INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Meta's Instagram Password Reset System Crashes

| 2026-01-11 23:43 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
A series of high-profile cyberattacks occurred in January 2026, with Meta's Instagram service being targeted by third-party attackers who exploited a vulnerability allowing them to generate password reset emails. The attack resulted in the theft of sensitive information from approximately 17.5 million Instagram accounts, including usernames, physical addresses, phone numbers, email addresses, and more. This was likely facilitated by an API leak detected in 2024, which exposed user data on notorious data leak site BreachForums. Meanwhile, a ransomware attack on gas station chain Handi revealed the exposure of customer data from around 377,082 sets of customers, including names, social security numbers, contact information, and driver's license numbers. The attackers exploited vulnerabilities in Veeam, a popular data management and backup vendor, which was patched by the company last week after four critical flaws were discovered, one of which scored a 9.0 on the CVSS scale.
Technical Mitigations AI-generated
• Patch CVE-2025-59470 in Veeam Backup and Tape Operator accounts to prevent RCE attacks. • Block or hunt for dark web posts offering bribes to insiders, as reported by Nord Stellar. • Monitor for API leaks like the one detected in 2024 that may expose user data.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-59470CVE-2025-59470
Target & Sectors
Global Scope educationeducation technologytechnology
Incident Timeline
‎2026/01/11
Threat actors obtained user credentials via infostealer malware to log in to ownCloud accounts without MFA, exposing sensitive information of 17.5 million Instagram users.
victims 17 Instagram users
infrastructure 17.5
Tactical Metrics
Metrics
victims
17,000,000
Instagram Users
Metrics
infrastructure
​17.5
Software Version
Intelligence Sources
The Register - Cybercrime 2026-01-11