How to secure Discord after being hacked
If your Discord account has been compromised, the first priority is to stop the attacker from staying connected.
This guide explains how to regain control, remove unauthorized access, and lock down Discord, email, and connected apps before the damage spreads.
Discord account takeovers often involve stolen passwords, session hijacking, malicious OAuth authorizations, or a compromised email account.
The faster you act, the better your chances of preserving server access, private messages, and account integrity.
Confirm the scope of the compromise
Before changing settings, determine what the attacker changed.
Check whether messages were sent from your account, usernames or avatars were altered, servers were joined or left, and whether your email or password was modified.
- Review direct messages for unusual links or scams.
- Look at your server list for unfamiliar communities.
- Check account settings for new email addresses, phone numbers, or connected apps.
- Ask trusted friends or moderators whether they saw suspicious activity from your profile.
If you still have access to the account, act immediately.
If you are locked out, start with password recovery and email account security first.
Change your Discord password immediately
Your first defense is a new, unique password.
Use a password that has never been reused on another site, because credential-stuffing attacks often succeed when people recycle logins across services.
- Open Discord and go to User Settings.
- Select Password and update it right away.
- Choose a long password from a trusted password manager.
If you cannot log in, use Discord’s password reset flow from the sign-in screen.
Make sure the reset email goes to a mailbox you control, not one that may also be compromised.
Secure the email account tied to Discord
Discord password resets, security alerts, and login confirmations all depend on your email address.
If an attacker controls your email, they can regain access to Discord even after you change the password.
- Change the email password and make it unique.
- Enable two-factor authentication on the email account.
- Review forwarding rules, recovery emails, and login sessions.
- Remove any unknown devices or app passwords.
Popular email providers such as Gmail, Outlook, and Yahoo offer security dashboards that show recent sign-ins and connected devices.
Review those records carefully for unfamiliar locations or IP addresses.
Enable two-factor authentication on Discord
Two-factor authentication, or 2FA, adds a second verification step and significantly reduces the chance of another takeover.
Discord supports authenticator apps such as Google Authenticator, Authy, and Microsoft Authenticator.
To secure the account:
- Go to User Settings in Discord.
- Open Password and Authentication.
- Enable two-factor authentication.
- Save the backup codes in a secure offline location.
Backup codes matter because they are your fallback if you lose access to your authenticator app or device.
Store them in a password manager or print them and keep them in a safe place.
Revoke unauthorized sessions and connected apps
Hackers often stay logged in through active sessions even after a password change.
You should force Discord to log out of other devices and remove any suspicious third-party integrations.
- Use Discord’s device and session settings to log out all other sessions.
- Check Authorized Apps for unknown OAuth permissions.
- Disconnect bots or integrations you do not recognize.
- Review browser extensions that may have captured your login token.
Malicious OAuth apps can publish messages, join servers, or access profile details without needing your password again.
If anything looks suspicious, revoke it immediately.
Scan your computer and browser for malware
Some Discord compromises begin on the device itself.
Infostealers, browser-based token stealers, and keyloggers can capture passwords, QR logins, and session tokens.
Run a full security scan using reputable antivirus or endpoint protection software.
Also check:
- Installed browser extensions
- Recent downloads and startup applications
- Saved passwords in browsers
- Unknown remote access tools such as AnyDesk or TeamViewer
If the compromise appears severe, consider changing critical passwords from a clean device and reinstalling the operating system after backing up essential files.
A reused or infected device can undo your recovery work.
Review server permissions and administrative roles
If you manage Discord servers, attackers may have used your account to change roles, invite malicious bots, or weaken moderation controls.
Review your server settings as soon as possible.
- Inspect role permissions for recent changes.
- Remove unauthorized administrators and moderators.
- Check audit logs for bans, webhooks, channel edits, and invite creation.
- Delete unknown webhooks and bots.
If the attacker created invite links or phishing channels, delete them and warn members not to click suspicious messages.
Server audit logs are especially useful because they reveal who changed what and when.
Report the incident to Discord support
When you need help recovering a hacked Discord account, submit a ticket to Discord Support.
Include the account email, approximate time of compromise, suspicious changes you noticed, and evidence such as screenshots or email alerts.
Useful details to provide include:
- Username and user ID
- Associated email address
- Date and time access was lost
- Unrecognized devices, messages, or server activity
- Proof of ownership if requested
Support may take time to respond, so do not wait on the ticket before securing your other accounts and devices.
Warn contacts and server members about phishing
Attackers often use hijacked Discord accounts to send scam links, fake Nitro offers, or malware downloads.
Alert your friends, teammates, and server members so they do not trust messages that came from the compromised account.
Tell them to avoid:
- Gift-card or cryptocurrency requests
- Fake game beta invites
- Requests to “verify” on external websites
- Links promising free Nitro, cosmetics, or rewards
If possible, post a short announcement in affected servers explaining that the account was compromised and that any messages sent during the breach should be treated as unsafe.
Harden your Discord security for the future
Once the immediate crisis is over, build a stronger security baseline.
Good account hygiene prevents repeat compromises and makes recovery easier if another threat appears.
- Use a password manager to generate unique passwords.
- Keep 2FA enabled on Discord and your email account.
- Avoid logging into Discord on shared or public computers.
- Never scan QR codes or open login links from DMs.
- Regularly review Authorized Apps and active sessions.
- Keep your operating system, browser, and antivirus software updated.
Also be cautious with third-party Discord tools, “free Nitro” generators, and unofficial login pages.
Social engineering remains one of the most common ways attackers trick users into giving away access.
What if the attacker changed the email and password?
If the hacker replaced your email address and password, recovery becomes more urgent but still possible.
Immediately secure the original email account, search for Discord security notices, and contact Discord Support with proof that you own the account.
You should also check whether the attacker set up mail forwarding, added recovery methods, or locked you out of your primary inbox.
If the linked email is restored first, Discord account recovery becomes much easier.
How to know the account is truly safe
A secured account should meet several conditions: you control the email, the password is unique, 2FA is enabled, unknown sessions are revoked, suspicious apps are disconnected, and your device scans clean.
After those steps, monitor the account for a few days.
Watch for new login alerts, unexpected messages, or server changes.
If anything abnormal reappears, treat it as an active compromise and repeat the recovery process from a clean device.