TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Ask HN: How does my Instagram keep getting compromised?

188 pointsby chinaover 3 years ago
I was an early Instagram user and got my nickname as my handle and I keep getting either locked out of my account or compromised altogether.<p>Over the years, hackers have tried a number of things to steal my handle and I can usually tell how they get in. These days, I have no idea. I&#x27;ve been SIM swapped a handful of times. One time a hacker faxed a fake ID to Godaddy to try and swap out my domain to gain control of my email (they were successful).<p>Now, I will try to log in to my account and will just be locked out. The email I created specifically for Instagram is not recognized, and there is no way to reset my password.<p>I have two-factor auth on, I don&#x27;t use the same password anywhere else, I change it regularly, etc.<p>My current theory is there is some employee at Meta that&#x27;s ultimately stealing the account. Does anybody have any idea how they&#x27;re hacking me?<p>PS: the worst part about all this is in order to get the handle back, I have to pull strings with folks I know at Meta, for a normal user, they would have absolutely no way of regaining access...<p>[Update] Just got the account back and still have no idea how my email was removed from the account...<p>[Update 2] Reviewing the security section I see a password reset email was sent to [username]@instagramz.com. No clue how or who changed the account email to that though.

24 comments

pkrotichover 3 years ago
Your situation is apparently common nowadays with OG usernames and can get very dangerous. I had no idea this was a thing until I listened to an episode on Darknet Diaries [0] recently.<p>In the old days, I remember people going after short domains in the same manner. ICANN ended up adding locking (auth codes) - perhaps IG and other social sites can learn from it.<p>Be safe!<p>[0]<a href="https:&#x2F;&#x2F;darknetdiaries.com&#x2F;episode&#x2F;106&#x2F;" rel="nofollow">https:&#x2F;&#x2F;darknetdiaries.com&#x2F;episode&#x2F;106&#x2F;</a>
评论 #29716938 未加载
评论 #29716665 未加载
评论 #29717402 未加载
评论 #29716706 未加载
评论 #29716648 未加载
iKlsRover 3 years ago
I&#x27;d auction and sell it and be done with the headache personally. It&#x27;s likely one day your meta well will dry up and that will be it, years of back and forth to see the handle gone and promoting crypto eventually or some crap.
评论 #29719218 未加载
评论 #29717303 未加载
评论 #29718067 未加载
toomuchtodoover 3 years ago
Have you tried reporting this to Meta’s security team and copying your state’s attorney general? Sounds like the CFAA would apply. You may not win, but making noise may help, and if it’s an insider they might be fired if Meta knows the legal apparatus is notified.<p><a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Computer_Fraud_and_Abuse_Act" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Computer_Fraud_and_Abuse_Act</a>
评论 #29716638 未加载
savolaiover 3 years ago
My account seems to have gotten hijacked too. Someone has (apparently) posted something that&#x27;s against community standards in my profile, as a consequence of which FB has disabled my account and says if I don&#x27;t appeal in 30 days, the account will be disabled.<p>The strange thing is when I try to appeal I get this page.<p>&quot;Security check To confirm your identity, we will text a confirmation code to your phone.&quot;<p>I select my phone number, and receive the right SMS, but it says<p>&quot;Error Sending SMS Could not send confirmation SMS. Please check the phone number and try again.&quot;<p>So I cannot actually enter the code.<p>I also have 2FA enabled and this doesn&#x27;t seem to have been breached.<p>On deviced that are still logged in I see them telling me I have posted something that is in typical photos grid format, but they don&#x27;t show me what the photos were. When I press the button to request review, it does nothing.<p>&lt;<a href="https:&#x2F;&#x2F;savolai.net&#x2F;uncategorized-en&#x2F;banned-from-facebook-and-instagram-screenshots&#x2F;" rel="nofollow">https:&#x2F;&#x2F;savolai.net&#x2F;uncategorized-en&#x2F;banned-from-facebook-an...</a>&gt;
zemnmezover 3 years ago
I would look at your email forwarding filters. It&#x27;s common to see compromises with this pattern where the email for your account was compromised and all the email is being forwarded to an attacker.
评论 #29718220 未加载
tpoacherover 3 years ago
Meta just seems to be superhackable with the company not giving a shit these days.<p>There was another user here the other day who had their heavymetal community page hacked, and facebook&#x27;s advice page was to &quot;politely ask the new owner to let them back in&quot; [1].<p>Absolutely ridiculous.<p>[1] <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=29706571" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=29706571</a>
thegingerover 3 years ago
If you are using the nickname china and have registered it a lot of places, even if you are completely non political and in no way associated with the country China, I can imagine the existence of these accounts outside of the governments control is a risk the government will be willing to spend millions trying to get rid of. I&#x27;m not sure you can fight that, at least not by yourself.
FDSGSGover 3 years ago
&gt; My current theory is there is some employee at Meta that&#x27;s ultimately stealing the account<p>This happens all the time, there is no recourse. Instagram employees are constantly taking usernames for themselves.
评论 #29716335 未加载
评论 #29717034 未加载
评论 #29716345 未加载
评论 #29716464 未加载
评论 #29716341 未加载
docdeekover 3 years ago
If your IG handle is the same as your HN handle, could it be some very motivated people from that country&#x27;s bureaucracy looking to take that handle for the state?
评论 #29716760 未加载
tgsovlerkhgselover 3 years ago
&gt; My current theory is there is some employee at Meta that&#x27;s ultimately stealing the account.<p>This was my first thought given the e-mail address change. Someone e.g. bribing a support person.<p>My (uninformed) guess would be that given that you got the account back, this probably got escalated, someone looked at it, fixed it, and hopefully got the criminal support person&#x27;s access disabled, until the next one gets bribed...
Jerrrryover 3 years ago
&gt;China<p>You will be forever fucked, as big as Meta&#x2F;Facebook&#x2F;Instagram&#x27;s exploit attack surface is. Microsoft&#x2F;Office&#x2F;Xbox is in a similar position as well.<p>early lucky adopters not employees will always have their accounts poached constantly on every common platform. eventually those who have the names paid for the &#x27;rights,&#x27; or defend it communally.<p>yes, communally - it is a literal racket of cybergangters on every platform leveraging anything from social engineering your doxxed naive grandma into reading a private key to 0-daying your teamviewer to install a common keylogger.<p>bribing csr&#x27;s is extremely common, as is sim-swapping (bribing att&#x2F;verizon csr&#x27;s), and there are a myriad of attack vectors in between<p>but of course 94% are just script kiddies using a &quot;turbo&quot;&#x2F;api-spammer to take the username between other 3rd party transactions. it&#x27;s a parasitic economy of bottom-feeders and iGangsters.
edm0ndover 3 years ago
You should tie your IG account to a Google Voice number instead of a your cell that way it cant be SIM swapped.
r0flover 3 years ago
My insta account keeps getting reset password requests every week for years. I’ve had multiple people ask to buy it, then threaten to sue, etc<p>I’ve tried to contact meta&#x2F;Instagram about 50 times and not once has anyone emailed me back<p>How is it this hard to get support? It’s a personal account and I still have it so I don’t really care that much but there must be a way to get a hold of someone isn’t there!?
skyzyxover 3 years ago
This happened to me several years ago. My account got locked out and I had no way to contact a human to get it back.
评论 #29716579 未加载
JSONderuloover 3 years ago
<a href="https:&#x2F;&#x2F;www.nytimes.com&#x2F;2021&#x2F;12&#x2F;13&#x2F;technology&#x2F;instagram-handle-metaverse.html" rel="nofollow">https:&#x2F;&#x2F;www.nytimes.com&#x2F;2021&#x2F;12&#x2F;13&#x2F;technology&#x2F;instagram-hand...</a><p>Her Instagram Handle Was ‘Metaverse.’ Last Month, It Vanished.
评论 #29717501 未加载
leeroyjenkins11over 3 years ago
Ok, so I had a similar situation. What it was is that I signed up for insta pre Facebook merger. Then I connected my Facebook account to insta. So my old username password combo were compromised because I re used them when I was a moron when I was younger. So someone gained access via the original Instagram password and username, changes my email. Then I would login via Facebook and have access at the same time. The different geo locations and unusual activity caused my account to be locked periodically. When they unlocked it I logged in quick, changed the email address and password on the account on the Instagram side and enabled 2 factor and haven&#x27;t had an issue since.
jsnellover 3 years ago
What devices are you using the account on? If it&#x27;s on a desktop browser, my assumption would be that you&#x27;ve got malware. That allows them to trivially steal the session cookies, steal the passwords the next time you log in, steal any device identification cookies that are used to control not using 2FA on logins from trusted devices &#x2F; sending new device notifcations, and also hijack your recovery and notification email address.<p>If you&#x27;re only using this via the app from a mobile device, then malware is an unlikely explanation though.<p>(Why are you regularly changing the password anyway? What&#x27;s the threat model you&#x27;re trying to guard against?)
评论 #29716671 未加载
edm0ndover 3 years ago
instagramz.com is a legit domain owned by Facebook
评论 #29717737 未加载
vogelfreiover 3 years ago
Instagram is severly broken. I have never had an account on there and it has repeatedly happened that I was logged into some random stranger&#x27;s account as I clicked on some Instagram weblink. I could read all their private conversations, message people in their name, mess with their settings. Their security is so badly broken, I wonder if they can be held criminally liable for it.
gecko39over 3 years ago
I had a two letter name which got hacked. I called in a favor from a friend of a friend at instagram&#x2F;FB and got it back.. then it happened again and I didn&#x27;t want to ask the favor again. IIRC they did not yet have 2FA even though I asked for it ( I was assuming it would happen again and it did. )
kasra85over 3 years ago
On top of all security measures, Meta, Google and other big tech that offer Auth-as-a-service need to offer paid service to reclaim an account. I am sure people would be happy to pay to talk to a real human and take back their account.
Jerrrryover 3 years ago
&gt;@instagramz.com<p>ha....someone stole this domain or hijacked&#x2F;spoofed an email chain in the password reset api. you should be honored.<p>&gt;Last updated from Registry RDAP DB: 2021-12-28 06:35:41 UTC<p>it of course still resolves to instagram.
Cypherover 3 years ago
Plot twist, you are the hacker
评论 #29717293 未加载
barbazooover 3 years ago
Someone at Facebook stealing your domain is quite an accusation. Assuming your domain was similar to your username&#x2F;IG handle, wouldn&#x27;t it be more likely to be people wanting your &quot;china&quot; domain for spam&#x2F;malware&#x2F;propaganda&#x2F;etc?
评论 #29716623 未加载
评论 #29716575 未加载
评论 #29716876 未加载
评论 #29716781 未加载