# Instagram Web Password-Reset Logic Bug — Unredacted Email & Phone Disclosure (June 2026)

> A business-logic flaw in Instagram's web-based password-reset/account-recovery flow returned fully unredacted email addresses and phone numbers in place of the normally masked recovery options. Triggered by initiating a standard password reset for any username, it was demonstrated against high-profile accounts (e.g. 'zuck'). Meta deployed an emergency hotfix within hours, but PoC screenshots circulated widely. No CVE assigned.

- **Published:** 2026-06-07T00:00:00Z
- **Last reviewed:** 2026-06-07T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0710
- **ID:** TL-2026-0710
- **Severity:** HIGH
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 13 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On June 6, 2026 security researchers publicly disclosed a business-logic vulnerability in Instagram's web-based password-reset and account-recovery flow. The account-recovery screen is designed to present only partially redacted recovery options (e.g. an email rendered as 'm***@fb.com' or a phone shown as a masked suffix) so a requesting party can choose where a reset code should be sent without learning the full contact value. Due to a flaw in how the recovery options were serialized to the client, the flow returned the fully unredacted email address(es) and complete phone number(s) associated with the target account instead of the masked forms.

The defect was a pure server-side authorization/output-encoding logic bug, not a memory-safety or injection issue: an unauthenticated party simply initiated the standard 'forgot password' flow for an arbitrary username and read the recovery options returned by the account-recovery endpoint. No password reset needed to be completed and no code needed to be intercepted — the masked-recovery selection step itself leaked the data. Researchers demonstrated the issue against well-known accounts including Meta CEO Mark Zuckerberg ('zuck'), and proof-of-concept screenshots circulated on social media via accounts such as @vxunderground and @Scot0xo. Some account responses enumerated multiple email addresses tied to a single account.

Meta deployed an emergency hotfix within hours of disclosure and stated: 'We fixed an issue that allowed an external party to request password reset emails for some Instagram users. There was no breach of our systems.' No CVE was assigned. While the live window was short, even brief exposure of unredacted recovery data is operationally significant: an attacker who harvested email/phone pairs during the window obtains durable selectors for highly tailored phishing, SIM-swap attacks against SMS-based 2FA, credential-stuffing target lists, and targeted account-takeover (ATO). This incident follows a January 2026 wave of mass unsolicited Instagram password-reset emails and a parallel scraped-dataset ('17.5M records') circulating publicly, which together amplify the downstream phishing and doxxing risk of the leaked recovery selectors.

Because exploitation rides entirely on the legitimate Instagram recovery flow, defensive value lies in detecting abusive reset-initiation patterns (high-volume or enumeration-style 'forgot password' requests against many usernames), monitoring for the resulting targeted phishing using harvested unredacted contacts, and hardening account-recovery channels (authenticator-app 2FA over SMS, secured linked email).

## MITRE ATT&CK

- T1589 Gather Victim Identity Information
- T1595 Active Scanning
- T1598 Phishing for Information
- T1586 Compromise Accounts
- T1585 Establish Accounts
- T1566 Phishing
- T1111 Multi-Factor Authentication Interception
- T1606 Forge Web Credentials
- T1110 Brute Force
- T1213 Data from Information Repositories

## Sources

- [Instagram Fixes Password Reset Flaw That Exposes User Emails and Phone Numbers](https://cybersecuritynews.com/instagram-password-reset-user-phone/)
- [Meta fixes Instagram password reset flaw, denies data breach](https://securityaffairs.com/186829/security/meta-fixes-instagram-password-reset-flaw-denies-data-breach.html)
- [Instagram Password Reset Attack: What to Know](https://www.packetlabs.net/posts/instagram-password-reset-attack/)
- [Instagram says there's been 'no breach' despite password reset requests](https://techcrunch.com/2026/01/11/instagram-says-theres-been-no-breach-despite-password-reset-requests/)
- [Why you received an Instagram password reset email that you didn't request](https://help.instagram.com/231141655544451/)
- [Instagram says accounts 'are secure' after wave of suspicious password reset requests](https://www.engadget.com/cybersecurity/instagram-says-accounts-are-secure-after-wave-of-suspicious-password-reset-requests-192105188.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0710
