How to Change Recovery Phone After Account Hack
If an attacker has accessed your account, your recovery phone number can become a weak point they use to regain control.
This guide explains how to change recovery phone after account hack, verify your identity, and lock down related security settings before the attacker can do more damage.
Recovery phone numbers are used by major services such as Google, Microsoft, Apple, and social platforms for identity verification, password resets, and account recovery.
Changing that number quickly can be the difference between regaining control and losing the account again.
Why the recovery phone matters after a hack
A recovery phone is not just a contact detail.
It is often tied to SMS verification, password reset codes, two-factor authentication flows, and account restoration requests.
If a hacker has already seen your messages, ported your number, or added their own device, leaving the old recovery phone in place can expose you to repeat compromise.
In many breaches, attackers do not need your password forever.
They only need one recovery path to remain connected to the account.
That is why changing the phone number is only one part of a broader recovery process.
Before you change the recovery phone number
Take a few minutes to secure the account first if you still have access.
This reduces the chance that the attacker will reverse your changes.
- Change the account password to a strong, unique password.
- Sign out of all devices and sessions.
- Review recent login activity for unfamiliar locations or devices.
- Remove unknown recovery email addresses, devices, or trusted contacts.
- Enable app-based two-factor authentication if available.
If you no longer have access, use the provider’s account recovery process immediately.
Prepare proof of ownership such as previous passwords, device history, billing details, or backup codes.
How to change recovery phone after account hack on major platforms
The exact labels vary by provider, but the process usually appears in the Security, Account, or Personal Info settings.
Below are the common paths users follow after regaining access.
Google account
In a Google Account, open Security or Personal info, then look for Recovery phone.
Remove the compromised number and add a new number you control exclusively.
Google may require you to verify with an existing session, password, or prompt on a trusted device.
- Check Security activity and Your devices for suspicious entries.
- Update Recovery email at the same time.
- Use Google Authenticator, passkeys, or a security key when possible.
Apple ID
For an Apple ID, go to Sign-In and Security and review trusted phone numbers.
Remove the compromised number and add a new trusted number.
Apple may send verification codes to trusted devices or require you to confirm changes on an iPhone, iPad, or Mac.
- Review devices signed in with your Apple ID.
- Check for unknown family sharing or account recovery settings.
- Use a passkey or hardware security key where supported.
Microsoft account
In a Microsoft account, open Security or Your info to update the phone used for recovery and verification.
Microsoft often uses a security code sent to your existing methods before allowing changes.
If a hacker changed your info, you may need to submit an account recovery request.
- Inspect Advanced security options.
- Delete any unrecognized alias or sign-in method.
- Switch from SMS-only protection to a Microsoft Authenticator app if possible.
Social media and email accounts
Platforms such as Facebook, Instagram, X, and Yahoo usually place recovery phone settings under Account Center, Privacy and security, or Account security.
Look for the phone number connected to login approvals or account recovery, then replace it with a secure number.
For social media accounts, also review connected apps, advertising accounts, and email forwarding rules.
For email accounts, look for mailbox filters or forwarding addresses that may silently redirect messages.
How to choose a safer recovery phone number
Not every number is equally safe after a hack.
The best recovery number is one you control directly, protect with a strong carrier account password, and monitor regularly.
- Use a personal mobile number instead of a shared or work number.
- Avoid numbers that have been publicly associated with your identity.
- Ask your carrier about a port-out lock or number transfer PIN.
- Keep your phone’s SIM protected with a SIM PIN if supported.
Consider using an authenticator app or a hardware security key as your primary second factor.
A recovery phone should be a backup, not your main defense.
What if the hacker changed the recovery phone first?
If you cannot access the account because the attacker replaced the recovery phone, act quickly through the provider’s official recovery tools.
Do not search for unofficial support channels or third-party “account recovery” services, because those are often scams.
Useful steps include:
- Start recovery from a device and location you have used before.
- Use the original email, old password, or backup code if available.
- Respond to verification prompts as accurately as possible.
- Check whether the provider offers identity verification, escrowed recovery, or security alerts.
- Contact the platform’s support only through its official help center.
If the account is tied to banking, business email, or financial services, notify the provider immediately and secure linked accounts at once.
How to confirm the new number is fully updated
After you change the number, confirm that it is actually being used for recovery and not just saved as a contact field.
Different systems separate sign-in methods, trusted contacts, and recovery settings.
- Trigger a test security code if the platform allows it.
- Review all recovery methods, including email and backup codes.
- Remove old phone numbers from every connected account.
- Check whether the old number still appears in billing, profile, or marketing settings.
Also update the number in your password manager, if you store account metadata there.
Keeping recovery details synchronized helps avoid confusion later.
How to prevent another takeover
Changing the recovery phone after a hack is only effective if you also close the door behind the attacker.
Account takeover prevention depends on layered protection.
- Use unique passwords stored in a reputable password manager.
- Enable multi-factor authentication with an authenticator app or passkey.
- Keep recovery codes offline in a secure place.
- Monitor account alerts for new sign-ins, password changes, and device additions.
- Review carrier account security to reduce SIM swap risk.
For high-value accounts, such as primary email, cloud storage, and payment services, consider a hardware security key like a YubiKey.
Security keys are resistant to phishing and make it harder for attackers to reuse stolen credentials.
When to contact your mobile carrier
If the hack involved SMS interception, SIM swapping, or a suspicious number transfer, your mobile carrier should be part of the response.
Ask whether any port-out request, SIM replacement, or call forwarding change was made recently.
Request any available protections, including account PINs, port freezes, transfer locks, and fraud alerts.
These measures can stop attackers from moving your number to another device and intercepting future recovery codes.
Quick checklist after an account hack
- Change the password and sign out of all sessions.
- Update the recovery phone number in account security settings.
- Remove unknown devices, emails, and backup methods.
- Enable app-based 2FA or a passkey.
- Review carrier protections against SIM swap attacks.
- Save backup codes in a secure offline location.
When you follow these steps in order, you reduce the chance that an intruder can reuse an old phone number or another forgotten recovery path to get back in.