Cyber Security News

Instagram’s to End Encrypted Chats for Direct Messages

Meta has announced that Instagram will officially discontinue its optional end-to-end encrypted direct message feature on May 8, 2026.

The feature was initially rolled out for testing in 2021 to provide users with a secure communication channel accessible only by the sender and recipient.

Meta cites very low adoption rates among its user base as the primary reason for sunsetting this privacy feature.

Once the May 8 deadline passes, all direct messages on the platform will revert to standard Transport Layer Security.

Transport Encryption Versus Privacy

The transition away from end-to-end encryption marks a significant shift in how user data is handled on Instagram.

With end-to-end encryption, cryptographic keys are stored exclusively on user devices, preventing intercepted messages from being read by anyone.

By reverting to standard transport encryption, data remains secure while traveling across the network, but is decrypted once it reaches Meta’s servers.

This architectural change allows Meta to perform several new actions on your private messages.

  • Automated scanning for safety violations and malicious links.
  • Integration of private chat data into machine learning and AI training models.
  • Fulfillment of legal requests or law enforcement subpoenas using plaintext data.
  • Routine moderation using server-side keyword tracking and behavioral analysis.

Furthermore, cybersecurity experts note that removing end-to-end encryption increases the risk of data exposure in the event of a server-side data breach.

Users who previously relied on the encrypted chat feature must take immediate action to preserve their communication history.

Meta is actively sending notifications urging affected users to export their encrypted chat data before the infrastructure changes take effect.

After the cutoff date, previously encrypted threads will become fully accessible to Meta’s automated moderation algorithms.

To safeguard their data, users should navigate to their account security settings and request a secure download of their personal information.

Failing to export this data before the deadline means those private conversations will seamlessly be added to the platform’s scannable database.

Community Backlash and Alternatives

The cybersecurity community and privacy advocates have strongly criticized this sudden policy change.

Threat intelligence experts emphasize that removing built-in security features contradicts the growing global demand for robust digital privacy.

Social media discussions, including alerts from security firms like Malwarebytes, highlight public frustration over corporate data harvesting.

In response to the changes, security researchers continue to recommend migrating sensitive conversations to dedicated secure platforms.

Meta actively encourages users seeking privacy to transition to WhatsApp. However, many privacy-conscious individuals are shifting to independent messengers like Signal.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

3 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

13 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

14 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

14 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

14 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

14 hours ago