
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.
instagram.com
What happened
In January 2026, data allegedly scraped via an Instagram API was posted to a popular hacking forum. The dataset contained 17M rows of public Instagram information, including usernames, display names, account IDs, and in some cases, geolocation data. Of these records, 6.2M included an associated email address, and some also contained a phone number. The scraped data appears to be unrelated to password reset requests initiated on the platform, despite coinciding in timeframe. There is no evidence that passwords or other sensitive data were compromised.
Data exposed
Frequently asked questions
The Instagram data breach occurred on January 7, 2026. It was added to Have I Been Pwned's breach catalog on January 11, 2026.
6,215,150 accounts were affected by the Instagram data breach, according to Have I Been Pwned's records.
The Instagram breach exposed the following data types: Display names, Email addresses, Geographic locations, Phone numbers, Usernames.
Yes. Have I Been Pwned has verified the Instagram breach, meaning there's confirmed evidence the exposed data is genuine and tied to real accounts.
Use KazaSec's free Email Breach Checker (/tools/breach-check) to check whether a specific email address has surfaced in the Instagram breach, or any other known breach — the tool never stores what you search.
Our free Email Breach Checker tells you whether a specific email address has surfaced in this breach — or any other known breach — without ever storing what you search.
Check your email →Talk to us about this
We help organizations find and fix the gaps that lead to a breach, before they do.