Confirm the signs and preserve useful information
An unfamiliar login, changed recovery address, messages you did not send or loss of access are serious signs. Note the times, devices, alert emails and visible actions without repeatedly attempting to sign in.
Work from an updated device you consider trustworthy. If you suspect malware, install updates and run the available security checks before entering a new password.
Secure email before starting official recovery
Your email inbox can usually reset other accounts. Review its password, forwarding rules, recovery details and active sessions. Remove any rule or address you do not recognise.
Then open the social network’s app or type its address yourself. Find the help route for hacked accounts. Do not buy recovery help from a stranger, and never share a code received by text message or authenticator app.
Remove persistent access
After regaining control, create a unique password and enable two-step verification. Sign out every device or session, then reconnect only the ones you control. Review authorised apps, administrators and recovery details.
Change the password on every other service where the old one was reused. Review posts, messages, follows and settings changed during the compromise.
Limit the impact and organise follow-up
Warn contacts through a trusted channel so they ignore recent links, requests for money or codes. For an organisation account, inform the team and remove obsolete access. Contact your bank promptly if financial details may have been exposed.
Keep evidence and support replies. Depending on the harm, use the reporting and law-enforcement routes available in your country. Recovery can take time; create a replacement account only after documenting the old one and clearly warning your community.
Put this guide into practice
Record the last safe login, changes observed and recovery channels still available. Use the official procedure from a trusted device; someone promising paid recovery may not have legitimate access.
How to assess the result
Recovery also restores expected contact details, sessions and administrative roles.
Editorial exercise; adapt it to your situation and keep sensitive details out of your notes.
Checklist
- I am using a trusted, updated device.
- The linked email and forwarding rules are secure.
- All unfamiliar sessions and connected apps are removed.
- My contacts know to ignore suspicious recent messages.
Frequently asked questions
Should I pay someone to recover the account?
No. Use the provider’s official support route. People promising guaranteed recovery for payment may be trying to scam you again.
Is changing the password enough?
Not always. Also close sessions, check email, authorised apps and recovery details, and enable a second login step.
What if I cannot recover the account?
Continue the case with official support, keep reference numbers and warn contacts. If you create a replacement account, say clearly that the old one is compromised without publishing sensitive details.
Sources & method
The sequence follows guidance from the NCSC, FTC and Cybermalveillance.gouv.fr. Screens and proof requirements differ by provider.
- NCSC — Recovering a hacked account ↗
- FTC — Recover your hacked email or social media account ↗
- Cybermalveillance.gouv.fr — Compromised social account response ↗
Editorial responsibility: Alexis RZG, WORLD SOCIAL NETWORKS. Suggest a correction.
Related methods
A question before putting this into practice
How should I organise recovery if I do not know what changed?
List email access, unfamiliar sessions, recovery contact details and unusual posts. Use official procedures and record completed steps. Once access returns, check permissions and devices; being able to log in does not prove every third-party access has been removed.
