Instacart insists it's probably your fault if your account got hacked

With Instacart customer data being sold on the dark web, the company wants you all to know that it's not at fault.
 By 
Jack Morse
 on 
Instacart insists it's probably your fault if your account got hacked

Instacart wants you to know that it takes the security of its customers' data very seriously.

With that in mind, the grocery-delivery dispatcher announced Thursday that if your account data is among the scores reportedly being sold on the dark web. then it's probably your fault.

According to the late afternoon blog post, a number of Instacart customers likely fell victim to what is known as credential stuffing. In no way, Instacart insists, was its platform "compromised or breached."

For the blissfully unaware, credential stuffing is a form of hacking that relies on victims reusing the same password across multiple online accounts (which people tend to do). So, if hackers manage to get ahold of emails and passwords from one service — like, possibly, TicketFly — they can then try those combinations en masse on a host of other platforms.

That, Instacart claims, is what it believes happened to its customers.

"In this instance, it appears that third-party bad actors were able to use usernames and passwords that were compromised in previous data breaches of other websites and apps to login to some Instacart accounts," reads the blog post. "In some instances, this would have given the third party bad-actors access to basic customer account information such as first name, address, last order, total order number, and in some cases, the last four digits of a customer's credit card."

Of course, if Instacart offered two-factor authentication (and people used it) then this entire mess could have been avoided. As far as we can tell, Instacart does not offer this standard security feature. Its help page makes no mention of it, for starters. We also created an account, and attempted to enable the feature to no avail.

We reached out to the company for comment and to confirm that it does not offer 2FA, but received no immediate response.

Instacart doesn't get into specifics about how many customers were affected (we also asked that when we reached out to the company), but thankfully a Wednesday report from BuzzFeed News does. According to the publication, "sellers in two dark web stores were offering information from what appeared to be 278,531 accounts, although some of those may be duplicates or not genuine."

SEE ALSO: Instacart will provide 'safety kits' to Shoppers, but still no hazard pay

That, if Instacart is to be believed, represents a lot of reused passwords.

Thankfully, however, its customers can rest easy knowing that the "security of [Instacart's] customers' accounts and data is a top priority," and that Instacart thinks this entire mess was probably their fault anyway.

Topics Cybersecurity

Mashable Image
Jack Morse

Professionally paranoid. Covering privacy, security, and all things cryptocurrency and blockchain from San Francisco.

Mashable Potato

Recommended For You
Save on groceries with these markdowns on Instacart gift cards
instacart gift card on pink background

The European Commission got hacked for the second time this year
Europe flag

GE unveils smart fridge with barcode scanner linked to Instacart for delivery
person scanning item with GE smart fridge barcode scanner

The Epstein Files: Read Epstein's emails as if you hacked into his Gmail with Jmail
Jmail World

How to delete your AdultFriendFinder account
By Jack Dawes
Scrubbing floor with rubber

Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone

What's new to streaming this week? (April 3, 2026)
A composite of images from film and TV streaming this week.


NYT Connections hints today: Clues, answers for April 2, 2026
Connections game on a smartphone
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!