UPDATED 21:43 EDT / AUGUST 14 2018

APPS

Russians are apparently hacking Instagram accounts, but no one knows why

Russians are apparently behind a strange hacking campaign that is taking over Instagram accounts, according to a report Monday from Mashable.

While no hard figures are given, at least several hundred users are reporting that they’ve found their Instagram accounts hacked and taken over.

“On Twitter, there have been more than 100 of these types of anecdotal reports in the last 24 hours alone,” the Mashable report noted. “According to data from analytics platform Talkwalker, there have been more than 5,000 tweets from 899 accounts mentioning Instagram hacks just in the last seven days. Many of these users have been desperately tweeting at Instagram’s Twitter account for help.”

The hacks all share a common story. Instagram users attempt to open the app to discover they’re logged out and when they try to log back in, they’re told that their username no longer exists. The accounts have the username, password and email address associated with the account changed, meaning that password recovery is impossible.

What’s missing from the story is the why, because it’s unknown why Russian hackers would want to hack Instagram accounts to begin with.

“We work hard to provide the Instagram community with a safe and secure experience,” Instagram said in a statement. “When we become aware of an account that has been compromised, we shut off access to the account and the people who’ve been affected are put through a remediation process so they can reset their password and take other necessary steps to secure their accounts.”

Travis Smith, principal security researcher at Tripwire Inc., told SiliconANGLE that although some of the users reporting issues didn’t have two-factor authentication enabled, it remains one of the most effective security methods.

“By having a unique code sent to your phone or leveraging a constantly changing pin code via an app, you can ensure that a hacker with your password will have difficulty getting into your account,” Smith said. But he noted that two-factor authentication is still a technical control implemented by humans.

“There may be other ways to bypass two-factor authentication outside of typical login methods,” he said. “Having strong and unique passwords for each account will minimize the chance that an attacker will reuse passwords from other breaches on accounts you’ve protected more heavily in the form of two-factor authentication.”

Photo: Kremlin/Wikimedia Commons

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.