Change Your Instagram Password Now As Third-Part Company Compromised 49 Million User Logins
A security researcher was able to provide a list of around 10,000 user accounts. The total database possessed a total of 49 million users.
We all love Instagram, sometimes even more than Facebook. However, in case you were an avid ¡®Instagrammer¡¯, it is time you change your password right now, as thousands of usernames and passwords have been leaked that could result in potential attacks from hackers.
The culprit behind this leak is a brand called Social Captain that enables users to increase their engagement and followers.
First reported by Tech Crunch, a vulnerability in the website allowed hackers to get into a user¡¯s profile without needing to log in to the Instagram login credentials. They stored users account details in a plain text format, without any kind of encryption whatsoever.
A security researcher was able to provide a list of around 10,000 user accounts. The total database possessed a total of 49 million users.
70 of those accounts were actually premium accounts of paid customers.
Social Captain later revealed that it had fixed the security vulnerability that allowed direct access to profile of users.
Instagram in its official statement admitted that the service has breached its terms of service. "We are investigating and will take appropriate action. We strongly encourage people to never give their passwords to someone they don't know or trust," said an Instagram spokesperson.
Adam Brown from Synopsis Software Integrity Group links to most of the vulnerabilities He told IANS, "They are seldom detected without performing a design review as this activity requires select expertise. That said, in this case, a penetration test should have easily identified this flaw."
He further stated, "This is especially bad for affected users not just because their Instagram passwords are now breached, but also due to the fact that people commonly reuse passwords which could lead to unauthorised access of additional accounts by extension."