How to Secure an X Account After Being Hacked
If your X account suddenly posts spam, follows unknown accounts, or locks you out, act quickly.
This guide explains how to secure X account after being hacked with the exact recovery, cleanup, and hardening steps that reduce damage and prevent repeat attacks.
First actions to take in the first 10 minutes
Speed matters because attackers often try to change the password, email address, phone number, and recovery settings right after gaining access.
Start by checking whether you can still sign in, then move through account recovery before the attacker can lock you out further.
- Try signing in from a trusted device and network.
- Check your email inbox for X security alerts.
- Look for posts, direct messages, or follows you did not create.
- Do not click unknown links inside the account or in messages claiming to be support.
Check whether your email account is also compromised
X account takeovers often begin with email compromise.
If the attacker controls your email, they can reset the X password repeatedly, so secure the email account first if you notice unusual sign-ins, forwarding rules, or recovery changes.
Reset your X password immediately
If you can still access the account, change the password right away from a clean device.
Use a long, unique password that has never been used on any other service, because reused passwords are a common cause of account takeover.
If you cannot sign in, use the X login recovery flow and the “Forgot password?” option.
Follow the reset link only from official X pages or messages sent to your verified email address or phone number.
- Choose a new password with at least 12 to 16 characters.
- Avoid personal details, common words, or recycled phrases.
- Store it in a password manager such as 1Password, Bitwarden, or LastPass.
Revoke suspicious sessions and connected apps
After resetting the password, remove any active sessions you do not recognize.
Attackers sometimes stay logged in on another device even after the password changes, especially if they stole a session token or signed in from a browser.
Review connected third-party apps and revoke anything unfamiliar.
OAuth app abuse is a frequent persistence method because malicious apps can retain access even when a password is changed.
- Sign out of all active sessions.
- Remove unknown connected apps and website permissions.
- Review login history for unfamiliar locations and devices.
- Disable browser extensions you do not trust if you logged in from a compromised browser.
Secure the email and phone number linked to X
X recovery depends heavily on the email address and phone number associated with the account.
If the attacker replaced either one, restore control immediately through your email provider or mobile carrier account.
At your email provider, check for mailbox rules, forwarding addresses, delegate access, and recovery method changes.
At your carrier, ask about SIM swap protection, port-out PINs, and unauthorized number transfers if you suspect a phone-based takeover.
What to verify in your email account
- Password and recovery email address
- Forwarding rules and filters
- Signed-in devices and recent login alerts
- Two-factor authentication settings
Turn on two-factor authentication for X
Two-factor authentication, or 2FA, adds a second verification step and is one of the most effective defenses against repeat compromise.
For best protection, use an authenticator app or a hardware security key rather than SMS whenever possible.
Security keys, including FIDO2-compatible keys, are especially strong because they resist phishing and credential theft.
If X offers them on your account type, they are a smart upgrade for high-risk users, brands, journalists, and creators.
- Prefer an authenticator app over text messages.
- Save backup codes in a secure offline location.
- Register a second hardware key if available.
Review what the attacker changed
Once you regain access, inspect the account for any changes that could affect your security or reputation.
Attackers may alter your display name, bio, profile photo, website link, email address, phone number, or privacy settings to impersonate you or spread scams.
Check direct messages, posts, drafts, lists, and scheduled content if available.
Delete anything malicious and warn followers if the account was used to send fraudulent links or phishing messages.
Common signs of post-breach tampering
- Unexpected crypto, giveaway, or investment posts
- New links in your bio or pinned post
- Messages sent to followers asking for money or codes
- New authorized devices or apps you do not recognize
Tell your followers and contacts
If the hacker used your account to message others, send a short warning from the recovered account or another verified channel.
This reduces the chance that friends, customers, or followers will trust scam messages that appear to come from you.
Use clear language and avoid overexplaining.
A simple notice that the account was compromised, the issue is resolved, and users should ignore suspicious links is usually enough.
Document the incident for support and future reference
Keep screenshots of suspicious logins, unauthorized posts, reset emails, and changes to account settings.
Documentation helps if you need to escalate to X support, confirm an identity issue, or report financial fraud tied to the breach.
If the account belongs to a business, record the timeline, who had access, what was changed, and what was restored.
This information is also useful for internal security reviews and incident response.
Contact X support if you cannot recover the account
If the hacker changed your email, phone number, or password and recovery is failing, submit an account access issue through X support.
Provide the original account details, the date you lost access, and any proof that you are the rightful owner.
Be patient but persistent.
In some cases, support requests are the only path back when identity data has been modified or the account is being used for spam, impersonation, or fraud.
How to keep the account secure after recovery
Recovering access is only part of the process.
To prevent another breach, strengthen the entire account ecosystem around X, including your email, password manager, devices, and connected apps.
- Use unique passwords for X and email.
- Keep your phone, browser, and operating system updated.
- Remove old devices from your account inventory.
- Avoid phishing links that mimic X login pages.
- Use a password manager to detect reused credentials.
Why X accounts get hacked in the first place
Most X account takeovers start with phishing, credential reuse, malware, or weak security on the linked email account.
Some attackers also use credential stuffing, where leaked passwords from other breaches are tested automatically on X until one works.
High-value accounts are often targeted because they can be used for scams, impersonation, affiliate fraud, or social engineering.
Understanding the attack path makes it easier to close the gap that allowed the breach in the first place.
Security habits that reduce future risk
Long-term protection depends on consistent habits rather than one-time cleanup.
Treat X like any other sensitive online identity and apply the same controls you would use for banking, work email, or cloud storage.
- Audit login alerts monthly.
- Use a dedicated email address for account recovery when appropriate.
- Enable app-based 2FA wherever possible.
- Review connected apps every few months.
- Keep backup codes separate from everyday devices.
When to escalate beyond account recovery
If the breach involved financial fraud, identity theft, extortion, or threats, take the issue beyond platform recovery.
Contact your bank, credit card provider, and local authorities if payments, personal data, or impersonation have been involved.
For brands and organizations, loop in IT, legal, and communications teams quickly.
A compromised social account can become a reputational incident within minutes, especially if followers receive malicious links or fake support messages.