18 ms·
Someone has stolen my Instagram account
- starpilot 6y agoHe got his account back it looks like: https://www.instagram.com/danny/ https://www.instagram.com/danny/
- OpticalWindows 6y agoother than the leading title, interesting post.
- shadowgovt 6y agoBasically. "A guy who stole my account claims someone at Facebook helped them" would be more accurate
- deft 6y agoThis is a very common thing. In fact influencers and FB employees publicly and loudly talk about this method and no one stops them. "Hey I'm visiting fb headquarters anyone want a new @ or a checkmark?" Why do random fb employees even have this capability?
- jfgg 6y agoDidn't a similar thing happen with a famous Soccer player?
- DLay 6y agoYes. Instagram’s explanation was they thought the account was an impersonator of Andrés Iniesta and disabled it/gave it away. Usually if Instagram wants your account they add underscores to the original handle like they did with @sussexroyal.
- gabereiser 6y agoAnd this is why I’ll never use Facebook or Instagram again. I can’t even begin to imagine and angst the OP is going through right now. Imagine if it was your business? My sister uses Instagram exclusively to market and promote her beauty salon business. I can only imagine what her reaction would be if something like this happened to her (really my only reference). Letting people have access to data let’s people manipulate that data. Whether this was an insider giving his friend the account or it was hacked and taken over, it doesn’t matter how, things like the OP’s situation should NEVER exist.
- hobby-coder-guy 6y agoSource?
- tinus_hn 6y agoThis is not Wikipedia
- hobby-coder-guy 6y agoIt’s not makeshitup.org either
- KaiserPro 6y agoJust because some vacuous air bag says it, doesn't make it true. Instagram is basically the school playground, but sadly unlike in real life, people can make a career from being "playground" popular.
- hyperdimension 6y ago> vacuous air bag Colloquialism: 100% understood. Reality: 0% possible...unless this 'air bag' is full of 'empty'. In other news, always be careful breaking the neck of a CRT...you'll let the vacuum out!
- mkl 6y ago"Vacuous" doesn't mean vacuum: https://en.wiktionary.org/wiki/vacuous https://en.wiktionary.org/wiki/vacuous
- deleted 6y ago[deleted]
- mrits 6y agoI live with a FB employee. Most of my close friends are FB employees. I've literally never heard this.
- zaz77 6y agoWell, thank God for that, because with that kind of authoritative observation we can close the books on this one permanently. Dodged a bullet there, didn’t we? Pitchforks down, everyone, ‘mrits has this one in hand. This is an extremely well-known phenomenon. This is the third time I’ve heard of it happening to an OG. It’s pretty common knowledge that the right teams inside Instagram look the other way; what’s a user going to do, sue? People are making money. I’m sure your roommate who works on Tupperware or whatever wouldn’t know a thing about it, but Facebook is also roughly the size of Romania, so perhaps your front row seat to the inner workings of an organization that also legally compels your roommate to not tell you things isn’t as end all as you’d assume. Hint: I work at Facebook.
- moonshinefe 6y agoIt's not an extremely well known phenomenon at all. Asserting things while being overly emotional and aggressive isn't evidence. So: Citation needed.
- zaz77 6y agoSo are you asking for screenshots from my email of the thread where everyone came together to agree on the terms and execution of the conspiracy, or? Also, sarcasm isn’t an emotion. I’m English, so perhaps consider that my culture of challenging someone is different from yours before projecting whatever big bad horrible emotional troll hurt your feelings once. Facebook is literally more employees than even populate this dreadful site, but someone says “my roommate’s brother’s uncle by blood works there and I’ve never heard of it so it’s plainly false” and we’re all to just fawn over the precious insight? I’m sorry, I’ll try again: thanks, ‘mrats. Very brave.
- 6y ago
- vmception 6y ago> Why do random fb employees even have this capability? Assuming that's what happened here, its because to them it is pure coincidence that the market values these database entries at all. Like sure, at this point they know it means a lot to people and inspires many other people and can effect entire markets that they are unaware of, but from their perspective it isn't "god mode" its "lol ok, wanna hit up sushi for lunch later?"
- forgotmypw17 6y agoBasically, you can't trump physical access...
- kaesar14 6y agoShocking behavior from the most immoral company on the Internet. What can be done about this?
- deleted 6y ago[deleted]
- lightgreen 6y ago> Shocking If you are so easier to shock, you will probably die from a heart attack at 30. But seriously, it is an action of one bad employee at worst, this story (if it is even true) can happen in any company. Facebook gets spotlighted simply because it is large.
- matsemann 6y agoNo, they get spotlighted because when stuff like this happen, it's impossible to resolve or get in touch with a human. If it was resolved after contacting support it wouldn't have been a story.
- lightgreen 6y ago> it's impossible to resolve or get in touch with a human I worked in a couple of large internet companies. The army of support people work long hours trying to deal with endless stream of support requests from people who cannot articulate what they actually need, disappear after a couple message, throw insults at support, and in addition to that a lot of fraud requests, spam and so on. I read some of their conversations with users (when they were related to my work), dealing with them is really hard. I belive companies technically physically cannot do much better at tech support. When your car breaks, you simply go to repair service, and pay to get the issue resolved. Asking to cancel any large internet company for bad tech support is childish. Adult response would be: I want paid tech support.
- kaesar14 6y ago/s needed perhaps.
- Simulacra 6y agoI had this happen to one of my accounts, it got taken over by someone, I don’t know how, but I moved heaven and earth to reach someone at Instagram to no avail. It confirmed in my mind that the employees of Facebook and Instagram could not care less about any of us unless we are making the money.
- bradlys 6y agoWell, duh? Does any company care about people who aren’t carrying the bags of money? As far as I’ve seen - companies only care about the whales because any other mentality is a money losing one.
- ipsum2 6y agoThere's no evidence to back the user's claims. This sounds like "Hey my dad works at Xbox and will ban you". There are other ways to compromise an Instagram account, like sim swapping (https://krebsonsecurity.com/2018/05/t-mobile-employee-made-unauthorized-sim-swap-to-steal-instagram-account/ https://krebsonsecurity.com/2018/05/t-mobile-employee-made-u...)
- gsich 6y agoThat depends if the Authenticator was used or normal SMS messages.
- maps7 6y agoIf that was the case why would FB be marking the issue as resolved?
- paxys 6y agoBecause there's no proof of any malicious activity. It could very well be that the guy Tweeting is trying to take over the account.
- deleted 6y ago[deleted]
- ipsum2 6y agoI don't know, but it sounds like the issue was resolved (correctly or incorrectly) the first time, so the user started filing a ton of issues, which were automatically marked as duplicate. Now he's spamming the white hat security form (https://twitter.com/dannyjhall/status/1310231761444581385 https://twitter.com/dannyjhall/status/1310231761444581385), which is not likely to get him a response.
- 6gvONxR4sf7o 6y ago“Spamming?” If repeated complaints about an issue the company won’t resolve is what we call spam now, I’m speechless.
- apkallum 6y agoIt's sad and upsetting, but when will people learn that Facebook, Google et al do not care at all about individual users? Their model simply does not factor in the worries of a single user. (Worse is how they want to propagate the idea that software should be free and of highest quality, thus preventing any communal attempts at creating different models.) I advice everyone who has an account to at least download their data to keep a copy of it: https://www.facebook.com/help/1701730696756992 https://www.facebook.com/help/1701730696756992
- Nextgrid 6y agoI’ve read somewhere that Facebook even embeds tracking pixels in the HTML of the data export, so keep this in mind if you ever actually look at the exported data.
- apkallum 6y agoWould you be kind enough to post more information about this?
- Nextgrid 6y agoGoogle produces irrelevant results no matter what I try (searching anything about Facebook tracking pixels brings up tons of marketing-related SEO spam) so I suggest someone with a Facebook account just tries it and reports back. Until then, better safe than sorry, assume the worst (which at this point should be the norm when dealing with the company we're talking about) and proceed accordingly.
- tomaszs 6y agoI have heard images are also marked
- Nextgrid 6y agoImages on public Facebook are indeed marked (a unique ID is embedded in every picture's EXIF data) so I wouldn't be surprised if the exported ones were too (not necessarily for malicious reason even, if the images are being marked at upload time, Facebook may not even have the original unmarked image anymore).
- TedDoesntTalk 6y agoPlease upvote this story — if it gets enough attention, someone at FB or IG might act.
- orangefarm 6y agoThe arbitrariness with which these companies rule over our digital lives infuriates me more from month to month. We do our best to fight dictators in the physical world but somehow accept them in the digital realm.
- croh 6y agoWell said. There should be really good laws for these companies. Sadly no same bad PR yet received to google/amazon like facebook. The amound of data both collect is enormous.
- asciident 6y agoWhile they do have power over users on their platform, they're voluntary applications that people choose to give control to for convenience and publicity. Unlike credit bureaus who actually ruin peoples' lives with their carelessness and you can't even opt out, social media apps are purely opt-in, and you don't get your wages garnished or bank accounts emptied or lose your ability to drive because of them. And while I hope danny gets his username back, and it's ridiculous what happened, the value of the user account handle that danny had was created by Instagram's efforts. You don't have property rights to it the same way you own actual property or a domain name registered under your name.
- bergstromm466 6y ago> they're voluntary applications ...in an unfree economic system (patents and IP give monopolies) with a black box money system (money is an enclosed protocol). Cooperative Open Value Networks are the future. [1] [1] http://mikorizal.org/ http://mikorizal.org/
- krebs_liebhaber 6y agoHere's a prediction for the future: This will be the first and last time I hear about "Cooperative Open Value Networks".
- Jon_Lowtek 6y ago
- Nbox9 6y agoIs this hearsay or is there proof? Aside from @danny saying it was from an fb employee, there’s nothing else to indicate it was, and I wouldn’t trust the word of a hacker/recipient of a hacked account.
- croh 6y agoWell what he should conclude if support doesn't work at all.
- Nbox9 6y agoInstagram has poor customer support.
- jmcgough 6y agoEven if the fb employee bit is untrue (I'm also skeptical), it indicates that someone can take over your account like this with no recourse.
- Nbox9 6y agoWell, no one is taking over my instagram account because I don’t have one, but it does indicate some people are taking over accounts with no recourse.
- whoknew1122 6y agoI think the biggest 'proof' there is that the twitter account states they haven't received any 2FA requests. Assuming we're taking this as truth then: 1.) Somehow MFA got disabled on the account (or avoided altogether) 2.) Could've got SIM swapped. However this seems rather unlikely, as there are no other reported IoCs which point toward SIM swapping (i.e. can't call or text). > "I wouldn’t trust the word of a hacker/recipient of a hacked account." I wouldn't discount it. This isn't some APT that ran a Stuxnet operation. It's someone who allegedly exploited a system to get an og account. The whole reason people want og accounts is because they're a status symbol in some circles. It's quite likely that someone associated with stealing an og is an immature braggart. So they may do things immature braggarts would do... like talk about their TTP.
- deleted 6y ago[deleted]
- croh 6y agoSadly companies like google, facebook only HN is the way to get resolution. Nobody cares about you. They look into it only when it affects PR.
- lightgreen 6y ago> companies like Any company with large number of users. It is not specific to internet companies. If you complain to McDonald's, you don't really expect to a proper investigation of that wrong burger incident.
- heavyset_go 6y ago> If you complain to McDonald's, you don't really expect to a proper investigation of that wrong burger incident. Apparently McDonald's franchisees take complaints from corporate very seriously, much to the dismay of their often teenaged employees.
- lightgreen 6y agoApparently, Google/Facebook contractors take complaints from Google/Facebook very seriously. What's your point?
- heavyset_go 6y agoThe claim that "wrong burger incident" won't be investigated by McDonald's is incorrect. McDonald's takes problems like that very seriously.
- lightgreen 6y agoWhen you got poisoned and had to go to the hospital, then yes. If it was ketchup instead of curry, or if they put 8 nuggets instead of 9, I very much doubt so.
- 6y ago
- josalhor 6y agoDoes the new owner of the account have access to his previous messages? I wonder how this would play out with GDPR if the original owner was from the EU.
- toonarmybarmy 6y agoAs someone who used to be following his account, any messages we'd had have now gone from my inbox. I also haven't been able to find any likes on any of my images (there was previously)
- Kapura 6y agoI think this is indicative of the biggest problem we have had with social media: there is no legalism here, just "codes of conduct" that companies and users both willfully ignore. If your handle gets sold by some facebook employee to a rich kid in LA, what recourse do you have? I don't know what laws this would break (maybe some broad definition of fraud? I Am Not A Lawyer) so it's not like this person has a slam dunk legal case... We have no external arbiters of online interaction, no well-respected third party we can go to to arbitrate. The last defense is the mob, potentially shaming the companies in question into recanting. I've seen it happen on this very website multiple times. But it is not sustainable, it does not scale, and it allows the companies to keep fucking with people who can't make their injustices known.
- Nextgrid 6y agoI don't think the "theft" of the username would break any kind of law, as this was a company decision (since it done by an employee) and the username was never your property anyway. I'm assuming that employee definitely violated some internal policies, but nothing from a legal point of view. The only recourse I can see from a legal point of view is that they seem to have handed over the entire account (as the followers seem to have been carried over), which contains private data including DMs, stories, archives of deleted pictures, etc. Given that the original owner of the account is based in the UK, GDPR should apply. I wonder if people he talked to via DMs (as well as those with private accounts who granted his account access) would also have a case, since Facebook's actions have disclosed private conversations & contents of private accounts) to an unauthorized person. I don't have a Twitter account but if someone could suggest this person to complain to their local data protection regulator (the ICO in case of the UK) that would be great.
- tdhz77 6y agoI wonder if the justice department would go after somebody who overtook Donald Trump or other high profile official. They might make the case based off national security as the legal rational. But, otherwise I do agree with your point.
- Scene_Cast2 6y ago
- Dolores12 6y agocould be phished fb employee's account like it was in twitter bitcoin case?
- ptero 6y agoIf true, this is despicable and deserves a lot of attention and (maybe) some regulatory response. However, is there a more detailed description instead of a few twits. It seems from the posted pictures that the account was stolen, but why does the author think that a Facebook employee or a Facebook company is behind it? An honest question.
- shadowgovt 6y agoThe tweet author is believing the words of the guy who stole the account. Which... I mean, reliable sources, right?
- cassepipe 6y agoThis is why you want Mastodon :)
- mattl 6y agoDoes Mastodon have an Instagram-esque mode now?
- grahamburger 6y agoPixelfed is the instagram-esque incarnation of the fediverse.
- Nextgrid 6y agoWhich I'd assume will be filled with alt-right and similar content (banned from other platforms usually for good reason), anime avatars and a liberal dose of poor taste (and potentially illegal in certain jurisdictions) content such as "lolicon". None of this is something most people want to be anywhere near. While mainstream social media has many flaws, at least I am grateful for the fact that it bans, discourages or significantly dilutes this kind of content so that it isn't visible in most cases.
- sneak 6y agoAsk for censorship and you will reap the controlled and powerless society that you have sowed.
- pwinnski 6y agoSo that's a yes, then?
- grahamburger 6y agoNot really, actually. Pixelfed (and mastodon, at least the official instances) aren't at all anti-moderation, for better or worse. They're more about moderation at the local instance level. I don't run in to any alt-right content on either pixelfed or mastodon. Not that I'm a huge user of either.
- dannyw 6y agoMy Instagram account has suddenly started asking for a phone number and won’t let me log in without one.
- lightgreen 6y agoOK, then give it a phone number? Why do you post about it on HN, what's the story you want to tell here?
- theduder99 6y agomore proof of instagram's shady business practices
- croh 6y agoThese companies care lot to scale their stack. But nobody gives shit to scale support and handling these kind of issues.
- deleted 6y ago[deleted]
- deleted 6y ago[deleted]
- noxer 6y agoHN is becoming a tool to report such crap. can we stop that pls. I know it may help some but get back their account but it ultimately does not solve the problem and it unfair as most people will not know how to make the necessary drama. + its annoying non-content post we get here every other week.
- harel 6y agoThe number of votes on this post says otherwise. I find HN is good at solving these kind of issues and I find the stories behind these posts interesting.
- nitrogen 6y agoit unfair as most people will not know how to make the necessary drama The solution to a deep problem is not to kick down the ladder a few people have found to climb out of it.
- noxer 6y agoI never said its a solution to the problem. Its a solution to the symptom - the crappy non-content posts on HN like this one. I'm pretty sure these post are against the guidelines anyway.
- megous 6y agoIt's part of ToS you can lose your account at any time for any reason. And it's their first rule.
- nrmitchi 6y agoAnd yet, that rule is stupid. But your logic instagram could just give @kyliejenner to some random person, and you think she would have no recourse? You think it would be acceptable for someone at instagram to do Kylie Jenner a personal favor and give her `@kylie`, and the person who currently has it should have no recourse? Kylie is just an example person with a larger following; I'm not implying that this happened, is happening, or she is in any way involved in this practice. People like to make the claim that "a handle or username has no value" which is just insane. If it had no value, people wouldn't try to steal them. If the first line of a bank ToS was "you can lose your account at any time for any reason", would you think that is acceptable? No, because money _obviously has value_. Usernames have value, and in some cases, usernames have more value than many people's bank accounts. "you can lose your account at any time for any reason" is just an excuse to avoid any concept of _public_ user support.
- rvz 6y ago> And yet, that rule is stupid. Doesn't matter. They can still do it to anyone anyway. > But your logic instagram could just give @kyliejenner to some random person, and you think she would have no recourse? Well yes. They (Facebook) own the platform, it's a privately owned company and they can do whatever they like either via the ToS or in general. You don't own your account handle. They reserve the right to terminate your account or disable the handle at any time.
- nrmitchi 6y ago> Well yes. Strong disagree. If Facebook tried this against anyone with a moderate following there would be a Tortious interference and/or fraud lawsuit filed _immediately_. When Trump's twitter account was deleted by a rogue employee for all of 10 minutes, Twitter most definitely did not just sit back and say "We reserve the right to terminate your account at any time". > it's a privately owned company I know this is going to sound pedantic, but this is wrong. Facebook is a publicly-owned company.
- talawahtech 6y agoLooking at the screenshot of the IG story, it indicates that the compromised account is now followed by @blood, @murder and @dead. Looks like whoever took over the account is not some random kid with a friend at Facebook, but a "professional" account hijacker. Whether they compromised the account via hacking, bribes or social engineering is anyone's guess, but it seems like this ain't their first rodeo.
- dddbbb 6y agoI find it strange that the Facebook employee wouldn't just forcibly change OP's username to something else (e.g. @danny123) then give the desired name to their friend. Actually stealing someone's account seems like an over the top and unlikely way to go about this.
- Nextgrid 6y agoI'd assume there would be bots or just someone trying to sign up with that username by random chance, so they didn't want to leave the username available for a moment. I'd assume there is a proper, transactional (as in database transactions) way to swap usernames like that but the person who did this most likely didn't have access to it (for good reason) and just did an email change + password reset on the original account.
- tluyben2 6y ago> and just did an email change + password reset on the original account. But isn't that why the user had 2FA on? Why can someone change the email + switch off 2FA; you would want only 1 of these would you not? If you tell support you lost your email and 2FA, that would be very unlikely, so why would it be so easy to set that up? Are there immutable logs with credentials for this kind of action and how easy is it for employees to access / change it; I mean why would many people have the permission to take this action? Especially without some kind of flag that there is something up with the account (like unused, flagged content etc).
- Nextgrid 6y agoI'd assume CS has the possibility to disable 2FA or change the phone number it's associated to.
- SpicyLemonZest 6y agoI'm worried about the failure of Internet literacy reflected here. As far as I can tell, the author of the Twitter thread is just some guy, not famous or otherwise widely known to be reputable. And he's presented no evidence which can be independently confirmed - he could be misunderstanding the scenario, or the framing could be made up, or the screenshots could be faked, or any of a million other things. But a bunch of us - 201, as of when I'm writing this comment - are signal boosting and discussing his accusation based on no information beyond our preconceptions about what kinds of things Facebook might do.
- toonarmybarmy 6y agoI know him. He's the poster on here, not just the tweet.
- SpicyLemonZest 6y agoI suppose that does alleviate my concerns.
- toonarmybarmy 6y agoI understand its not exactly proof, but its the best I could do lol.
- SpicyLemonZest 6y agoYeah, it makes sense. I don't mean to propose a standard where nobody can believe anything because it might be made up.
- neurobashing 6y agoSkepticism is warranted but, did everyone forget about a month (?) ago when an insider and "OG username" people did the bitcoin scam on twitter? It's not an unreasonable assumption that this can happen elsewhere.
- rgbrenner 6y agoThis reminded me of an article I read a while ago about Instagram employees selling verification... one of the sources mentions they also sell accounts, but the story is mostly about selling verification. https://mashable.com/2017/09/01/instagram-verification-paid-black-market-facebook/ https://mashable.com/2017/09/01/instagram-verification-paid-... Previously discussed here: https://news.ycombinator.com/item?id=15156790 https://news.ycombinator.com/item?id=15156790
- eisa01 6y agoA friend of mine lost access to his Instagram account that was blocked for impersonating others (he shares the name with a known person). He had no recourse for six months as the form to appeal the decision didn’t work... finally got it fixed in 10 minutes this summer when the form magically worked again This needs to stop
- tomaszs 6y agoI lost my Insta account a year ago. I have explored all possible ways to fix it. Really all. Was working on it for six months. But Facebook didn't provide any real way to restore the access. Even though I had my phone number verified before. If you don't have good connections or can make a social media storm, it is impossible to get the account back. But it occurred I was authentic enough to remove my account. Not to regain access but to delete it - yes. Which I did. It is one of many moments during last year's Facebook gave me the cringy feeling I am not a valuable product for them
- lumberingjack 6y agoYou don't own stuff that you post on the cloud the cloud is just somebody else's computer
- rvz 6y agoCorrect. I'm sure we all knew that already. Too a while for non-technical users to realise this. Unfortunately, via the hard way.
- deleted 6y ago[deleted]
- warrenq 6y agoITT: Proof, how the smartest crowd can be so gullible. These are the same guys who proclaim "Ads will never work with me"
- jtchang 6y agoThis is one of the symptoms of possible anticompetitive issues. Facebook has a lot more power now and really no meaningful competitors. The more you learn the more you realize that competition can be a good thing and facebook may be abusing their position.
- ylee 6y agoOn a related note, I would appreciate suggestions on how to regain my Facebook account, shut down without explanation a year ago. Despite its age (15 years) I barely used it, let alone for anything "controversial", but did regularly log into it. I have repeatedly tried to verify my identity by submitting an image of my driver's license, without any response. I don't want to create a fake new Facebook account. I want my own back.
- covercash 6y agoThis happened a while back to Brian Hoff’s wife, he was able to eventually get it back: https://medium.com/@behoff/they-say-nothing-will-change-5c546662abc0 https://medium.com/@behoff/they-say-nothing-will-change-5c54...
- p2detar 6y agoOh, man. I was skeptical about OP's Facebook employee hack thing at first, but then I read this medium write up. Not good.
- throwaway981723 6y agoI work at FB and I assure you if an FB employee is involved they'll be fired right away and there'll be a lot records so they cannot escape.
- ajb 6y agoI can understand why someone would need a throwaway to criticise their employer; using one to praise them is a little odd, however.
- yipbub 6y agoMaybe they've got other stuff on their main account they don't want their employer to see.
- chinathrow 6y agoI believe you once he get his account back.
- raverbashing 6y agoI'm thinking even with 2fa there can be a way of ask for support to reset your password, that's probably what happened Because OF COURSE people set 2fa without getting the recovery codes or using sms (why is that even an option I don't get it) Edit: some ideas here from a phishing expert https://twitter.com/RachelTobac/status/1310264189861019649 https://twitter.com/RachelTobac/status/1310264189861019649
- polynomial 6y agoIt appears to have reverted back to the originally Danny? (6 posts, not 100, 5,563 followers, 6 posts, set to private) https://www.instagram.com/danny/ https://www.instagram.com/danny/
- JanNash 6y agoI’ve asked danny on Twitter if he can confirm this.
- toonarmybarmy 6y agoIt hasn't. Although a product designer at FB has got involved. https://twitter.com/diegojimenez/status/1310266030388846595?s=21 https://twitter.com/diegojimenez/status/1310266030388846595?...
- JanNash 6y agoLo’ and behold!
- notdang 6y agoapparently he did not lost his images. the original account was swapped with this one: https://www.instagram.com/danny.miracle.done3/ https://www.instagram.com/danny.miracle.done3/
- iJohnDoe 6y agoAs soon as I saw the first name only as the username I didn’t even have to scroll to see that it was probably an Instagram employee that stole it.
- scott31 6y agoI suppose he has read and agreed to Terms of Service when he signed up, which gives the company ability to do anything with their account. Facebook is not in the wrong here against this guy, just some employee did not follow the Facebook's internal rules.
- ansley 6y agoSomething similar happened to me too - an automated squatter took control of my account when I changed email addresses, started posting TOS violating images and got banned. There’s zero support unless you ask someone to abuse their access to help.
- watertom 6y agoTechnically nobody owns anything. An ID is assigned at the discretion of the issuing organization. The ID wasn’t purchased, rights and ownership was never transferred.
- xwdv 6y agoThere is no reason here to believe the victim is telling the truth. He could have simply grown tired of the Danny username, because of the constant spam it gets, and decided to cash in on it in exchange for some internet fame. I assure you no Facebook employee would do something like this, an audit would clearly show what happened and that employee would be terminated quickly and probably face legal repercussions. Don’t believe everything you read.
- fedd 6y agoMy instagram account belongs to somebody else too. I could once recover it with "forgot my password" feature, but then they took it back anyway
- tehlike 6y agoWhat username?
- Kiro 6y agoAre we seriously just going to presume that this is true based on a hacker saying "my friend works at facebook"? This feels like the Apple refund thread all over again, with the same problematic outcome if it turns out to be false - people not seeing the rebuttal and still thinking it actually happened.
- Kiro 6y agoFor all the talk about The Social Dilemma and how quickly unconfirmed stories spread and are cemented due to social media I'm disappointed that we are no better. We devour this as facts just because it fits our narrative.
- wdr1 6y agoThe only evidence of Facebook being involved is the hacker claims it? Seems somewhat flimsy...
- throwigemp1 6y agoI work at Instagram and there's literally zero chance of this happening. I work on the backend, so I know the kind of tools or logging we do. If in the chance this happens remotely, like 1 in a million chance, the employee will be fired like instantly. I can't believe a random tweet with a screenshot is on front page of HN with 500+ upvotes.
- TavsiE9s 6y agoWell then I'm sure you'll put in a ticket on Monday and have this investigated.
- dredmorbius 6y agoThe account transfer happening may well have occurred, whilst the mechanism is misrepresented (likely by the attacker). Either way, a claimed user is plausibly representing a problem with no viable recourse from IG/FB. The upshot of unauthorised account transfer would still lie on Instagram/Facebook, and should you in fact be a back-end engineer, filing a ticket and escalation would be strongly encouraged.
- milofeynman 6y agoThat is the software engineer mantra: "There is no way that bug could happen... Oh"
- mFixman 6y agoIf you can't believe a crazy conspiracy theory about Facebook would get 500+ on HN then you haven't been in post-2016 HN much.
- charia 6y agoI mean this has happened with Instagram accounts historically. https://medium.com/@behoff/they-say-nothing-will-change-5c546662abc0 https://medium.com/@behoff/they-say-nothing-will-change-5c54...
- cnst 6y agoThat's from 2014. However, it seems like there's not been an official statement, so, unclear how or why it got resolved. These days in 2020, a short Instagram handle is probably worth more than it was in 2014, though.
- beshrkayali 6y agoRegardless of the technical aspect if this is possible or not (I like how a random commenter here claiming he’s from Instagram is asking people not to trust a random tweet with a screenshot), I don’t see the problem as some suggested with the lack of regulation in social media. The issue is really in the blind trust people have put in these companies. Losing the username is one thing, but losing access to messages and potential private images on there is the actual pain, maybe not for this guy specifically but fun general. Having your private conversation on these platforms, your entire business or a huge portion of your marketing, or as a main way to “connect” with others is the problem, it’s like leaving your door and windows open for a week and then being surprised that your house got robbed. It might not happen, but it’s a huge risk. The solution is easy: don’t entirely depend on these platforms and don’t store valuable data there.
- cgb223 6y agoSounds an awful lot like the Twitter Blue Checkmark Hack a few months ago where a hacker got into a db and just reset all the accounts to his own/his friends email addresses www.theverge.com/platform/amp/2020/7/15/21326372/twitter-hack-bitcoin-scam-new-tweets-shut-off-verified-accounts
- Google234 6y agoI’m going to guess they sold the account are now trying to get it back
- bhay 6y agoThis has happened to me previously on FB. Had an account, of my first and middle names, that I'd stayed up to get when they released that feature on FB. Both short names like LeoMark. Woke up one morning and they'd changed it to LeoMarkus, and given the old account to someone. Pretty sure something similar also happened on LinkedIn. Was pissed off at the time but pretty happy with no Facebook account these days.
- ericabiz 6y agoI’m pretty sure PlugWalkJoe is behind this. Someone here mentioned the “dead” account on IG and I remembered, for some reason, Krebs talking about that in his article about the Twitter crypto attack. Either this was a SIM swap or someone in that group has gotten access to IG internal tools just like they did Twitter. I’ve Tweeted @dannyjhall about this. PlugWalkJoe owns “dead” on IG: https://krebsonsecurity.com/2020/07/whos-behind-wednesdays-epic-twitter-hack/ https://krebsonsecurity.com/2020/07/whos-behind-wednesdays-e... Danny’s new account follows “dead” and two other “OG” accounts: https://news.ycombinator.com/item?id=24608990 https://news.ycombinator.com/item?id=24608990
- rasz 6y agoIn US? Contack FBI, report identity theft, maybe extortion (message from new "owner").
- easytiger 6y agoI had my I instagram account stolen. I think it's not an employee but a flaw in their account recovery process that lets 3rd parties change the email. Only way to resolve it was to click the link in the email notification for change of email address.
- javierbyte 6y agoDanny was deleted a minute or two ago https://www.instagram.com/danny/ https://www.instagram.com/danny/
- botverse 6y agoI would guess a FB employee is reading the thread
- Svoka 6y agoStill there it seems.
- javierbyte 6y agoIt was restored to the original owner, I'm not sure when.
- swalsh 6y agoSocial media accounts can be worth real money in the right conditions. It might be time to start having some real regulations around these things. If my bank account was hijacked, the bank wouldn't be able to just ignore my pleas. I remember seeing a youtuber who made a living off her account about a year ago get her account hijacked, and it took months to resovle the issue. Youtube didn't really help her at all until it became quite public.
- rainyMammoth 6y agoGood reminder that all "your" messages, photos, private data etc never belonged to you. It always belonged to Facebook and they can do whatever they want with it. Including deleting everything on a whim if it pleases them. How do we change that? We go back to personal websites that you fully own. All of those platforms have been proven to be highly unethical (especially Facebook). Trusting them with all your data has always been a bad move. We need to take back ownership of our platform.
- kamel3d 6y agoI lost my facebook account last year after someone copyrighted my own profile photos, I get a strike every time I upload a selfy then my account got shut down, this is slightly different from this story but it show that facebook spend zero effort to fix this issue unless the story blow up, I am political activist in Algeria and the dictator regime there were using some 3rd party companies to copyright activists content on facebook and use it to shutdown their pages
- cryptoz 6y agoReminds me of when Instagram stole some dude's account and just handed it to the "Royals" https://www.instagram.com/sussexroyal/ https://www.instagram.com/sussexroyal/ Poor dude was like a WAU for years and Instagram just went 'nah' and gave it to royals. Your account isn't yours, it's Instagram's. They don't care about you or your photos or your likes or friends or connections either.
- itsthecourier 6y agoI wrote an article showing how fucked up instagram is letting thieves steal and destroy accounts. they did mine: "Your instagram account could be destroyed in 10 minutes and there is nothing you can do" https://dariogalvis.com/post/630455195481063424/your-instagram-account-could-be-destroyed-in-10 https://dariogalvis.com/post/630455195481063424/your-instagr...
- AA-BA-94-2A-56 6y agoAnecdotal, but I used to own the @clonetrooper Twitter handle. One day I woke up and someone else had it. Tried contacting Twitter, and they wouldn't accept my screenshots as evidence that I owned it. So what do I do? It's been almost a decade now, and I will never get it back.
- intrasight 6y agoGet a new one. I think they are free.
- will_walker 6y agoThere's a great episode on ReplyAll podcast[0] about the methods for bypassing 2FA to snag accounts. Was the 2FA endpoint a SMS cell number? In that case, it's probable the thief fraudulently impersonated the victim to the cell service provider and phished the 2FA code. Sadly, the cell providers are the weakest link in that particular chain (probably much weaker than Facebook's security). I also wouldn't put it past someone to guess a password or have reused a password with another service that has been hacked. Humans are terrible at password hygene. [0] https://gimletmedia.com/shows/reply-all/v4he6k https://gimletmedia.com/shows/reply-all/v4he6k
- higerordermap 6y agoMore than this, instagram doesn't take reports seriously. I have reported many accounts obviously impersonating celebrities to gain followers, and they didn't ban those accounts.
- iamleppert 6y agoThis isn’t your property. It belongs to Facebook, they are just letting you use it and they have the right to take it away or do whatever they want with it. If you’re a nobody you don’t have a lot of recourse, just got to move on with your life.
- Deely123123 6y agoIts exactly the same as with government, yes? Roads isn't our property, houses (sometime) isn't our property, country where we all live isn't our property. So what?
- rasengan0 6y agohttps://help.instagram.com/519522125107875 https://help.instagram.com/519522125107875 based on the data policy, Danny Hall and imposter collected as the same identity. One wonders if the ads will be pitched to the same 2 individuals.
- trollied 6y agoHe has the account back: https://twitter.com/dannyjhall/status/1310499000471224320 https://twitter.com/dannyjhall/status/1310499000471224320
- gertrunde 6y agoA bit late - but worth adding anyway, the issue was apparently resolved, and the relevant Instagram account returned. Although no explanation on what occurred. https://twitter.com/dannyjhall/status/1310499000471224320 https://twitter.com/dannyjhall/status/1310499000471224320
- scott800 6y agoThe Internet Of Today is filled with scam due to the world pandemic, the rich are getting richer and you have to follow Quality job assurance,These hackers have helped Individuals Organization to Secure and to Recover their lost files/Password/ funds etc. They Are Hackers for Hire. I am saying leave your problem & your Worries for them to solve for you 100%guarantee* iOS/windows/iPhone/Android Phone Hacking * loans University Grades Iclouds breaching Criminal Records Hacking ATM/Credit Cards Binary Recoveries BTC Mining * Cyber Scam recovery etc…!!!Email:-Theredhackergroup@gmail.com Or Text/Whatsapp:+1 571 318 9498