User data for the popular social media service Instagram has been leaked and is being sold online on a website for US$10 (RM42.70) each, according to a report by the technology news site Ars Technica today.

The news portal said it had been contacted regarding the website by a person who claims to have scraped together the data of six million Instagram users and compiled it into a searchable database.

The website offers to allow a search of the website for US$10 per query, and its operator had purportedly provided Ars Technica with a sample of data from 10,000 users.

Working with a security researcher Troy Hunt, Ars Technica said it is nearly certain that the data is legitimate.

“There's nothing in here to disprove the data. It's possible it has been scraped together from other sources, but every indication is that it's legitimate and the vector you wrote about earlier is absolutely feasible and certainly not unprecedented,” Hunt was quoted as saying.

The report said that out of the 10,000 records provided as a sample, 9,911 of them included either a phone number or email address; 5,341 include a phone number, and 4,341 include a phone number and e-mail.

“The data clearly isn't thrown together. A search of several dozen user names, for instance, showed they all corresponded to real Instagram users, and those user profiles were consistent with the phone numbers associated with them.

“The data, for example, included user names for three users whose profiles showed they were located in Australia, Thailand, and Germany. The phone numbers accompanying those users all contained the corresponding phone number country codes.

“Some of the users in the database had millions of followers,” the report said.

The report said the person who created the website claimed to have learned about a vulnerability in Instagram’s systems through an online discussion and was certain that others have also exploited the same vulnerability.

The person claimed that it was possible to automate the process at about one million accounts per hour. Instagram had purportedly closed the vulnerability within 12 hours after the person started exploiting it.

“Assuming the six million figure is true, and the 10,000-record sample is representative, millions of e-mail addresses and phone numbers are now available for sale, and still more account data may be in the hands of other hackers.

“Until the company says more, Instagram users should entertain the possibility the numbers and e-mail addresses associated with their accounts are now public. This post will be updated as new information becomes available,” the report said.

It quoted Instagram officials as saying that the company is aware of the claims and investigating the issue.

Earlier hacking reports

Earlier today, Ars Technica reported that the antivirus software provider Kaspersky Lab had found hackers advertising the personal details of unnamed celebrities on online forums.

However, it believed at the time that only a relatively small number of people had been affected because the vulnerability used was “labour intensive” to exploit.

This entailed the hacker using an outdated version of the Instagram app to send a request to reset a user’s password, and then intercept and modify the request before forwarding it to Instagram’s servers.

Instagram would then reply with a response that included the target’s user information.

“While the hackers used the outdated app to exploit the bug, the attack worked against all Instagram users, regardless of the app version they used,” the report said.

Instagram had reportedly responded to the earlier report saying that it was aware of at least one person actively exploiting this vulnerability.

“We recently discovered that one or more individuals obtained unlawful access to a number of high-profile Instagram users' contact information - specifically email address and phone number - by exploiting a bug in an Instagram API. No account passwords were exposed. We fixed the bug swiftly and are running a thorough investigation.

“Our main concern is for the safety and security of our community. At this point, we believe this effort was targeted at high-profile users so, out of an abundance of caution, we are notifying our verified account holders of this issue.

“As always, we encourage people to be vigilant about the security of their account and exercise caution if they encounter any suspicious activity such as unrecognized incoming calls, texts, and e-mails,” the report quoted Instagram as saying.

Instagram is a social media service primarily used to share photos and short videos. It is owned by the social media giant Facebook.

In April this year, Instagram announced that it has 700 million users.