Report: Facebook notified some Instagram users that a now fixed bug in its data download tool sent their passwords in plaintext in a URL that the users received
According to The Information, Instagram has suffered a serious security leak of its own that could've exposed user's passwords.
Context & Ripple Effects
This report slots into a widening sequence of Facebook credential-handling failures rather than standing alone. A year earlier, Instagram had disclosed that a bug in its API let attackers pull phone numbers and email addresses for some high-profile accounts; the new incident shows the same class of failure moving from contact data to passwords themselves.
The arc then compounds: months after this URL-leak report, Facebook disclosed it had stored hundreds of millions of passwords in readable format, first describing the Instagram exposure as thousands of users before revising it upward to millions of Instagram users. Each disclosure has been narrower on day one than the eventual correction.
First-order effects
- Affected Instagram users received their own passwords embedded in plaintext URLs — meaning the credential sat in browser histories, referrer logs, and any intermediary that logged the request — and Facebook's notification went only to 'some' users, leaving the full blast radius undefined at disclosure time.
Second-order effects
- The pattern forces Facebook into reactive, escalating self-audits: the data-download-tool bug surfaced publicly here, and the subsequent readable-password-storage admission emerged from internal review, so each fix now triggers scrutiny of adjacent credential paths rather than closing the file.
Third-order effects
- If the sequence holds — narrow initial disclosure, later upward revision — platform security reporting drifts toward a compliance ritual where trust depends less on any single fix than on whether the next correction rewrites the last one, raising the stakes for regulators assessing Facebook's data handling.
The trend: Facebook's credential-security failures are surfacing as a serial-disclosure pattern, where each reported bug is followed by broader admissions about how widely user passwords were exposed.