What to do first after a Twitter account hack
If your X, formerly Twitter, account has been compromised, speed matters.
The first goal is to stop the attacker from keeping access, changing recovery details, or posting harmful content.
Start by checking whether you can still log in.
If you can, immediately change your password and review all active sessions.
If you cannot, use Twitter’s account recovery flow right away and secure the email account tied to the profile.
How to secure Twitter account after being hacked
The process of how to secure Twitter account after being hacked begins with regaining control of the account, then removing unauthorized access points, and finally hardening every linked login method.
Acting in the right order reduces the chance of repeated compromise.
1. Reset your Twitter password immediately
Choose a long, unique password that has never been used on any other site.
A password manager such as 1Password, Bitwarden, or LastPass can generate and store a strong credential without reusing old ones.
- Use at least 12 to 16 characters.
- Mix uppercase and lowercase letters, numbers, and symbols.
- Avoid names, birthdays, pet names, and common phrases.
- Never recycle a password from Gmail, Facebook, Instagram, or LinkedIn.
2. Secure the email address linked to Twitter
Most account recovery systems rely on email.
If an attacker still controls your inbox, they may be able to reset your Twitter password again even after you regain access.
- Change your email password.
- Enable two-factor authentication on the email account.
- Review forwarding rules, filters, and recovery emails for unknown changes.
- Check whether the attacker added a new recovery phone number or backup email.
3. Sign out of all active sessions
Twitter lets you review active sessions and connected devices.
Signing out everywhere removes logged-in access from phones, browsers, and apps that may still be under attacker control.
After a breach, assume unknown devices may have authenticated cookies or app tokens.
Force a full sign-out, then log in again only on devices you trust.
4. Revoke suspicious third-party app access
One of the most overlooked security steps is removing app integrations you do not recognize.
Malicious or abandoned apps can keep access to your account even after a password reset.
- Open account settings and review connected apps.
- Remove anything unfamiliar or unnecessary.
- Check for automation tools, analytics dashboards, and scheduling apps you no longer use.
- If an app has broad posting or direct message permissions, revoke it unless you absolutely need it.
How to remove signs of unauthorized activity
Once access is restored, inspect the account for changes the attacker may have made.
Hackers often alter profile details to mislead followers, spread scams, or lock out the owner.
Check your profile, username, and bio
Look for changes to your display name, profile photo, bio, website link, location, and username.
Restoring these details helps protect your identity and reduces confusion for your audience.
Review tweets, DMs, and scheduled content
Delete posts, direct messages, replies, or scheduled tweets you did not create.
If the hacker sent phishing links or impersonation messages, warn your followers or contacts if appropriate.
Inspect privacy and notification settings
Attackers sometimes change settings to hide activity or intercept alerts.
Confirm that notifications, login verification prompts, and recovery settings still match your preferences.
What if you cannot log in anymore?
If the hacker changed your password, email, or phone number, use Twitter’s account access and hacked account support process.
Be prepared to verify ownership with information such as the original email address, account handle, and recent login context.
When filing a support request, keep your explanation brief and specific.
Include the approximate time the compromise began, what changes you noticed, and which recovery methods no longer work.
Document the incident
Take screenshots of suspicious emails, password reset notices, unknown posts, and altered profile details.
This evidence can help with support requests and with reporting fraud if the attacker used your account for scams.
Protect your email, phone, and device
Account security is only as strong as the weakest connected system.
If the attacker reached Twitter through your email, SIM swap, malware, or an exposed browser session, you need to fix the source too.
Scan your devices for malware
Run a reputable anti-malware scan on every device you use to access social media.
Update your operating system, browser, and security software before logging back in.
Check your phone number with your carrier
If you use SMS-based login verification, call your mobile carrier and ask whether a SIM swap or port-out request occurred.
Add a port freeze or account PIN if your carrier supports it.
Review browser security
Clear saved passwords from shared computers.
Remove suspicious browser extensions, especially those requesting social media permissions, clipboard access, or session data.
Turn on stronger Twitter security settings
After recovery, enable every security layer available.
Basic password protection is not enough for accounts with public visibility, brand value, or access to private messages.
Enable two-factor authentication
Two-factor authentication adds a second step beyond the password.
An authenticator app such as Google Authenticator, Microsoft Authenticator, or Authy is generally stronger than SMS codes because text messages can be intercepted or redirected.
- Use an authenticator app instead of SMS when possible.
- Store backup codes in a safe offline location.
- Test the login flow to make sure you can still access the account if you replace your phone.
Use login alerts and recovery options
Make sure login alerts are active so you know when a new device signs in.
Confirm your recovery email and phone number are current, secure, and controlled only by you.
How to prevent another Twitter hack
Long-term protection comes from habits, not one-time fixes.
A secure account depends on password hygiene, careful app permissions, and fast response to suspicious activity.
- Use a unique password for every important account.
- Update passwords after any known data breach involving an email address or reused credential.
- Do not click login links in unsolicited DMs or emails.
- Verify URLs carefully before entering credentials.
- Limit access to trusted devices and networks.
- Review connected apps and sessions regularly.
Watch for phishing and social engineering
Attackers often impersonate Twitter support, brand partners, or followers to trick users into sharing credentials.
Be cautious with urgent messages, prize offers, verification claims, and fake security warnings.
When to report the compromise to others
If your hacked account was used to send scams, spam, or harmful links, alert your followers, customers, or team members as soon as you can.
If the account belongs to a business or public figure, coordinate the response through official channels so the warning appears consistent and credible.
For serious incidents involving financial fraud, identity theft, or business email compromise, consider documenting the event for law enforcement, your security team, and any affected service providers.
Security checklist after account recovery
- Change your Twitter password.
- Secure the linked email account.
- Sign out of all devices and sessions.
- Remove unknown third-party apps.
- Restore profile details and delete unauthorized posts.
- Enable two-factor authentication.
- Check your phone carrier for SIM-swap risk.
- Scan devices for malware and remove suspicious extensions.
- Store backup codes safely.
- Monitor the account for new login alerts.
By following these steps in order, you can recover from a breach, reduce immediate damage, and build a more resilient account against future takeover attempts.