If your X account was compromised, speed matters: attackers often change the email, password, and recovery settings within minutes.
This guide explains how to recover hacked Twitter account access, lock out the intruder, and harden the account so it is less likely to be taken over again.
Signs Your Twitter Account Was Hacked
Before you begin recovery, confirm that the issue is truly a compromise and not a login mistake.
Common warning signs include unexpected password resets, posts or direct messages you did not send, and security alerts from X or your email provider.
- Posts, reposts, or follows you do not recognize
- Email or phone number changes in account settings
- Password reset notifications you did not request
- Messages sent to followers asking for money or links
- Login alerts from unfamiliar locations or devices
Attackers may also rename the account, disconnect connected apps, or enable a new authentication method to block access.
If you see any of these changes, move directly to recovery steps.
First Steps to Recover a Hacked Twitter Account
Start with the fastest path to regain control: reset the password, reclaim the email account tied to X, and secure any phone number used for login verification.
These steps can stop the attacker from keeping access even if the account settings were changed.
Reset the password immediately
Go to the X login page and choose the password reset option.
If the attacker has not yet replaced your recovery email, you may receive a reset link or code that lets you create a new password.
- Use a strong, unique password that has never been reused
- Do not include names, birthdays, or common phrases
- Store the new password in a trusted password manager
Secure the email account linked to X
Email compromise is one of the most common reasons social media accounts are stolen.
If the attacker has access to your inbox, they can continue resetting passwords and intercepting security notifications.
- Change the email password
- Review forwarding rules and inbox filters
- Remove unfamiliar recovery emails and devices
- Enable two-factor authentication on the email account
Check your phone number and SIM security
If your phone number is connected to the account, verify that your mobile service has not been affected by SIM swapping or number porting.
Contact your carrier if you notice unexpected service changes, calls, or text forwarding settings.
How to Use X Support to Regain Access
If password reset does not work, use X’s official account access and hacked-account support channels.
The recovery form helps X verify that you are the legitimate owner and identify unauthorized changes made by the attacker.
When submitting a support request, provide clear and accurate details.
Include your username, the approximate time the account was compromised, and the recovery email address you can still access.
- Describe exactly what changed, such as password, email, or phone number
- Note any suspicious posts, DMs, or login alerts
- Use the original account email if possible
- Check spam and junk folders for replies from X Support
If your account was used for spam, scams, or impersonation, mention that in the request.
That context can help support prioritize the case and confirm that the activity was unauthorized.
How to Remove the Attacker’s Access
Once you regain entry, assume the attacker may still be connected through active sessions, third-party apps, or authentication methods.
A full cleanup is essential if you want to prevent immediate re-entry.
Log out of all devices
Use X’s security settings to end every active session except the one you are using.
This forces the intruder to sign in again and can remove access from compromised browsers and mobile devices.
Review connected apps and sessions
Check for suspicious third-party apps, automation tools, or API access you did not authorize.
Revoke anything unfamiliar, especially apps with posting, messaging, or account management permissions.
Update recovery information
Replace any email addresses, phone numbers, or backup methods that were exposed during the breach.
Make sure the recovery channels belong only to you and are protected by strong authentication.
What to Do If the Hacked Account Was Used for Scams
Many compromised accounts are used to send phishing links, crypto scams, or fake support messages.
If that happened, act quickly to limit harm and reduce the chance of account suspension.
- Delete fraudulent posts and direct messages as soon as you regain access
- Warn followers not to click links or send money
- Screenshot suspicious activity for records
- Report impersonation or scam content through X’s reporting tools
If the attacker targeted followers with fake login links or payment requests, those messages may still appear in inboxes even after recovery.
A public clarification post can help followers identify the scam and avoid further losses.
How to Protect the Account After Recovery
The best defense after an incident is a stronger security setup.
Focus on reducing password risk, protecting your email, and adding login verification that cannot be easily intercepted.
Enable two-factor authentication
Two-factor authentication adds a second login step and is one of the most effective protections against account takeover.
Use an authenticator app or hardware security key when possible, since SMS codes can be weaker if your phone number is targeted.
Use a password manager
A password manager helps generate and store unique passwords for X, email, and related accounts.
This lowers the chance that one stolen password will expose multiple services.
Monitor for repeat compromise
After recovery, keep an eye on login alerts, profile changes, and suspicious direct messages.
If the account is repeatedly targeted, review whether your email, browser extensions, or devices are infected or exposed.
Common Mistakes to Avoid During Recovery
Rushing the process can make recovery harder.
Avoid shortcuts that give attackers more time or reveal more of your information.
- Do not reuse an old password that may already be known
- Do not trust unsolicited DMs claiming to be support
- Do not ignore email security if X access is restored
- Do not leave third-party app permissions in place without review
- Do not skip checking for other compromised accounts using the same password
When the Account Cannot Be Recovered Immediately
In some cases, the attacker may have fully replaced your email, phone number, and password.
If that happens, continue using the official recovery process and secure the associated email provider, mobile carrier, and any connected devices.
You can also prepare identity details that may help verify ownership, such as the original signup email, prior usernames, recent login locations, and screenshots of the profile before the compromise.
Keep communication with support factual and concise so the case is easier to review.
Useful Security Checks After a Hack
A single compromised social account sometimes indicates a broader security problem.
Review the following areas to reduce the risk of another takeover:
- Primary email account security and recovery settings
- Other social media accounts using the same password
- Browser extensions and saved login sessions
- Mobile carrier protections against SIM swaps
- Device malware scans and operating system updates
If you treat the incident as a full security reset rather than a one-time fix, you improve your chances of keeping the account and your wider digital identity safe.