Instagram has announced that it has resolved the problem related to suspicious password reset emails.
Days after many users reported suspicious password reset emails, Instagram announced that the issue has been resolved.
Recently, numerous Instagram users received emails regarding password reset requests. Concurrently, reports surfaced that cybercriminals had obtained personal information from over 17 million users, with the recent phishing emails for password resets being connected to this breach. Instagram claims the problem has been addressed but denies any data breach has occurred.
What transpired?
A variety of users on platform X, including HaveIBeenPwned's founder Troy Hunt, shared screenshots of the questionable Instagram password reset emails they received. Additionally, cybersecurity firm Malwarebytes informed that hackers had stolen personal information from millions of users, with data—such as usernames, physical addresses, phone numbers, and email addresses—being sold on the dark web.
"We fixed an issue that enabled an external party to request password reset emails for some individuals. There was no compromise of our systems, and your Instagram accounts are safe. You can disregard those emails — we apologize for any confusion," stated Instagram (@instagram) on January 11, 2026.
According to Instagram, the issue has been resolved, allowing users to safely ignore the emails. The company reaffirmed on X that there was no data breach that compromised user personal data. However, it is advisable to change your Instagram password via the app’s accounts center, especially if two-step authentication hasn’t been enabled.
How to ensure safety?
Scammers often impersonate businesses or customer support representatives to coax users into disclosing their personal information. The recent series of password reset emails to Instagram users is an example of such tactics. Links in these emails can lead to pages where hackers either mimic legitimate websites or create various traps to acquire sensitive information, including login credentials and credit card numbers.
The initial step is to verify the sender’s email address and check for any unusual spelling mistakes. It is wise to confirm these addresses against the official support page of the respective company or service. Furthermore, look for a blue checkmark next to the email address, as legitimate companies, including Instagram, utilize these checkmarks.
As a general practice, avoid clicking on any links or buttons in suspicious password emails unless you can confirm the sender’s identity. Also, ensure your accounts are secured with multi-factor or two-factor authentication, with passkeys being one of the most convenient and secure methods, locking identity verification behind biometric checks such as face or fingerprint recognition.
Other articles
Instagram has announced that it has resolved the problem related to suspicious password reset emails.
Many Instagram users have reported receiving questionable password reset emails following claims of a significant data scrape. The social media platform asserts that the problem has been addressed, but it denies any occurrence of a data breach.
