Man gets his Instagram hacked. Then he realizes just how easy it was: ‘didn’t even ask for your password or 2FA’

Man gets his Instagram hacked. Then he realizes just how easy it was: ‘didn’t even ask for your password or 2FA’
Credit: @aftab.barkat/Tiktok Photo by Solen Feyissa on Unsplash

Tap in; a new tech fear just dropped. Aftab Barkat (@aftab.barkat), a London-based tech and cybersecurity creator, says he can slip into someone's Instagram account with nothing but a browser. No Kali Linux, no password, no two-factor code. In a video that received more than 430,000 views, he walks through the method. The TikTok guide doubles as a plain-language crash course in why the login page isn't the last line of defense.

“I'm gonna show you how hackers can get into your Instagram account without knowing your password or your two FA code,” he says. “All you need for this demo is your web browser.”

The story

Barkat frames the concept with a theme-park analogy: you show your ticket at the gate, they hand you a wristband, and every ride after that just checks the band. “The websites work in a similar way,” he says. “Once you give your password, they give you something called session ID.”

@aftab.barkat How hackers hack and get access to your Instagram and other accounts if you are not careful. Educational purposes only!!! #techtok #cybersecurity #cybersecuritytips #hacking #pentesting ♬ original sound – Aftab Barkat | Cyber & AI

Barkat's walkthrough makes it more terrifying and real. From a logged-in account, a person can right-click, Inspect, open the Applications tab, take a peek into Instagram's cookies, and then just copy the session ID value. Then they can open a second profile in the same browser, paste over its session ID with the copied string, and refresh. The window loads inside the first account. Why does this work? “The website never asked for a password or the two FA code,” he says. “This is because it trusted the existing session.”

Barkat calls the demo educational; he's not trying to encourage malfeasance. He also says it runs in “a controlled vulnerable environment”—a hedge worth noting. He also provides some keys to keep people out of your business—never stay logged in on shared or public devices, sign out when done, and audit active sessions in account settings.

Malicious browser extensions and phishing sites, he adds, are among the most common ways attackers grab real cookies in the wild.

The peanut gallery

Some people didn't believe Barkat. “That's not going to work,” one person said. “As soon as you refresh or click on anything you'll be logged out. What you want is 2fa session tokens.”

Barkat replied, “Not in the slightest good Sir! Try it first and then we'll talk. I think you're going to have a moment of enlightenment if you do try it ;).”

The wristband in the wrong hands

The FBI's Atlanta division issued its own warning in October 2024, flagging “Remember-Me cookies” as an increasingly popular way for attackers to sidestep multi-factor authentication. “Cybercriminals are gaining access to email accounts by stealing cookies from a victim's computer,” the bureau wrote.

In July 2025, it moved its Device Bound Session Credentials protocol into open beta in Chrome on Windows, binding session cookies to a private key inside the device's secure hardware.

Andy Wen of Google Workspace said DBSC “helps bind a session cookie… to the device a user authenticated from.” Replayed on another machine, the cookie is inert.

Buzz News reached out to Barkat and Meta via email for more information.