Researcher: since at least October, web source code for thousands of Instagram profiles leaked the user's contact info; the issue was fixed in March
Laura Hautala / CNET :
Context & Ripple Effects
This lands two days after a researcher found a Chtrbox database with millions of Instagram users' contact info sitting online, and it revives a familiar arc: back in 2017 an API bug breached high-profile accounts, and access to the stolen data was later sold for $10 per search. The new wrinkle is the vector — not an API or a broker's database, but the web source code of ordinary profile pages, leaking quietly since at least October.
First-order effects
- Users whose profile pages rendered contact details into the HTML had phone numbers and emails readable by anyone who viewed source, from October until Instagram's March fix — months of exposure the company did not announce until now.
Second-order effects
- The timing sharpens questions about the Chtrbox dataset's provenance: if profile source code carried contact info for thousands of accounts, researchers and press will press both Instagram and data brokers on whether scraped page data explains how such databases were assembled.
Third-order effects
- The pattern across 2017's sold searches, 2018's plaintext-password URLs, and now this points toward independent researchers, not company disclosures, becoming the primary discovery channel for platform data leaks — raising the case for mandatory disclosure timelines rather than fix-first, announce-later practice.
The trend: Instagram's contact-data leaks keep surfacing through outside researchers months after internal fixes, shifting accountability pressure from single bugs to the platform's disclosure practices.