Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Hackers Sell Celebrity Info Obtained in Instagram Hack

Hackers claim to have obtained the personal details of millions of Instagram users, including celebrities, after exploiting a vulnerability in the Facebook-owned photo-sharing service.

Hackers claim to have obtained the personal details of millions of Instagram users, including celebrities, after exploiting a vulnerability in the Facebook-owned photo-sharing service.

The data is sold on a website named DoxAGram, which is available both via regular Web access and over the Tor network. The site’s operators, allegedly based in Russia, claim to possess information on more than 200 million of Instagram’s 700 million users.

The full database is allegedly only available to people who spend at least $5,000 on their website. However, anyone can buy the phone number and/or email address of more than 6 million celebrities and other high profile users for $10 worth of bitcoin per record. Discounts have been offered for bulk purchases.

The Daily Beast obtained a sample of data from the operators of DoxAGram and determined that email addresses allegedly belonging to celebrities are indeed associated with Instagram accounts and they are not publicly available.

DoxAGram claims it’s a “100% legal service” that serves as a data broker. “We don’t sell anything illegal only phone numbers as in phone books,” they said in a post on a Bitcoin forum.

The data was allegedly obtained using an Instagram API bug related to the password reset feature. The vulnerability was patched by Instagram after it was reported to the company by Kaspersky Lab researcher Ido Naor. A Saudi Arabian hacker using the online moniker “1337r00t” has published what he claims to be an exploit for this flaw on GitHub.

Advertisement. Scroll to continue reading.

In a blog post published on Friday, Instagram co-founder and CTO Mike Krieger said the bug was quickly fixed and law enforcement notified. Krieger confirmed that the flaw could have been used to access private email addresses and phone numbers, but highlighted that passwords and other data was not exposed.

“Although we cannot determine which specific accounts may have been impacted, we believe it was a low percentage of Instagram accounts,” Krieger explained. “Out of an abundance of caution, we encourage you to be vigilant about the security of your account, and exercise caution if you observe any suspicious activity such as unrecognized incoming calls, texts, or emails.”

DoxAGram operators pointed out that the data they are offering could also be used in some cases to hijack Instagram accounts, but they don’t provide information on how it can be done and they “don’t recommend it.” It’s unclear if the recent hack of Selena Gomez’s account involved this recently patched vulnerability.

Related: Instagram Gets Two-Factor Authentication

Related: Facebook, Researcher Quarrel Over Instagram Hack

Related: Flaws Allowed Hackers to Brute-Force Instagram Accounts

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

Explore how attackers are using AI to scale threats and how security teams can respond with AI-driven defenses. Protecting against unmonitored use of generative AI (Shadow AI) in business units and building and enforcing AI governance frameworks.

Register

People on the Move

Opal Security has appointed CPO, CTO, VP of Field Engineering, VP of Marketing, and Head of Product and Solutions Marketing.

The Department of the Air Force has appointed Ashley Devoto as Chief Information Officer.

Bartley Richardson has been named Chief AI and Autonomous Systems Officer at CrowdStrike.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.