Connect with us

Technology

Instagram password reset surge: Protect your account

Published

on

Instagram password reset surge: Protect your account

NEWYou can now listen to Fox News articles!

If your inbox suddenly shows an Instagram “Reset your password” email you never requested, you are not alone. A wave of unexpected reset messages is hitting people right now, and attackers are betting you will panic, click fast and make a mistake.

Here is the tricky part. Many of these emails are real. They can come directly from Instagram because someone triggered the legitimate password reset flow. That makes the alert feel extra convincing, even when you did nothing wrong.

Sign up for my FREE CyberGuy Report 
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.

FACEBOOK, INSTAGRAM ARE USING YOUR DATA TO TRAIN AI: LEARN HOW TO PROTECT IT

Advertisement

Unexpected Instagram password reset emails can look completely legitimate, which is why so many users are caught off guard during this surge. (Cyverguy.com)

Why Instagram password reset emails are surging

This surge is happening because the reset emails themselves can be real, even when the intent behind them is not. Instead of building fake phishing pages or using malware, attackers take advantage of Instagram’s normal account recovery system.

The process is simple. An attacker enters your username or email into Instagram’s real password reset form. Instagram automatically sends a legitimate reset email to you. The attacker then waits to see how you react.

At this point, your account has not been hacked. The risk comes from what happens next. Attackers are counting on common mistakes, such as clicking the reset button and rushing through the process, reusing a weak password, getting redirected to a fake follow-up page or falling for a second scam email that arrives soon after.

That is why this tactic works as a stress test. It creates urgency and pressure, even though nothing has been compromised yet.

Advertisement

Why attackers love this tactic

This is classic social engineering. The attacker does not need to outsmart Instagram. They need to outsmart you in a stressed moment. A reset email creates urgency. It also feels official. That combination leads people to click first and think second, which is exactly the outcome attackers want. You can treat these surprise reset emails as an early warning system. If you get one:

  • Someone may know your username or email
  • Your account could be on a target list from a leak or scrape
  • Your current security setup will decide whether this stays annoying or turns into a takeover

If an email pressures you to act immediately, threatens account deletion or asks for extra information, treat it as suspicious.

The BreachForums leak connection

The timing of this surge has raised fresh concerns. Reports point to data tied to roughly 17.5 million Instagram accounts being shared on BreachForums, an underground forum where cybercriminals trade and discuss stolen data. The alleged post appeared in early January 2026, which lines up with when many users began reporting a sudden wave of password reset emails, sometimes receiving several in a short period of time.

This timing alone does not prove a direct connection. However, leaked usernames or email addresses can make it much easier for attackers to target large numbers of accounts at once, which is exactly what this kind of reset spam depends on. We reached out to Meta for comment but did not receive a response before our deadline. 

We reached out to Meta for comment, and a spokesperson for the company told CyberGuy, “We fixed an issue that allowed an external party to request password reset emails for some Instagram users. We want to reassure everyone there was no breach of our systems and people’s Instagram accounts remain secure. People can disregard these emails and we apologize for any confusion this may have caused.” 

How to tell if the reset email is legitimate

A legitimate Instagram reset email can still be part of an attack attempt. So your goal is not “confirm it is real,” it is “avoid reacting in a risky way.” Instagram’s own guidance boils down to this:

Advertisement
  • A reset email alone does not mean your account is compromised
  • If you did not request it, do not use the link
  • Use Instagram’s official paths in the app to review security and report suspicious messages

Also, if you get emails about changing your account email address, Instagram says those messages can include a way to reverse the change, which can help you recover if someone broke in.

These real-looking messages are designed to create urgency and push people to click before slowing down and checking their account security. (Cyverguy.com)

What a real Instagram password reset email looks like

A legitimate reset email usually has these elements:

  • Sender: Comes from an official Instagram domain, such as security@mail.instagram.com
  • Subject line: Often says “Reset your Instagram password” or “Password reset request”
  • Instagram branding: Logo at the top with clean formatting
  • Call to action button: A button like “Reset Password”
  • Reassurance text: A line explaining that if you did not request this, you can ignore the email and nothing will change
  • Safety option: Language telling you how to report the email if you did not initiate it

This is why the current surge is so effective. The emails look normal and arrive from real Instagram systems. 

META ENDS FACT-CHECKING PROGRAM AS ZUCKERBERG VOWS TO RESTORE FREE EXPRESSION ON FACEBOOK, INSTAGRAM

What Instagram reset alerts can look like inside the app

You may also see security messages directly in Instagram, such as:

  • Login attempt alerts
  • Notifications about a password reset request
  • Prompts asking you to confirm a login from a new device

These in-app alerts are generally safer to interact with than email links, especially during a surge.

What scammers rely on

Attackers are counting on one thing: panic. When users see a reset email they did not request, many rush to click before reading the fine print. That fast reaction is what turns a harmless reset request into a real account takeover.

Advertisement

What to do right now if you get a reset email you did not request

So, what should you do if one of these password reset emails lands in your inbox? Take a breath first. Then do this.

1) Do not click the button in the email and use strong antivirus software 

Even if the message looks real, treat it like a hot surface. If you want to change your password, do it from the Instagram app or by typing Instagram’s address into your browser yourself. Strong antivirus software adds another layer of protection here. It can help block malicious links, fake login pages and follow-up scams that often appear during a reset email surge.

The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.

Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com.

2) Check your Instagram security activity in the app

Open Instagram and look for signs someone tried to log in:

Advertisement
  • Unknown devices
  • Login alerts you do not recognize
  • Changes to email, phone number or linked accounts

If anything looks off, remove the device and update your credentials.

3) Turn on two-factor authentication (2FA) and keep it on

Two-factor authentication (2FA) is the biggest roadblock for account takeover. Even if someone knows your password, they still need your code to get in from an unfamiliar device. Instagram has pushed 2FA heavily for higher-risk accounts and urges users to enable it. Use an authenticator app if you can. It is often safer than SMS.

4) Change your password if you feel unsure

If you suspect someone guessed your password, or you reused it elsewhere, change it. Make it long and unique. A password manager can help you generate and store strong passwords without reusing them. Then update the password on your email account too. Your email inbox controls most password resets, so make sure it also uses a strong, unique password.

Next, see if your email has been exposed in past breaches. Our #1 password manager (see Cyberguy.com/Passwords) pick includes a built-in breach scanner that checks whether your email address or passwords have appeared in known leaks. If you discover a match, immediately change any reused passwords and secure those accounts with new, unique credentials.

Check out the best expert-reviewed password managers of 2026 at Cyberguy.com.

5) Use a data removal service to reduce targeting

Password reset surges often follow data leaks. When your email address and personal details appear on data broker sites, attackers can target you more easily. A data removal service helps limit where your information shows up online. By shrinking your digital footprint, you reduce the chances of being singled out during large-scale reset email attacks.

Advertisement

While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice. They aren’t cheap, and neither is your privacy. These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites. It’s what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet. By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you.

Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com.

Get a free scan to find out if your personal information is already out on the web: Cyberguy.com.

The safest response is to avoid email links, open the Instagram app directly and review login activity and security settings instead. (Kurt “CyberGuy” Knutsson)

6) Watch for follow-up scams

After a reset surge, criminals often switch tactics. Next, you may see:

Advertisement
  • Fake “Instagram Support” emails
  • DMs claiming your account will be deleted
  • Login approval prompts you did not trigger

Slow down and verify everything inside the app.

Kurt’s key takeaways

A spike in Instagram password reset emails feels scary because it looks like someone is already inside your account. Often, they are not. Still, the surge is a reminder to tighten your basics. Use the app to check security. Turn on two-factor authentication. Change the passwords you reused. Most importantly, do not let an unexpected email rush you into the one click that hands over access.

Have you received an unexpected Instagram password reset email recently, and how did you handle it? Let us know by writing to us at Cyberguy.com.

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Sign up for my FREE CyberGuy Report 
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – when you join my CYBERGUY.COM newsletter. 

Copyright 2026 CyberGuy.com. All rights reserved. 

Advertisement

Technology

Barret Zoph is out at OpenAI again after just five months

Published

on

Barret Zoph is out at OpenAI again after just five months

Five months after returning to OpenAI, Barret Zoph — the company’s head of enterprise AI sales — has departed, The Verge has learned.

Zoph returned to OpenAI in mid-January after a stint as co-founder and CTO of Thinking Machines Lab, the competing AI company founded by former OpenAI CTO Mira Murati. Shortly after Zoph returned to OpenAI, the company said he would lead its push into enterprise — a significant role at OpenAI, since in recent months it had vowed to stop chasing so-called “side quests” and focus on key revenue drivers like enterprise and coding ahead of its planned IPO.

OpenAI confirmed to The Verge that Zoph will be departing. He posted a goodbye message in the company’s Slack channels. Zoph did not immediately respond to a request for comment.

Zoph originally left OpenAI in the fall of 2024 for Murati’s Thinking Machines Lab, but departed the role abruptly in January 2026 after reports of alleged misconduct involving an undisclosed relationship with a colleague. Murati posted on X in January that Thinking Machines Lab had “parted ways” with Zoph and that he would be replaced as CTO.

Thinking Machines Lab has its own tensions with OpenAI. Murati briefly took over as CEO from OpenAI CEO Sam Altman during his November 2023 ouster, and during the recent OpenAI trial, Murati testified that she couldn’t trust everything Altman said. In September 2024, when Murati left OpenAI to start Thinking Machines Lab, a group of OpenAI employees followed shortly after. But three of them — including Zoph — all returned to OpenAI together this past January. Fidji Simo, OpenAI’s CEO of Applications, wrote on X at the time that she was “excited to welcome Barret Zoph, Luke Metz, and Sam Schoenholz back” and that the decision had “been in the works for several weeks.”

Advertisement
Continue Reading

Technology

6 in 10 identity crimes now begin with a new account

Published

on

6 in 10 identity crimes now begin with a new account

NEWYou can now listen to Fox News articles!

For years, two women in Bremerton, Washington, opened credit cards and lines of credit in other people’s names, working from documents they pulled out of stolen mail. Emily Vranic and Heather Marquis redirected the new accounts’ statements to an address they controlled, so no bill ever reached the victims. They pleaded guilty in federal court this month to bank fraud and aggravated identity theft in a scheme prosecutors say stole nearly $229,000 from banks and bank customers.

If you have ever worried about a credit card opened in your name, this case shows how quickly stolen mail can turn into a much bigger identity theft problem. Opening a new account is the leading form of identity misuse reported to the Identity Theft Resource Center. In its latest data, 62.1% of attempted misuse cases began with a new account application rather than the takeover of an account the victim already held.

Sign up for my FREE CyberGuy Report

  • Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
  • For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com trusted by millions who watch CyberGuy on TV daily.

Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.

WARNING SIGNS YOUR MAIL HAS BEEN FRAUDULENTLY REDIRECTED

Advertisement

A credit card opened in your name can start with stolen mail, exposed personal details or documents pulled from the trash. (Nastasic/Getty Images)

How stolen mail helped thieves open credit cards

When people picture an account opened in their name, they may imagine a checking account at a bank they have never set foot in. The more likely target is a credit card. Credit cards made up 41% of attempted account misuse reported to the ITRC last year. Checking accounts came to 17.7% and personal loans to 8.5%.

A credit card is one of the easier accounts to open in someone else’s name, and the reason is in how the application is cleared. A lender matches the submitted name, date of birth, address and Social Security number (SSN) against the bureau file. When those details fit a record that already exists, an automated system can approve the application with no one confirming that the applicant is the person being described. Assemble enough of someone’s information from breaches and stolen mail, and the check clears.

Why identity thieves rarely stop at one account

Vranic and Marquis did not stop at one account per victim. Once they controlled someone’s identity, they activated existing cards, opened new credit lines and moved money out of bank accounts tied to the same name.

This is common. The ITRC found that 25.6% of victims are now handling two or more identity incidents at once, up from 23.5% the year before. The same stolen details, including name, date of birth, address and SSN, can open the next account as easily as the first.

Advertisement

DON’T LET THIS CREDIT CARD FRAUD NIGHTMARE HAPPEN TO YOU

A fraudulent credit card may stay hidden for weeks if statements and notices are sent to an address controlled by the thief. (Kurt “CyberGuy” Knutsson)

Why weeks can pass before you learn about the account

A new account does not announce itself. It reaches your credit report only after the first statement closes, which puts the first record 30 to 60 days behind the opening. Banks report to the bureaus monthly, and the bureaus need up to two weeks more to post the change.

The first paper notice goes wherever the application is listed. Vranic and Marquis had the statements mailed to their own address, not the victims’. When the mail reaches the right house, it may read like a routine offer or a card no one ordered, which makes it easy to set aside.

By the time a denied loan or a collections call makes the account impossible to ignore, it has been open and drawing money for weeks.

Advertisement

WHY THAT $4 CHARGE ON YOUR STATEMENT COULD BE FRAUD

Freezing your credit, watching for new accounts and acting quickly can help limit the damage if your identity is used. (Kurt “CyberGuy” Knutsson)

What to do if a credit card appears in your name

Move quickly, because every day an account stays open gives a thief more time to spend money, damage your credit or try the same information somewhere else.

1) Contact the card issuer immediately

Call the credit card company or lender that opened the account and tell them the account is fraudulent. Ask them to close or freeze the account, stop any pending charges and send written confirmation that you are not responsible for the debt.

2) Start at IdentityTheft.gov

Go to IdentityTheft.gov. The Federal Trade Commission’s site generates an Identity Theft Report and recovery plan to help you report identity theft, limit the damage and fix your credit.

Advertisement

3) File a police report if a creditor asks for one

Your FTC Identity Theft Report is usually the key document for disputing fraudulent accounts. Some lenders, banks or debt collectors may also ask for a police report. If that happens, file one with your local police department and keep a copy for your records.

4) Save every document and confirmation number

Keep copies of account statements, collection letters, emails, dispute letters, FTC reports, police reports and confirmation numbers. A clear paper trail can make it easier to prove the account was fraudulent if a creditor, credit bureau or debt collector questions your claim.

5) Dispute the account in writing

Dispute the fraudulent account directly with the lender that opened it, in writing. Also dispute it with Equifax, Experian and TransUnion if it appears on your credit reports. Under the Fair Credit Reporting Act, companies that furnish information to credit bureaus have a duty to investigate disputed information.

6) Freeze your credit at all three bureaus

Place a freeze at Equifax, Experian and TransUnion to help block the next application. Freezes have been free since 2018 and can be lifted online when you need to apply for credit.

7) Add a fraud alert

A credit freeze blocks access to your credit file. A fraud alert tells lenders to take extra steps to verify your identity before opening new credit in your name. You only need to contact one of the three major credit bureaus to place a fraud alert, and that bureau must notify the other two.

Advertisement

8) Report suspected mail theft

If you believe stolen mail helped someone open the account, report it to the U.S. Postal Inspection Service, the law enforcement arm of the Postal Service. You can report mail theft, identity theft, fraudulent change-of-address requests, fraudulent mail holds and fake Informed Delivery accounts at mailtheft.uspis.gov.

9) Request an IRS Identity Protection PIN

If your Social Security number was used, request an IRS Identity Protection PIN at irs.gov/ippin. This helps keep a thief from filing a tax return in your name.

10) Change passwords and lock down your accounts

Change the passwords on your bank, credit card and email accounts, especially if your email address was part of the fraud. Use a password manager to create and store strong, unique passwords for each account, so one exposed password cannot unlock the rest of your financial life. Turn on two-factor authentication (2FA) where available. Then review recent transactions, saved payment methods and automatic payments for anything you do not recognize. 

11) Get help cleaning up the damage

Cleaning up identity theft can mean dealing with creditors, credit bureaus, debt collectors and repeat follow-ups. Keep copies of every report, dispute letter, confirmation number and account closure notice so you have a clear paper trail if the fraud resurfaces.

No service can prevent every account opened in your name. Continuous three-bureau credit monitoring may alert you to new accounts as they are reported, rather than weeks later when a lender turns you down or a collections notice arrives. See my tips and best picks on Best Identity Theft Protection at Cyberguy.com

Advertisement

Kurt’s key takeaways

A stolen credit card account can quietly grow into a much bigger identity theft mess before you ever see a bill. That is what makes this Washington case so alarming. The victims were not ignoring warning signs. The statements were being sent somewhere else. The best move is to make it harder for thieves to open the next account. Freeze your credit at Equifax, Experian and TransUnion, watch for hard inquiries and check your credit reports for accounts you do not recognize. If something appears, go straight to IdentityTheft.gov, file a report and dispute the account in writing with the lender. Credit monitoring can also give you a faster heads-up when a new account or inquiry hits your file. It will not stop every scam, but it can shorten the time between the fraud starting and you finding out.

Have you ever found a credit card, loan or account on your credit report that you did not open? Let us know how you discovered it and what it took to fix it by writing to us at Cyberguy.com

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Sign up for my FREE CyberGuy Report

  • Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
  • For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com trusted by millions who watch CyberGuy on TV daily.
  • Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.

Copyright 2026 CyberGuy.com. All rights reserved.

Advertisement
Continue Reading

Technology

Valve is so behind on Steam Controller orders that some won’t ship until 2027

Published

on

Valve is so behind on Steam Controller orders that some won’t ship until 2027

Valve has some good news and bad news about Steam Controllers. The good news: if you make a reservation for a Steam Controller, the company will now show you one of three estimates of when you’ll be able to actually order your gamepad: by September 2026, by December 2026, or sometime in 2027. The bad news: any reservations made today “indicate a 2027 date for shipping,” Valve says.

“We have no plans to stop making Steam Controller,” according to Valve. “But as we look at the current demand compared to how many we know we can make by the end of the year, we want to manage expectations as much as we can with regards to when folks can expect to receive their order.”

Valve’s very good new Steam Controller went on sale in early May, and the initial rush led some people to run into frustrating problems with trying to check out ahead of the controllers eventually going out of stock. A few days later, the company announced that it would be implementing a reservations queue for interested buyers so they could get on a waitlist. If you’re on the waitlist, when you get notified that a Steam Controller is ready for you to buy, you have 72 hours to actually make the order.

“When we launched Steam Controller last month, we quickly saw that initial demand exceeded our expectations,” Valve says. “Switching to a reservation queue has (hopefully) cut down on the headaches on the customer side, and for us it’s also been helpful as we plan ahead and try to get as many out as quickly as we are able.”

All three of Valve’s big hardware products were delayed from a planned early 2026 launch because of the component crisis, Valve still hasn’t announced when the Steam Machine PC or Steam Frame VR headset might go on sale. However, just yesterday, Valve officially launched its big SteamOS 3.8 update with support for the Steam Machine. It’s also been importing a lot of hardware into the US as of late.

Advertisement
Continue Reading
Advertisement

Trending