Instagram Leak From API Spills High Profile User Info

Use Netsparker


Another high profile Instagram leak, this time no there’s actual tangible repercussions other than it could possibly link to the recent Justin Bieber nudes leaked via a compromise of Selena Gomez’s account.

Instagram Leak From API Spills High Profile User Info

There isn’t a whole lot of details about what actually happened, in terms of what went wrong with the API? A wild guess would be some kind of authentication or token bug in the API that allowed you to access certain information about other users that you weren’t supposed to be able to get access to.

Instagram is blaming a bug in its API for the partial breach of verified users’ accounts.

All verified users have been notified that some of their profile data – email address and phone number – could have been viewed by one or more attackers.

The Facebook-owned organisation isn’t explaining any details of the API flaw, which it says has been patched. It’s not clear, for example, whether the API only leaked verified members’ details, or that attackers only dug into verified accounts because they’re more likely to be celebrities.

The notice to users says the malicious activity “was targeted at high-profile users,” and added extra vigilance, particularly if anyone encountered “unrecognised incoming calls, texts, and e-mails”.


It could be possible the Selena Gomez compromise was linked to this indirectly if an attacker managed to get her private contact details through the API then used those to social engineer their way into the account, or even took control exploiting an SS7 flaw to grab SMS OTPs.

As per usual though with no details all we are doing is speculating, and as it’s been fixed it’s very unlikely any details will be forthcoming – this is not the first Instagram leak and it won’t be the last.

As entertainment industry bible Variety has reported, someone recently hijacked actor Selena Gomez’s account to post Justin Beiber nudes.

While it’s feasible that Gomez was tricked into giving her credentials to an attacker who’d obtained her e-mail or phone number through the API bug, there’s nowhere near enough information to definitively link the two events.

The New York Daily News says Instagram confirmed to it that only one attacker had tried to exploit the bug.

Perhaps they should have been using something like Scumblr by Netflix to search their own API..

Facebook is a huge company with so many moving parts, it’s hard to see everything – there will be flaws, they will be found and they will be exploited. That’s just the nature of the Internet machine.

Source: The Register

Posted in: Hacking News, Privacy


Latest Posts:


Intercepter-NG - Android App For Hacking Intercepter-NG – Android App For Hacking
Intercepter-NG is a multi functional network toolkit including an Android app for hacking, the main purpose is to recover interesting data from the network stream and perform different kinds of MiTM attacks.
dcipher - Online Hash Cracking Using Rainbow & Lookup Tables dcipher – Online Hash Cracking Using Rainbow & Lookup Tables
dcipher is a JavaScript-based online hash cracking tool to decipher hashes using online rainbow & lookup table attack services.
HTTP Security Considerations - An Introduction To HTTP Basics HTTP Security Considerations – An Introduction To HTTP Basics
HTTP is ubiquitous now with pretty much everything being powered by an API, a web application or some kind of cloud-based HTTP driven infrastructure. With that HTTP Security becomes paramount and to secure HTTP you have to understand it.
Cangibrina - Admin Dashboard Finder Tool Cangibrina – Admin Dashboard Finder Tool
Cangibrina is a Python-based multi platform admin dashboard finder tool which aims to obtain the location of website dashboards by using brute-force, wordlists etc.
Enumall - Subdomain Discovery Using Recon-ng & AltDNS Enumall – Subdomain Discovery Using Recon-ng & AltDNS
Enumall is a Python-based tool that helps you do subdomain discovery using only one command by combining the abilities of Recon-ng and AltDNS.
RidRelay - SMB Relay Attack For Username Enumeration RidRelay – SMB Relay Attack For Username Enumeration
RidRelay is a Python-based tool to enumerate usernames on a domain where you have no credentials by using a SMB Relay Attack with low privileges.


Comments are closed.