If you've ever had an account or relationship with Instacart, it's worth checking whether your personal data was exposed in this incident. Here's what happened, what data was involved, and what to do about it.

What Happened

In 2020, journalists reported that Instacart customer account data — including names, order histories, and partial payment card digits — was being sold on a dark web marketplace. Instacart investigated and stated that the exposure was not the result of a direct breach of its own systems, but rather attributed to credential stuffing: attackers using email and password combinations leaked from other, unrelated breaches to log into Instacart accounts where customers had reused the same credentials.

What Data Was Exposed

The exposed data reportedly included customer names, the last four digits of payment cards, and order histories, obtained by logging into individual accounts using credentials stolen from other services rather than through a direct database compromise.

Why This Still Matters

Exposed data doesn't expire. It's sold, traded, and reused for years, fueling credential stuffing attacks — automated attempts to reuse your email and password combination across other sites. If you reused a password anywhere, one old exposure can compromise several current accounts.

How to Check If You Were Affected

Use our free breach checker below — enter your email and we'll scan it against known breach databases instantly, no signup required.

What to Do If You Were Affected

👉 Check your own exposure in 30 seconds → scan your email free.

Frequently Asked Questions

Was Instacart actually hacked?

Instacart stated that this incident was not a direct breach of its own systems. Instead, it attributed the exposure to credential stuffing, where attackers used login details leaked from unrelated breaches to access Instacart accounts belonging to customers who had reused the same password.

What data was found exposed from Instacart accounts?

Reports indicated exposed data included customer names, order histories, and the last four digits of payment card numbers for accounts accessed through credential stuffing.

How do I know if my Instacart account is at risk?

If you have ever reused your Instacart password on another site that was later breached, your account could be vulnerable to credential stuffing. Use the free checker at Scan My Shadow to see if your email has appeared in any known breaches.

What did Instacart do in response?

Instacart stated it implemented additional account security monitoring and recommended users enable unique, strong passwords and be cautious of password reuse across services.

How can I protect my Instacart account from credential stuffing?

Use a unique password for your Instacart account that you don't use anywhere else, enable any available account security features, and change your password immediately if you learn it was exposed in an unrelated breach.

Sources

Related Reading