If you've ever had an account or relationship with Instacart, it's worth checking whether your personal data was exposed in this incident. Here's what happened, what data was involved, and what to do about it.
What Happened
In 2020, journalists reported that Instacart customer account data — including names, order histories, and partial payment card digits — was being sold on a dark web marketplace. Instacart investigated and stated that the exposure was not the result of a direct breach of its own systems, but rather attributed to credential stuffing: attackers using email and password combinations leaked from other, unrelated breaches to log into Instacart accounts where customers had reused the same credentials.
What Data Was Exposed
The exposed data reportedly included customer names, the last four digits of payment cards, and order histories, obtained by logging into individual accounts using credentials stolen from other services rather than through a direct database compromise.
Why This Still Matters
Exposed data doesn't expire. It's sold, traded, and reused for years, fueling credential stuffing attacks — automated attempts to reuse your email and password combination across other sites. If you reused a password anywhere, one old exposure can compromise several current accounts.
How to Check If You Were Affected
Use our free breach checker below — enter your email and we'll scan it against known breach databases instantly, no signup required.
What to Do If You Were Affected
- Change any reused password immediately, starting with your most sensitive accounts.
- Enable two-factor authentication wherever it's offered.
- Monitor financial and health accounts closely if that kind of data was involved.
- Watch for phishing — exposed data is often used to craft convincing scam messages.
- Freeze your credit if your SSN or government ID number was exposed.
👉 Check your own exposure in 30 seconds → scan your email free.
Frequently Asked Questions
Was Instacart actually hacked?
Instacart stated that this incident was not a direct breach of its own systems. Instead, it attributed the exposure to credential stuffing, where attackers used login details leaked from unrelated breaches to access Instacart accounts belonging to customers who had reused the same password.
What data was found exposed from Instacart accounts?
Reports indicated exposed data included customer names, order histories, and the last four digits of payment card numbers for accounts accessed through credential stuffing.
How do I know if my Instacart account is at risk?
If you have ever reused your Instacart password on another site that was later breached, your account could be vulnerable to credential stuffing. Use the free checker at Scan My Shadow to see if your email has appeared in any known breaches.
What did Instacart do in response?
Instacart stated it implemented additional account security monitoring and recommended users enable unique, strong passwords and be cautious of password reuse across services.
How can I protect my Instacart account from credential stuffing?
Use a unique password for your Instacart account that you don't use anywhere else, enable any available account security features, and change your password immediately if you learn it was exposed in an unrelated breach.