How to Recover a Social Media Account After a Hack
If you need to know how to recover social media account after hack, speed matters: the longer an attacker controls your profile, the more damage they can do to your messages, ads, followers, and connected services.
The recovery process is usually possible, but it works best when you act quickly, document everything, and secure every linked account at the same time.
This guide explains what to do first, how major platforms typically verify ownership, and how to reduce the chance of another breach after you get back in.
First 10 minutes: contain the damage
Before you try to change settings or contact support, limit further access.
Hackers often keep control by changing your password, email address, phone number, or recovery methods.
- Try to sign in from a trusted device and location.
- If you are still logged in on any device, change the password immediately.
- Review recent emails from the platform for alerts about login, password, or recovery changes.
- Check whether the attacker posted content, sent messages, or ran ads.
- Warn close contacts not to click suspicious links from your account.
If you can still access the account, log out of all other sessions and revoke unknown devices.
Most platforms provide a security page that lists active logins, connected apps, and app passwords.
How to recover social media account after hack using official support tools
The fastest safe path is almost always the platform’s own recovery system.
Avoid third-party “account recovery” services; many are scams or phishing attempts designed to take your information.
What recovery tools usually ask for
- Your username, email address, or phone number
- A verification code sent to a trusted device or inbox
- Previous passwords
- Identity checks such as a selfie video, government ID, or trusted contacts
- Approximate account creation details or recent activity
Many platforms use automated checks first and then escalate to manual review if the account was fully taken over.
Be precise and consistent when entering your details.
Small mismatches can delay the process.
When the attacker changed your email or phone number
If the attacker replaced your recovery email or phone number, look for a message from the platform that lets you undo the change.
Social networks such as Instagram, Facebook, TikTok, X, and Snapchat commonly send a security email with a short window to reverse unauthorized updates.
Search your inbox and spam folder for terms like “email changed,” “password reset,” “new login,” or “security alert.” If the message includes a link to secure the account, use it right away from a trusted browser.
Recovering by platform: what to expect
Every service has its own flow, but the pattern is similar: verify ownership, restore access, then secure the account.
Knowing the common steps helps you move faster.
Facebook and Instagram
Meta platforms typically direct users to their hacked account help flows.
You may be asked to confirm your identity, submit a photo or video verification, or use a trusted device where you were previously signed in.
If your profile was used for ads, check Meta Business Suite and ad account settings for unauthorized campaigns or payment methods.
X (formerly Twitter)
X account recovery often starts with password reset options and account access forms.
If the username or email was changed, you may need to submit a support request and provide details such as previous usernames, approximate signup date, and device history.
TikTok
TikTok commonly uses email or phone-based reset flows.
If you no longer control either, use the in-app feedback or hacked account support route and explain whether the account was used for impersonation, spam, or unauthorized content.
Snapchat
Snapchat recovery usually centers on password reset and verification through email or phone.
If the attacker enabled two-factor authentication on the account, support may require additional identity confirmation before restoring access.
LinkedIn may ask you to confirm identity and review sign-in alerts.
Because LinkedIn accounts are tied to professional identities, it is important to remove fraudulent posts, connection requests, and job messages quickly after recovery.
What to do if you still cannot log in
Sometimes the attacker has locked you out completely.
In that case, persistence and documentation matter more than repeated password attempts.
- Use the official “hacked account” or “can’t access account” form.
- Submit from the same name, email, and phone number you used originally.
- Attach screenshots of security alerts, password reset emails, or unauthorized activity.
- Explain exactly what changed: password, email, phone number, posts, or two-factor authentication.
- Monitor support responses and answer quickly if they request more verification.
If the platform supports trusted contacts, backup codes, or recovery codes, mention that you no longer control them.
Clear, structured facts help support teams process your case faster.
Secure the rest of your digital identity
A social media hack is often the result of a broader compromise.
If one password was reused, the attacker may have access to email, cloud storage, or payment accounts.
- Change passwords on email first, then social accounts, then banking and shopping accounts.
- Use a password manager to generate unique, long passwords.
- Enable two-factor authentication with an authenticator app or hardware security key.
- Review connected apps and remove anything you do not recognize.
- Check saved payment methods, shipping addresses, and ad accounts for fraud.
Your email account is especially important because it is usually the reset channel for every other service.
If you lose email access, recovery becomes much harder.
Signs your account was used for fraud or impersonation
After you regain access, inspect the account for hidden damage.
Hackers may not just post spam; they may use your identity to deceive friends, followers, or customers.
- Direct messages sent to ask for money or codes
- Posts promoting fake giveaways, crypto scams, or phishing pages
- Changed profile photo, bio, links, or display name
- New admins added to business pages or creator tools
- Unauthorized ad spending or billing activity
If your audience received harmful messages, post a brief warning that your account was compromised and that any recent suspicious links or requests should be ignored.
How to prevent another hack
Once you recover the account, strengthen the setup immediately.
This is the point where most people leave security unfinished and become vulnerable again.
Use stronger authentication
Turn on two-factor authentication with an authenticator app or a security key such as a YubiKey.
SMS codes are better than no protection, but they are weaker than app-based or hardware-based methods.
Audit recovery methods
Remove old phone numbers, outdated email addresses, and unfamiliar trusted devices.
Save backup codes in a secure offline location so you can recover access without relying only on your inbox or phone.
Review devices and sessions
Sign out of all sessions, then log back in only on devices you own.
Check for browser extensions, remote desktop tools, or malware that could capture passwords.
On shared or public devices, always use private sessions and avoid saving passwords.
Watch for future phishing attempts
Attackers often try again after a successful compromise.
Be suspicious of urgent messages claiming your account will be deleted, suspended, or verified through a link.
Go directly to the official app or website instead of tapping embedded links.
When to involve additional support
If the account belongs to a business, creator brand, public figure, or organization, expand your response beyond the platform.
Inform your IT team, legal contact, or communications team immediately.
If financial loss, identity theft, or extortion occurred, file a report with local law enforcement and preserve evidence such as emails, usernames, IP alerts, and screenshots.
For high-value accounts, document the timeline of the attack: when you first noticed unauthorized access, what changed, which support steps you took, and when access was restored.
That record helps with platform escalation, insurance claims, and internal incident review.
Useful recovery checklist
- Secure your email account first
- Use the platform’s official hacked-account flow
- Reverse unauthorized email or phone changes if possible
- Submit identity verification promptly and accurately
- Review sessions, devices, apps, ads, and billing
- Change reused passwords across all important accounts
- Enable two-factor authentication with an authenticator app
- Warn contacts about possible scam messages