Home » Security News » A Third-party exposes thousands of Instagram accou...

A Third-party exposes thousands of Instagram account passwords

A Third-party exposes thousands of Instagram account passwords
Deepanker Verma January 31, 2020 Security

Add Techlomedia as a preferred source on Google. Preferred Source

A social media boosting service for Instagram, Social Captain, has exposed passwords of thousands of Instagram accounts.

Social Captain asks users to enter the Instagram username and password to get started. The worst part os that they were keeping passwords in unencrypted plaintext. They were also keeping the username and password in the source code of the profile page on their site that one can see on his/her profile page.

A bug on their website allowed anyone to access Social Captain user’s profiles without log in. Just by modifying the URL’s unique account ID, anyone can access other people’s Social Captain profiles and then Instagram username/password on the page’s source code.

TechCrunch got access to about 10,000 scraped user accounts from which 4,700 sets had Instagram usernames and passwords. This bug affected both free and paid customers. There were

After this bug came into light, Social Captain blocked direct access to other users’ profiles. But passwords and other account information are still there.

Instagram said that Social Captain has breached the terms of service by storing login credentials improperly. They are now investigating the issue and promised to take appropriate action.

Users who signed up to Social Captain should change their Instagram password immediately.

Follow Techlomedia on Google News to stay updated. Follow on Google News

Affiliate Disclosure:

This article may contain affiliate links. We may earn a commission on purchases made through these links at no extra cost to you.

Deepanker Verma

About the Author: Deepanker Verma

Deepanker Verma is the Founder and Editor-in-Chief of TechloMedia. He holds Engineering degree in Computer Science and has over 15 years of experience in the technology sector. Deepanker bridges the gap between complex engineering and consumer electronics. He is also a a known Security Researcher acknowledged by global giants including Apple, Microsoft, and eBay. He uses his technical background to rigorously test gadgets, focusing on performance, security, and long-term value.

Related Posts

Stay Updated with Techlomedia

Join our newsletter to receive the latest tech news, reviews, and guides directly in your inbox.