Instagram is one of the most popular social media platforms in the world, with over a billion active users. However, this also makes it a tempting target for hackers who want to gain access to other people's accounts. In this article, we will explore how hackers can use a technique called brute force attack to crack Instagram passwords and what you can do to protect yourself.

What is brute force attack?

A brute force attack is a method of hacking that involves trying different combinations of passwords until finding the correct one. It is based on the assumption that the password is weak or common enough to be guessed by a computer program. A brute force attack can be performed manually or with the help of automated tools that can generate and test thousands of passwords per second.

How does brute force attack work on Instagram?

Instagram has some security measures to prevent brute force attacks, such as limiting the number of login attempts from a single IP address and requiring a captcha verification after a few failed attempts. However, these measures are not foolproof and can be bypassed by hackers who use proxies, VPNs, or bots to disguise their location and identity. Hackers can also exploit some vulnerabilities in Instagram's mobile and web applications that allow them to bypass the rate limiting and captcha mechanisms.

For example, a researcher named Arne Swinnen discovered two distinct vulnerabilities in Instagram's mobile and web applications that enabled him to brute force any account without being detected. The first vulnerability was an implementation bug in the mobile authentication process that allowed him to make 1000 guesses from each IP address before getting blocked. The second vulnerability was a scripting error in the web registration endpoint that revealed whether a password was correct or incorrect without any limit.

By using these vulnerabilities and a list of common passwords, Swinnen was able to crack several accounts in a matter of minutes. He reported his findings to Facebook, which owns Instagram, and received a reward as part of their bug bounty program.

How to protect yourself from brute force attacks?

The best way to protect yourself from brute force attacks is to use a strong and unique password for your Instagram account. A strong password should be at least 8 characters long and include a mix of uppercase and lowercase letters, numbers, and symbols. A unique password means that you should not use the same password for other accounts or services. You can also use a password manager to generate and store your passwords securely.

Another way to protect yourself is to enable two-factor authentication (2FA) on your Instagram account. 2FA adds an extra layer of security by requiring you to enter a code sent to your phone or email whenever you log in from a new device or location. This way, even if someone manages to guess your password, they will not be able to access your account without your code.

To enable 2FA on Instagram, go to Settings > Security > Two-Factor Authentication and follow the instructions. You can choose between text message or authentication app as your preferred method of receiving codes.


Brute force attacks are a common and effective way of hacking Instagram accounts, but they can be prevented by using strong and unique passwords and enabling 2FA. By following these simple steps, you can keep your account safe and secure from hackers.


