As per reported by The Information, Instagram experienced a serious security flaw which could have leaked the passwords of its users to the public.
The users were notified that a bug attacked the platform and could have exposed the passwords if users had used the “Download Your Data” tool which asks the users to download a copy of their data. In doing so, their passwords were leaked by being added to the URL of a webpage attached to the tool. Not only that, but the passwords were also saved on Facebook’s systems.
After the password breach, Facebook also notified affected Instagram users that when they saved the copy of their data, the password had been sent in plaintext in the URL. These passwords were also saved on Facebook’s servers, nonetheless, Instagram has issued the notification saying that data and passwords have been deleted and the tool was updated so it would not happen now.
In a statement to The Information, a spokesperson said the flaw only affected a “small number of people” but if those users were using a shared computer, or on a compromised system then it could have left their account info and password wide open. Instagram has only sent the notification to impacted users if you have not received any such notification then your account apparently was unaffected.