On January 7, 2026, a dataset of 17.5 million Instagram user records appeared on BreachForums, including names, emails, phone numbers, and partial location data. Meta denied any breach, claiming the data came from API scraping rather than a system compromise. The post explains how API scraping works—through distributed IP

14m read timeFrom securityboulevard.com
Post cover image
Table of contents
What Actually HappenedWhat Data Was ExposedHow API Scraping Actually WorksMeta's Denial vs. User RealityWhy This Keeps HappeningWhat Users Should Do Right NowWhat Instagram/Meta SHOULD DoThe Bigger Picture: API Security Is BrokenThe Bottom LineKey Takeaways

Sort: