If your Twitter (X) account is hacked and you can still log in, change the password straight away, make sure the email address on the account is yours, and revoke any connected apps you don't recognise. If you're locked out, use Forgot password on the login screen; if the reset doesn't work, submit X's support request for hacked or compromised accounts from the account's email address, giving your username and the date you last had access.
This page covers getting back in and cleaning up afterwards. Preventing the next takeover, including protecting the phone number behind your logins, is the subject of our SIM swap protection guide. If X has suspended the account because of the hack, secure it first and then follow the X suspension appeal guide.
Signs the account is no longer only yours
X's compromised account page lists the signals: posts you didn't write, Direct Messages you didn't send, follows, unfollows or blocks you didn't make, a notice from X that the account may be compromised or that its details changed, and a password that suddenly stops working. The Australian Cyber Security Centre's guide to recovering a compromised account adds login times, places or devices that look wrong, being logged out everywhere at once, and contacts reporting odd messages from you.
Not every oddity is an attacker. X notes that a buggy third-party app can cause unexpected activity, and that changing the password or revoking the app stops it in either case, so the first steps below are worth taking even if you're unsure.
Recovery checklist, most urgent first
- Undo an email change. If verify@x.com wrote to say the account's email address changed and you didn't do it, the compromised account page says the link in that email can reverse the change. Check spam and junk folders too.
- Reset the password. If you're logged in, go to Settings and privacy, then Your account, then Change your password. If you're logged out, choose Forgot password at login; X's password reset page says you need access to the phone number or email linked to the account. Pick a strong password you haven't used anywhere else.
- Use the support form if the reset fails. X's hacked or compromised account form first asks whether you can log in. If you can't, fill it in using the email address linked to the account, and include your username and the date you last had access.
- Take back the email account if it fell too. The FTC's hacked account guidance explains why this comes early: whoever controls your inbox can request password resets for your other accounts.
- End every other session. In Apps and sessions, choose Log out all other sessions. X's third-party apps page says this stops further actions from those sessions but may not delete data, such as Direct Messages, already cached on a device.
- Revoke the mobile apps as well. X's pages disagree here. The password reset page says changing your password logs you out of all other active sessions, but the compromised account page says it does not automatically log the account out of X for iOS or Android, and tells you to revoke those apps under Apps. Revoke them anyway; it costs nothing.
- Turn on two-factor authentication. X's two-factor page offers an authentication app or a security key to everyone, and text message codes only to Premium subscribers since March 2023. Store the backup code offline.
- Switch on password reset protection. X's password reset help suggests it if reset emails keep arriving that you didn't request; it makes anyone starting a reset enter the account's email address or phone number.
- Give trusted tools the new password. Schedulers and other apps still using the old password can trigger repeated failed logins, which X's temporary lock-out page says can lock you out for about an hour. With two-factor on, X says apps that need your password require a temporary password instead.
- Scan your devices. X recommends checking computers for viruses and malware and installing security patches, especially if unwanted posts keep appearing after the password change.
- Report it. In Australia, the Cyber Security Centre's recovery guide lists its 24/7 hotline, 1300 CYBER1 (1300 292 371). If the attacker threatens you or demands money, go to the police.
Connected-apps audit table
Apps keep their access after a password change unless you revoke them, so go through the Apps and sessions section one entry at a time. Permission names and abilities come from X's third-party apps page; the team member row comes from the compromised account page.
| Permission or access shown | What it lets someone do | Keep it when | Revoke it when |
|---|---|---|---|
| Read | View your profile, your posts including protected ones, who you follow, mute and block, and your Lists | You use the app regularly and know who makes it | You don't recognise it or haven't opened it for months |
| Read and write | All of the above, plus posting, deleting posts, following, unfollowing, profile edits and settings changes | It is the scheduler or analytics tool you set up yourself | It was authorised around the time the takeover began |
| Read, write and Direct Messages | All of the above, plus sending, reading, managing and deleting your DMs | An inbox tool you depend on, configured by someone you trust | There is any doubt at all, because it can message your fans as you |
| Email address | See the email address linked to your X account | The service genuinely needs to email you | It is a quiz, giveaway or follower-boosting site |
| X Ads analytics | Read campaigns, audiences, ad account details and creatives | You advertise and this is your reporting tool | You have never run ads on X |
| X Ads campaign management | Create and change campaigns, audiences and ad account settings | An agency runs your ads under a written agreement | That agency relationship has ended |
| OAuth 2.0 lists of things the app can view or do | Granular reading and acting on your behalf, as shown on the consent screen | The listed actions match the job the app does | It asks to post or follow for you when it only needs to read |
| Active login sessions | Show where and when the account is signed in | Every device and location belongs to you | Anything you can't place, logged out at once |
| X Pro team members | Other people working inside your account through the teams feature | You added them and still work with them | You can't name the person or the reason they have access |
If an app ever asked for your X password rather than sending you to X's own authorisation screen, revoke it and change the password again. X's apps page warns against giving your login to sites promising more followers fast or apps that post affiliate ads to your timeline.
Cleaning up what the attacker did
- Delete posts and replies you didn't write; X's compromised account page lists this among its precautions.
- Read through your Direct Messages for anything sent in your name. X's Direct Messages page says deleting a message removes it from your account only, and others in the conversation can still see it, so contact those people directly.
- Reverse any follows, unfollows, blocks and mutes you didn't make.
- Restore your display name, bio, website link, pinned post and images, checking carefully for swapped links that send fans elsewhere. If you subscribe to Premium, edits to your name or photo can hide the checkmark until X re-reviews the account, as our guide to verification on X explains.
- Look in your email account for forwarding rules you didn't create and for messages sent or deleted without you, as the FTC guidance suggests.
- Change the password on any other account that shared the old one.
- Keep a short timeline with screenshots: when you noticed, what changed, and every message X sent you.
Warning followers and partners
Notifying contacts is one of the eight steps in the Australian Cyber Security Centre's account recovery guide, and for a creator it protects fans as well as your reputation.
- Once you are back in, pin one short post saying the account was compromised and giving the window of unauthorised activity.
- Ask people not to open links or act on payment requests sent from the account during that window.
- State plainly that you will never ask for money, gift cards or login codes by DM.
- Message brand partners, collaborators and anyone who received a DM, because deleted messages stay in their inboxes.
- Repeat the notice on the other places fans follow you, such as a WhatsApp channel or a Telegram channel.
- Watch for lookalike accounts using your name and photos, and report them through X's in-app reporting.
- Unpin the notice once the questions stop.
When you can't reach the email or phone
X's email access page is blunt: without access to the account's email address or a verified mobile number, X says it can't continue troubleshooting, won't deactivate the account for you or release the username, and may eventually remove the account under its inactivity policy. Start with your email provider's own recovery process, then request a new X password once you're back in the inbox. If a verified mobile number is on the account, choose the text message option on the reset page.
The password reset page says that without the phone or email you may need to sign up for a new account. That is X's last resort for an account you can no longer prove is yours. It is not a way around a suspension, where opening a replacement breaks X's ban evasion rule.
If X locked or suspended the account during the hack
X's locked accounts page describes a lock for security purposes when it detects suspicious behaviour: log in and follow the prompt to change your password, and look for instructions in the account's inbox. The temporary lock-out page adds that X may reset passwords itself on hacked or phished accounts and email the real owner with next steps. If the profile shows Account suspended, X's suspended accounts page says compromised accounts may be suspended until they can be secured and restored, so finish this checklist and then appeal.
Stopping it happening again
Takeovers tend to start in a few familiar ways. X's Authenticity policy lists login data shared with a malicious app or website, weak or reused passwords, malware that collects passwords, and logging in on a compromised network. Before typing your password, check that the page address starts with https://x.com, connect apps only through X's authorisation screen, and never hand your password to a site offering followers. If assistants or an agency help run the account, give each person separate access and remove it when they leave; our account access checklist sets out how. The phone number behind your codes is the next weak point, which our SIM swap guide covers.
Limitations of this checklist
The steps follow X's help pages and the government guidance linked above as they read on 1 October 2026. X renames menus and changes its forms regularly, and some options differ between the website and the apps. Getting the account back depends on X confirming you are the owner, so no checklist can promise recovery. This page covers X itself, not a forensic review of your devices; if you suspect malware, financial fraud or extortion, contact your bank, a qualified IT security professional or the police.