If your Instagram account has been hacked, look in the account's email inbox for a message from security@mail.instagram.com, which can reverse an email change, and open instagram.com/hacked in a browser to follow the recovery route that fits. If you can still log in, change the password straight away, turn on two-factor authentication, and remove any linked accounts and third-party apps you don't recognise.
For a creator, getting back in is only half the job. A takeover can leave behind a changed email, a stranger's device, a connected app or a business partner with access, and any of them can lose you the account again. This guide gives a first-hour recovery checklist built on Instagram's own help pages, then a lockdown list for everything around the account. Accounts that Instagram itself disabled follow a different process, set out in our guide to the Instagram disabled account appeal.
Signs the account was taken over
Meta's page If your account was hacked lists the usual signs: your email or password changed, your name or birthday changed, messages went out that you didn't write, or posts and ads appeared that you didn't create. Instagram's article on unauthorised content adds comments and shares you didn't make, and notes that you may see a “Try again later” error if Instagram detects inauthentic activity on the account.
First-hour recovery checklist
Work down this list in order. Every step comes from Instagram's article If you think your Instagram profile has been hacked unless another source is linked, and the article recommends trying all of them, because some won't be available for every account.
- Check the email inbox on the account. If a message from security@mail.instagram.com says your email address was changed, use the secure my account option inside it to undo the change. Look in spam too.
- Go to instagram.com/hacked. Open it in a desktop or mobile browser and choose the option that matches what happened.
- Request a login link. On the login screen, tap Forgot password, enter the username, email or phone number, complete the captcha and open the link that arrives by email or text.
- Ask for a security code or support. If the login link fails, request a security code from a mobile device, and give a secure email address that only you can access when asked.
- Be ready to verify your identity. For an account without photos of you, Instagram asks for the email or phone number you signed up with and the type of device you used. For an account with photos of you, it asks for a video selfie turning your head in different directions. If the first video fails, you can submit another.
- Secure the email account behind Instagram. If the attacker got into your email as well, recover that first through your email provider, or every reset link you request will go to them.
- Ignore offers of help. Strangers selling account recovery in comments or DMs are not part of Meta's process. Meta also states on its phone support page that none of its apps has a general customer-service phone line, so treat any number offering Meta support as a likely scam.
- Keep a record. Note the time you noticed, what changed and every email you receive, with screenshots. You will need it if recovery drags on or a brand asks what happened.
- Use Meta Verified support if you have it. Meta's Meta Verified support page lists account access and security among the issues it handles and says it can help subscribers who were hacked secure their account. Our analysis of whether Meta Verified is worth it weighs that against the cost.
If the identity check worries you, Instagram's hacked-account article adds that it deletes the selfie video within 30 days and never shows it on Instagram.
If you can still log in
Act before the attacker locks you out. Instagram's hacked-account article and its article on unauthorised content give the same core steps:
- Change your password, or send yourself a password reset email. The unauthorised content article says changing the password logs out every device signed in to the account.
- Turn on two-factor authentication.
- Confirm the phone number and email address in your account settings are yours.
- Open Accounts Center and remove any linked accounts you don't recognise.
- Revoke access for any suspicious third-party apps.
- Check for posts, comments, messages or profile edits you didn't make, and delete or reverse them.
If the account is a professional account and someone is still taking actions on it after you have done all this, the hacked-account article links to a separate Instagram page for that case. That pattern often means another person or business still has access, which is what the partner rows in the lockdown list deal with.
Post-recovery lockdown list
Once you are back in, close every route the attacker might use to return. Work through the rows in one sitting and write down what you changed.
| Area | What to check | Source |
|---|---|---|
| Password | New, unique to Instagram, never used on another site | Unauthorised content |
| Two-factor authentication | On, using an authentication app, which Instagram recommends over text messages; WhatsApp codes need text messages set up first | Two-factor authentication |
| Backup codes and trusted devices | Backup codes saved somewhere offline; trusted devices list cleared of anything you don't own, and no shared or public device marked as trusted | Two-factor authentication |
| Signed-in devices | Log out of any device you don't own | Meta scams and phishing |
| Email account | Its own strong password and multi-factor authentication, plus recovery options you control | Australian Cyber Security Centre |
| Accounts Center | Linked accounts you recognise and nothing else | Hacked account article |
| Connected apps and websites | Revoke anything you don't use, and anything that offered likes or followers for your login | Unauthorised content |
| Business portfolio and partners | People and partner businesses with access to the Instagram account in Meta Business Suite; remove anyone you can't vouch for | Compromised business portfolio |
| Team and agency logins | Nobody working on the account shares your password; access is granted per person and can be withdrawn | Account access checklist |
| Profile fields | Name, bio, links, contact email and phone all back to your versions, with no attacker links left behind | Signs of a hacked account |
Meta's business help page on recovering a compromised business portfolio says these compromises typically start when one individual account is hacked or reached through malware or phishing. If several people help run your account, every one of them needs the same lockdown, not just you. Our account control map is a simple way to list who holds which access.
Warning your followers
Your followers may have received messages from the attacker, and brands may have seen posts you didn't write. Once the account is secure, tell them clearly and once, without drama:
- Post a Story and, if the attacker posted publicly, a feed post saying the account was compromised and is now back under your control.
- Give the time window of unauthorised activity, so people know which messages to ignore.
- Ask anyone who received a link or a payment request from the account in that window not to open it, and to report it.
- Say plainly that you will never ask for money, gift cards or login codes in DMs.
- Email brand partners and collaborators directly rather than relying on them seeing a Story.
- Search for lookalike accounts using your name and photos, since attackers sometimes set up copies; our guide to reporting a fake Instagram account covers what to do.
- Keep the note pinned or highlighted for a while, then remove it once the questions stop.
How takeovers usually start
Instagram's article on phishing describes the commonest opening: a message or link asking for personal information, often claiming the account will be banned or deleted if you don't comply, leading to a site that collects your username and password. Genuine Meta email comes only from a short list of domains, among them instagram.com, facebookmail.com and meta.com, according to its scams and phishing page.
Creators face a few extra variants: fake brand collaboration offers that ask you to log in to see a brief, fake copyright or verification notices, and apps promising followers in exchange for your login, which Instagram's unauthorised content article warns against by name. Reused passwords and logins shared with helpers widen the gap. Our creator safety and privacy guide covers the wider habits that keep accounts secure.
If recovery stalls
Keep to the official routes. Instagram's hacked account hub points to instagram.com/hacked and to Meta's Account Recovery and Support Hub, and those are the places to return to. If you see a message saying the account was disabled rather than taken over, switch to the disabled-account process. Don't pay anyone who offers to recover it; in the US, the FTC's guidance on refund and recovery scams warns that people asking for an upfront fee to get back what you lost are running a scam. If the takeover involves threats, extortion or stolen intimate content, report it to the police and, in Australia, to eSafety.
Limitations of this checklist
Instagram says some recovery steps are not available for every type of account, and the options you see can differ by device, region and how much of the account the attacker changed. Menu names also change as Meta moves accounts into Accounts Center and Meta Accounts. Follow the on-screen instructions where they differ from this list, which reflects Meta's pages as they read on 1 October 2026.
No checklist can promise you get the account back; recovery depends on Meta confirming you are the owner. This page covers Instagram itself, not a full security review of your devices. If you suspect malware, or the attacker accessed financial accounts, get help from your bank and a qualified IT security professional.