HT TECH wants to start sending you push notifications. Click allow to subscribe

Social media booting service leaks 1000s of Instagram users’ personal details

Users who have signed up on Social Captain should change their Instagram passwords immediately.

By: HT CORRESPONDENT
Updated on: Aug 20 2022, 19:10 IST
Personal details of thousands of Instagram users have been leaked by a social media booting service called social Captain. (REUTERS)

Personal details of thousands of Instagram users have been leaked by a social media booting service called social Captain. These details include username and passwords and that means it can be easily used by hackers.

Social Captain claims help thousands of users grow their Instagram follower counts by connecting their accounts to its platform. Users are asked to enter their Instagram username and password to get started. TechCrunch reported that Social Captain stored these passwords of linked Instagram accounts in unencrypted plain text.

You may be interested in

Mobiles Tablets Laptops
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
23% OFF
Samsung Galaxy S23 Ultra 5G
  • Green
  • 12 GB RAM
  • 256 GB Storage
₹115,999₹149,999
Buy now
Google Pixel 8 Pro
  • Obsidian
  • 12 GB RAM
  • 128 GB Storage
₹106,998
Check details
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹87,900
Check details
21% OFF
Acer Swift Go SFG14 41 NX KG3SI 002 Laptop
  • Pure Silver
  • 8 GB RAM
  • 512 GB SSD
₹58,990₹74,999
Buy now
39% OFF
Acer Aspire 5 A515 57G Laptop
  • Gray
  • 16 GB RAM
  • 512 GB SSD
₹54,949₹89,999
Buy now
22% OFF
Acer Aspire 3 A315 24 NX KDESI 004 Laptop
  • Silver
  • 8 GB RAM
  • 512 GB SSD
₹33,499₹42,999
Buy now
39% OFF
Asus VivoBook 15 X515JA BQ322WS Laptop
  • Transparent Silver
  • 8 GB RAM
  • 512 GB SSD
₹31,490₹51,990
Buy now
34% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹26,299₹39,999
Buy now
55% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹47,000
Buy now
32% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹19,790₹28,999
Buy now
Honor Pad X9
  • Gray
  • 4 GB RAM
  • 128 GB Storage
₹14,999
Check details

Any user viewing the web page source code on their Social Captain profile page could see their Instagram user name and password easily as long as they were connected to the platform.

Also read: Looking for a smartphone? To check mobile finder click here.

What made things worse was a website bug that allowed anyone to access any Social Captain profile without logging in. Plugging in an user's unique account ID into Social Captain's web address would grant you access to that Social Captain account and the Instagram credentials.

Also Read: Instagram saw highest outage, Twitter least in Q4 2019: Downdetector

Because user account IDs were "for the most part sequential, it was possible to access any user's account and view their Instagram password and other account information with relative ease", reported TechCrunch.

A security researcher, who did not wish to be named, alerted TechCrunch about this vulnerability and provided a spreadsheet of about 10,000 scraped user accounts as proof (however, a recent court ruling stated that scraping websites does not fall afoul of US computer hacking laws.)

The spreadsheet that TechCrunch has contains about 4,700 complete sets of Instagram usernames and passwords. The rest of the records on the spreadsheet contained just the user's name and email address.

The spreadsheet data also showed if the accounts were on free trial or were paid premium accounts. "Only about 70 accounts were paying customers, the data said, but many of those premium accounts also contained the customer's billing addresses," reported TechCrunch.

TechCrunch also verified the bug by creating a dummy Instagram account and "connecting it to a new Social Captain account, and viewing the web page source code of our profile page on Social Captain".

After TechCrunch reached out, Social Captain confirmed that they had fixed the vulnerability by "preventing direct access to other users' profiles". However, passwords and other account information are still visible in the web page source code of a user's profile page.

"Early analysis indicates that the issue was introduced during the past weeks when the endpoint, meant to facilitate integration with a third-party email service, has been temporarily made accessible without token-based authentication," said Anthony Rogers, chief executive at Social Captain.

"As soon as we finalise the internal investigation we will be alerting users that could have been affected in the event of a breach and prompt them to update the associated username and password combinations," Rogers said.

Rogers has not mentioned how long this investigation is going to take.

Commenting about this leak, Instagram said that Social Captain has breached its terms of service by improperly storing login credentials.

"We are investigating and will take appropriate action. We strongly encourage people to never give their passwords to someone they don't know or trust," said an Instagram spokesperson.

Users who signed up to Social Captain should change their Instagram passwords immediately.

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 31 Jan, 13:27 IST
Tags:

Sale

Mobiles Tablets Laptops
11% OFF
Samsung Galaxy S24 Ultra
  • Titanium Black
  • 12 GB RAM
  • 256 GB Storage
₹119,999₹134,999
Buy now
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
13% OFF
Xiaomi 14
  • Matte Black
  • 12 GB RAM
  • 512 GB Storage
₹69,999₹79,999
Buy now
10% OFF
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹80,990₹89,900
Buy now
38% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹24,999₹39,999
Buy now
38% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹34,000
Buy now
38% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹17,999₹28,999
Buy now
25% OFF
Samsung Galaxy Tab A7 Lite
  • Silver
  • 3 GB RAM
  • 32 GB Storage
₹9,529₹12,700
Buy now
23% OFF
Infinix INBook X1 Neo XL22 Laptop Intel Celeron Quad Core 8 GB 256 GB SSD Windows 11
  • Blue
  • 4 GB RAM
  • 128 GB SSD
₹22,990₹29,990
Buy now
44% OFF
HP ZBook Firefly 14 G9 7M3U0PA Laptop
  • Nouvelle Silver
  • 16 GB RAM
  • 1 TB SSD
₹79,990₹142,659
Buy now
39% OFF
HP ZBook Firefly 14 G9 7M3T2PA Laptop
  • Nouvelle Silver
  • 16 GB RAM
  • 1 TB SSD
₹98,900₹162,500
Buy now
9% OFF
Asus Vivobook K15 OLED K513EA L512TS Laptop
  • Indie Black
  • 16 GB RAM
  • 512 GB SSD
₹41,999₹45,999
Buy now