← All posts

What to do if your social media account was hacked

You went to open Facebook or Instagram and your password no longer worked, or friends started messaging to ask why you were posting strange links and asking them for money. Maybe the email tied to the account changed without you touching it, or a login alert arrived from a city you have never been to. Whatever tipped you off, the feeling is the same: something that holds years of your photos, messages, and connections is suddenly not yours to open.

Take a breath. Most hijacked accounts can be recovered, and the sooner you start, the more of your account and your contacts you can protect. Here is where to begin.

Move fast, and start from a device you trust

Do the recovery from a phone or computer you own and know is clean, not a shared or public machine. If you can still get into the account at all, change the password immediately to something long and unique that you have never used elsewhere, and sign out of all other sessions. If you are already locked out, do not keep guessing the old password. Go straight to the platform’s official recovery flow, which is built for exactly this situation.

Use the platform’s recovery flow

Each service has a dedicated path for compromised accounts, and it is the fastest legitimate route back in. For Facebook and Instagram, start at facebook.com/hacked, which walks you through identity checks and can flag that your email or password was changed by someone else. Instagram also offers recovery directly in its app under login help, including a video selfie step if a scammer swapped your email. On other platforms, search the official help center for “hacked” or “recover account” and follow only links on the service’s own domain. Be patient with these steps, since providing the original email, phone number, or a recognizable device speeds things up considerably.

One caution while you are searching for help: do not call a “support number” you find through a random web search or a sponsored ad. Real platforms handle account recovery through their own website or app, not a phone line, and fake support numbers are their own scam.

Once you are back in, lock it down

Getting back in is only half of it. The person who took the account may have left themselves a way back, so close those doors while you are logged in. Change the password again if you reset it in a hurry, then turn on two-factor authentication using an authenticator app rather than text messages where you can. Review the list of active logins and devices and remove anything you do not recognize. Check the email address and phone number on the account and reset them to yours if they were changed. Finally, look at connected or authorized apps and remove any you did not add yourself.

It is worth checking the email inbox tied to the account as well. Attackers often set up hidden forwarding or filtering rules so password-reset messages quietly disappear, and clearing those out is part of fully taking the account back.

Warn the people in your contacts

While the account was out of your hands, whoever held it likely messaged your friends and followers, often with a fake emergency, a “check out this video” link, or an investment tip. Let people know the account was compromised and that any money request or link during that window did not come from you. A short, plain note is enough. This protects the people who trust you and slows the scammer from turning your account into a launchpad for the next victim.

Report it and document what happened

Report the compromise inside the platform so it is on record and so they can act on any fraudulent posts sent from your account. Take screenshots of the login alerts, the changed-email notice, and any scam messages sent in your name before they vanish, since that record helps if you need to prove the activity was not you. If the hacker used your account to defraud someone, or if your personal or financial information was exposed, file a report with the FTC at ReportFraud.ftc.gov, and use IdentityTheft.gov if you think your identity is now at risk. Where a real financial loss occurred, IC3.gov is the right place for that report too.

How this usually happens, so it does not happen again

Most account takeovers start with a reused password exposed in some unrelated breach, or with a phishing page that copied the real login screen and captured what you typed. A smaller but serious share start when someone takes over your phone number first, which lets them intercept text-based codes. If your phone recently lost service around the time this began, our guide on the SIM swap scam is worth a read. Switching to unique passwords and app-based two-factor closes off the two most common paths at once.

Watch for what comes next

Two follow-ups are common after a hijacking. The first is impersonation: even after you recover your account, a scammer may spin up a lookalike profile using your name and photos, and our guide on someone impersonating you on social media covers how to get those taken down. The second is a “recovery” offer, where a stranger messages you promising to restore the account or your lost money for an upfront fee. That is a second scam. Real recovery comes from the platform’s own tools, never from someone who contacts you first and asks to be paid. If private material was exposed in the process, our guide on what to do if someone doxxed you may help too.

Losing access to an account that holds so much of your life is unsettling, but it is a solvable problem. Work the platform’s recovery steps, close the doors behind you, tell your people, and you will be back on solid ground.

— Gus