Instagram denies data breach of 17 million users after password reset email wave — here's what to do next

Instagram app logo on a phone display
(Image credit: Shutterstock)

Instagram users across the platform received unexpected password reset emails over the weekend, triggering widespread alarm about a potential security breach. The unsolicited requests arrived in inboxes without warning, and according to Malwarebytes, 17.5 million users are affected.

Social media exploded with speculation that Instagram had been hacked, with users questioning whether their accounts and personal information had been compromised. Instagram has since responded to the concerns, clarifying that no data breach occurred and that the issue has been resolved.

Avoid clicking on this email

(Image credit: Tom's Guide)

If you received a password reset email like this one, don't click any links or buttons inside it, even if it looks legitimate.

These emails can lead to phishing sites designed to steal your login credentials. Attackers create fake Instagram login pages that look identical to the real thing, and once you enter your password on these fake sites, they immediately capture it.

Even if the email came from Instagram legitimately during this incident, clicking links in unsolicited emails trains you to trust unexpected communications, making you more vulnerable to future phishing attempts.

What Instagram says happened

Instagram posted on X stating that it "fixed an issue that let an external party request password reset emails for some people." The company emphasized that "there was no breach of our systems and your Instagram accounts are secure," advising users to simply ignore the emails.

However, Instagram didn't explain how an external party managed to trigger password reset requests without accessing Instagram's systems.

Some outlets, such as CyberInsider, have suggested the incident may be connected to a 2024 Instagram API breach that leaked data from over 17 million users — including usernames, phone numbers, and email addresses.

If this leaked data was used to trigger password resets, it would explain how an external party could initiate requests without directly hacking Instagram. Instagram hasn't confirmed or denied this connection.

How to change your Instagram password

Regardless of whether this incident directly affected you, changing your Instagram password is smart security practice, especially if you haven't updated it recently.

Don't click any links in password reset emails — instead, change your password directly through the Instagram app by following the steps below.

Step 1)

Open Instagram and go to Settings and activity by tapping the three lines in the top right corner.

Step 2)

Tap Accounts Center, then select Password and security.

Step 3)

Tap Change password and choose your Instagram account if you have multiple accounts linked

Step 4)

Enter your current password, then create a new strong password. Use a combination of letters, numbers, and symbols that you don't use for other accounts. Avoid using personal information like birthdays or names that could be guessed.

After changing your password, you'll be logged out of all devices and will need to sign back in.

Set up two-factor authentication immediately

Two-factor authentication (2FA) is the most important security measure you can enable. With 2FA active, no one can access your account with just your password — they'll also need an authentication code.

Go to Settings and activity, Accounts Center, Password and security, and Two-factor authentication. Then simply select your Instagram username and choose your authentication method.

Authenticator apps (like Google Authenticator or Authy) are more secure than SMS since phone numbers can be hijacked, but SMS is better than nothing. Once enabled, anyone logging in from an unrecognized device will need both your password and the authentication code.


Google

(Image credit: Future)

Follow Tom's Guide on Google News and add us as a preferred source to get our up-to-date news, analysis, and reviews in your feeds. Make sure to click the Follow button!


More from Tom's Guide

Category
Arrow
Arrow
Back to Mobile Cell Phones
Brand
Arrow
Storage Size
Arrow
Colour
Arrow
Minimum Price
Arrow
Any Minimum Price
Maximum Price
Arrow
Any Maximum Price
Showing 10 of 159 deals
Filters
Arrow
(256GB Silver)
Our Review
1
iPhone 17 Pro Max 256GB Silver
Amazon
(256GB Black)
Our Review
2
Samsung Galaxy S25 Ultra,...
Amazon
(128GB)
Our Review
3
Google Pixel 10 Pro -...
Amazon
Our Review
4
Google Pixel 9a with Gemini -...
Amazon
bundle
(256GB Silver)
Our Review
5
Apple iPhone 17 Pro Max 256GB...
Verizon
(256GB)
Our Review
6
Samsung Galaxy S25 Ultra...
Samsung
bundle
(256GB Black)
Our Review
7
Google Pixel 10 Pro 256GB in...
Verizon
(128GB)
Our Review
8
Google - Pixel 9a 128GB...
Best Buy
(256GB Orange)
Our Review
9
Apple iPhone 17 Pro Max 256...
Visible
(Black)
Our Review
10
Samsung Galaxy S25 Ultra...
Mint Mobile
Show more
Kaycee Hill
How-to Editor

Kaycee is Tom's Guide's How-To Editor, known for tutorials that skip the fluff and get straight to what works. She writes across AI, homes, phones, and everything in between — because life doesn't stick to categories and neither should good advice. With years of experience in tech and content creation, she's built her reputation on turning complicated subjects into straightforward solutions. Kaycee is also an award-winning poet and co-editor at Fox and Star Books. Her debut collection is published by Bloodaxe, with a second book in the works.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.