GramLove
We noticed a significant exposure originating from GramLove, a defunct third-party Instagram utility, discovered on July 12, 2018. What struck us was the age of the service, suggesting a long-standing vulnerability that remained unaddressed until its eventual public disclosure. The presence of MD5 hashed passwords, a notoriously weak hashing algorithm, immediately raised concerns regarding the potential for credential stuffing attacks against associated services. The scale, while not astronomical, is substantial enough to warrant investigation into any overlap with our user base.
The breach of GramLove, a service that provided Instagram search and viewing functionalities, resulted in the exposure of 13,437 unique records. The compromised data set comprised email addresses and MD5 hashed passwords. This information was subsequently disseminated on a prominent hacking forum, indicating a deliberate act of data exfiltration and subsequent publication. The nature of the data suggests a direct database compromise, likely through SQL injection or a similar vulnerability, followed by the extraction of user credentials. The use of MD5 hashing, a cryptographic hash function vulnerable to rainbow table attacks and brute-forcing, means these password hashes are readily crackable, posing a direct risk to any users who reused their credentials across different platforms.
While GramLove itself is no longer operational, the implications of this 2018 breach persist. The leaked data, particularly the cracked passwords, can be incorporated into larger credential stuffing lists used by threat actors. This specific incident did not garner widespread mainstream media attention, typical for breaches of smaller, specialized services. However, OSINT investigations into similar breaches from that era reveal a consistent pattern of third-party applications acting as vectors for credential harvesting, often due to inadequate security practices. Researchers at the time frequently highlighted the dangers of MD5 hashing and the importance of migrating to stronger algorithms like bcrypt or Argon2.
Breach Breakdown
13,437 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds