sent as a result of a hack.
"Cybercriminals stole the sensitive information of 17.5 million Instagram accounts, including usernames, physical addresses, phone numbers, email addresses, and more," it claimed in a post on X, along with a screenshot of a password reset email from Instagram.
No further details were given by the company, but the post has been viewed more than 2.3 million times.
Malwarebytes told the BBC it believed the password reset emails were a direct result of an ongoing sale of private data on a hacker forum, where a criminal has claimed to have the personal details of 17.5 million Instagram users.
The advert claims the data comes from a "leak" in 2024.
But some security researchers think it is actually an old database that was gathered from data which could be publicly viewed - such as names and locations - in 2022.
'No breach'
The password reset emails coupled with the Malwarebytes warning has prompted confusion for thousands of people on social media.
And Instagram's explanation also posed questions.
"We fixed an issue that let an external party request password reset emails for some people," the company said.
"There was no breach of our systems."
But Instagram did not respond to the BBC's questions about who the external party was which could send out legitimate password reset requests on behalf of the firm.
The emails caused concern for some users on social media, who feared it was a scam or phishing attempt designed to glean more of their details.
But the links in the email do not appear to be malicious, and the password reset process a user is guided through appeared to be legitimate.
However the advice, as ever, is to go straight to the website or app to make changes to passwords and add extra protection.
Latest Stories
-
Anidaso Mutual Fund net assets rise 47.7% to GH¢6.31m in 2025
4 minutes -
WFP-Korea programme strengthens local economy and builds resilience in Northern Ghana
8 minutes -
GIIF’s Accra-Kumasi Expressway Ltd. SPV Initiative: A bold blueprint for financing Ghana’s infrastructure development
17 minutes -
From surviving dry spells to building resilience: Alhassan’s Story
18 minutes -
GRA targets over double revenue by 2028
29 minutes -
Black Maidens bring the jama, then bring the goals in WAFU B opener [VIDEO]
33 minutes -
GNPC Explorco showcases Voltaian Basin exploration potential at AOW:Energy 2026
38 minutes -
Black Maidens cruise past Burkina Faso in WAFU B opener
39 minutes -
Dafeamekpor calls for forensic audit after alleged GH¢600m COVID-19 fumigation gap
44 minutes -
Minority demands itemised accounts for GHS50m South Africa evacuation, pulls out of closed-door meeting
48 minutes -
Black Princesses arrive in Ghana after participating in FIFA U20 Women’s World Cup in Poland [PHOTOS]
51 minutes -
Effiduase Asokore MP sues Rev. Owusu Bempah for GH¢10m over alleged defamatory comments
56 minutes -
Chris Wilder backs Jordan Ayew to be a success at Sheffield United
1 hour -
Forestry Commission arrests 12 illegal miners, impounds three excavators in South Formangso Forest Reserve
1 hour -
Ghana’s mineral resources must benefit host communities – Lands Minister
1 hour