Facebook reveals 'millions' of Instagram passwords were exposed

Yikes.
 By 
Karissa Bell
 on 
Facebook reveals 'millions' of Instagram passwords were exposed
Millions of Instagram passwords were exposed by Facebook. Credit: Chesnot / Getty Images

Welp, it looks like millions of Instagram accounts were left out in the open for Facebook employees to see.

A full month after Facebook admitted it mistakenly stored hundreds of million of passwords in plaintext where employees could see them, the company quietly added a significant update: that millions of Instagram passwords were also affected.

"Since this post was published, we discovered additional logs of Instagram passwords being stored in a readable format," Facebook wrote. "We now estimate that this issue impacted millions of Instagram users. We will be notifying these users as we did the others. Our investigation has determined that these stored passwords were not internally abused or improperly accessed."

The company did not offer an explanation on why it took four weeks for this additional piece of information to be added to its initial disclosure, or why it chose to do so at almost exactly the same time as the entire freaking Mueller report dropped.

The initial password issue was only disclosed after KrebsOnSecurity revealed its existence thanks to an anonymous tipster. About 20,000 employees had access to the passwords, according to his sources. Now, we know "millions" of Instagram passwords were also floating around for employees to find, though Facebook says it's found no evidence of that happening.

But even though Facebook claims nothing nefarious came of the blunder, it's alarming that the company would be so careless with Instagram passwords. Many Instagram users are already deal with frequent hacking attempts, and users whose accounts are hacked are often unable to get them back because of Instagram's flawed support system. That so many passwords were exposed doesn't support the company's assertions that it cares about its users' security.

It's equally troubling that the company would wait for one of the most momentous political events in recent memory to disclose the information and would bury it in a month-old press release. Instagram says it will notify those affected directly, so all users should probably keep an eye out for any emails from Instagram. (And, needless to say, if you do get such an email from Facebook, you should definitely change you password.)

Mashable Image
Karissa Bell

Karissa was Mashable's Senior Tech Reporter, and is based in San Francisco. She covers social media platforms, Silicon Valley, and the many ways technology is changing our lives. Her work has also appeared in Wired, Macworld, Popular Mechanics, and The Wirecutter. In her free time, she enjoys snowboarding and watching too many cat videos on Instagram. Follow her on Twitter @karissabe.

Mashable Potato

Recommended For You
Sears AI chatbot chats and audio files found exposed online
A general view of newly reopened Sears department store in Downtown Burbank

Viral anti-masturbation app exposed sensitive user data
person browsing a porn site on laptop

How hackers are stealing millions from ATMs, FBI warns
a card being inserted into an atm

Grok is producing millions of sexualized images of adults and children
A sign next to bus stop in London reads "Who the hell would want to use social media with a built-in child abuse tool?" and a photo of Elon Musk.

Adult performer Siri Dahl doxxed by Grok: 'Go f*ck yourself you nazi clanker'
siri dahl appears at an event

More in Tech
How to watch Chelsea vs. Port Vale online for free
Alejandro Garnacho of Chelsea reacts

How to watch 'Wuthering Heights' at home: Margot Robbie and Jacob Elordi's controversial romance now streaming
Margot Robbie and Jacob Elordi embracing in still from "Wuthering Heights"

How to watch New York Islanders vs. Philadelphia Flyers online for free
Matthew Schaefer of the New York Islanders warms up

How to watch Mexico vs. Belgium online for free
Israel Reyes of Mexico reacts

How to watch Brazil vs. Croatia online for free
Vinicius Junior #10 of Brazil leaves

Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone

Google launches Gemma 4, a new open-source model: How to try it
Google Gemma

What's new to streaming this week? (April 3, 2026)
A composite of images from film and TV streaming this week.

NYT Strands hints, answers for April 3, 2026
A game being played on a smartphone.
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!