Confirm the signs and preserve useful information
An unfamiliar login, changed recovery address, messages you did not send or loss of access are serious signs. Note the times, devices, alert emails and visible actions without repeatedly attempting to sign in.
Work from an updated device you consider trustworthy. If you suspect malware, install updates and run the available security checks before entering a new password.
Secure email before starting official recovery
Your email inbox can usually reset other accounts. Review its password, forwarding rules, recovery details and active sessions. Remove any rule or address you do not recognise.
Then open the social network’s app or type its address yourself. Find the help route for hacked accounts. Do not buy recovery help from a stranger, and never share a code received by text message or authenticator app.
Remove persistent access
After regaining control, create a unique password and enable two-step verification. Sign out every device or session, then reconnect only the ones you control. Review authorised apps, administrators and recovery details.
Change the password on every other service where the old one was reused. Review posts, messages, follows and settings changed during the compromise.
Limit the impact and organise follow-up
Warn contacts through a trusted channel so they ignore recent links, requests for money or codes. For an organisation account, inform the team and remove obsolete access. Contact your bank promptly if financial details may have been exposed.
Keep evidence and support replies. Depending on the harm, use the reporting and law-enforcement routes available in your country. Recovery can take time; create a replacement account only after documenting the old one and clearly warning your community.
Checklist
- I am using a trusted, updated device.
- The linked email and forwarding rules are secure.
- All unfamiliar sessions and connected apps are removed.
- My contacts know to ignore suspicious recent messages.
Frequently asked questions
Should I pay someone to recover the account?
No. Use the provider’s official support route. People promising guaranteed recovery for payment may be trying to scam you again.
Is changing the password enough?
Not always. Also close sessions, check email, authorised apps and recovery details, and enable a second login step.
What if I cannot recover the account?
Continue the case with official support, keep reference numbers and warn contacts. If you create a replacement account, say clearly that the old one is compromised without publishing sensitive details.
Sources & method
The sequence follows guidance from the NCSC, FTC and Cybermalveillance.gouv.fr. Screens and proof requirements differ by provider.
- NCSC — Recovering a hacked account ↗
- FTC — Recover your hacked email or social media account ↗
- Cybermalveillance.gouv.fr — Compromised social account response ↗
Editorial responsibility: Alexis R., World Web Certified. Suggest a correction.
