Your Facebook or Instagram Was Hacked. Here’s How to Get It Back.
You went to log in and your password didn’t work. Or a friend messaged you asking why you’re suddenly selling crypto in your Stories. Or you got an email from Facebook saying the address on your account was just changed, and it wasn’t you who changed it.
Whatever tipped you off, someone else is in your account now. And the first thing most guides tell you is to “report it to the platform,” as if there’s a person on the other end waiting to help. There usually isn’t. The recovery forms are automated, slow, and built to stop the attacker from using them against you, which means they’re not always fast for you either.
I spent 20 years building identity protection products, and I’ve watched the account-takeover recovery process from the inside. Account takeover just means someone else has gained control of an account that belongs to you. Here’s the honest version. Whether your Facebook account was hacked or your Instagram account was hacked, the recovery follows the same logic, and what you do first depends entirely on how far the takeover has gone. So that’s where we start.
First: Figure Out How Far You’ve Been Locked Out
Account takeovers come in stages. The further the attacker got, the harder recovery is. Before you do anything else, find out which stage you’re in, because it changes your whole approach.
Stage one: you still have access somewhere. You’re logged out on your phone, but still logged in on your laptop, or in the Facebook app on a tablet you forgot about. This is the best case. You can act from inside the account.
Stage two: you’re locked out, but the email and phone on the account are still yours. Your password was changed, but the attacker didn’t change your recovery email or phone number. The platform can still reach you to verify it’s really you.
Stage three: the attacker changed your email and phone. This is the hard case. The recovery paths that rely on emailing or texting you now go to the attacker. You’ll need the identity-verification fallback, which is slower and less certain.
Check your email first, both inbox and spam. Facebook and Instagram send a notice every time the email, phone, or password changes, and that notice usually includes a “if this wasn’t you, reverse it” link that’s valid for a short window. If you catch it in time, that single link can undo the whole thing. Look for it before you do anything else.
If You Still Have Access: Move Fast
If you’re logged in anywhere, you have a narrow window before the attacker locks you out completely. Do these in order, quickly.
Change your password first. Use something you’ve never used before, not a variation of the old one. If the old password leaked in a data breach, and that’s the most common way these accounts get taken, a variation won’t help.
Then end every other session. Both platforms let you see everywhere your account is currently logged in and kick out all other devices at once. On Facebook it’s under Settings, Password and Security, Where You’re Logged In. On Instagram it’s Settings, Accounts Center, Password and Security, Where You’re Logged In. Log out of everything except the device you’re on. That drops the attacker immediately.
Now check what they changed while they were in. Look at your recovery email, your phone number, and your two-factor settings. Attackers often add their own email or turn on two-factor with their own phone so they can lock you back out later. Remove anything you don’t recognize.
Only after you’ve done all three are you actually back in control. Skipping the “log out other devices” step is the most common mistake, because people change the password and stop, and the attacker is still sitting in an active session.
The Facebook Recovery Path When You’re Locked Out
If you can’t get in at all, Facebook has a specific recovery flow. It’s not obvious, and the wording changes, but the path is real.
Start at facebook.com/login/identify. This is the account-recovery entry point, separate from the normal login screen. Enter the email, phone number, or username tied to your account. If your email and phone are still yours, Facebook will offer to send a code. Enter it, set a new password, and you’re most of the way back.
If the attacker changed your email and phone, that code goes to them, not you. When that happens, look for the option that says something like “No longer have access to these?” It routes you to identity verification, where Facebook asks you to confirm who you are. Depending on the account, that can mean uploading a photo of a government ID. Facebook says it deletes the ID after verification. This is the slow path, and response times vary from hours to over a week.
For accounts that had a real hold taken over, Facebook also runs a dedicated flow at facebook.com/hacked. Use it if the standard recovery says your account looks compromised. It walks you through securing the account and, in some cases, reversing changes the attacker made.
One honest caveat about two-factor.
If the attacker enabled two-factor with their own phone, recovery gets meaningfully harder, and the ID-verification route may be your only way through. That’s not a failure on your part. It’s the security system doing its job, just aimed the wrong way for the moment.
The Instagram Recovery Path When You’re Locked Out
Instagram’s flow is similar in shape but lives in different places, and Meta has actually improved it in the last couple of years.
On the login screen, tap Forgot password, then Get help logging in (iPhone) or Forgot password (Android). Enter your username, email, or phone. If your contact info is intact, you’ll get a reset link.
If you’re fully locked out, the better entry point is instagram.com/hacked. This is Instagram’s dedicated compromised-account flow. It checks whether your account shows signs of being hacked and, if it does, tries to guide you back in. It can also send a verification code to a device you previously used the app on, which is why keeping the app installed on an old phone occasionally saves people.
Instagram now also offers video selfie verification for accounts with photos of you. You record a short video turning your head, and Meta matches it against the photos on the account. It’s not perfect, and it doesn’t work for accounts without a face in them, like a business or meme page, but when it works it’s faster than the ID route.
If your account had two-factor turned on and the attacker didn’t disable it, that actually helps you here. Your authenticator app or backup codes still work even if your password was changed, as long as the attacker didn’t move two-factor to their own device.
If Someone Changed Your Instagram Email
This is the moment a lot of people panic, and it’s worth handling on its own. When an attacker changes the email on your account, Instagram sends a notice to your original email saying the address was changed. That message includes a link to reverse it, usually reading “secure my account” or “revert this change.” Open your inbox, find that email, and use the link before it expires. This is the single fastest way back in, and it works precisely because Instagram sent it to the address you still control.
If that window has already closed, go to instagram.com/hacked and choose the option for not having access to the email on the account. That routes you to the code-to-a-known-device path or the video selfie verification, which don’t depend on the email the attacker just took. The changed email feels like the end of the road. It usually isn’t.
When Recovery Stalls
Here’s the part the platform help pages won’t tell you plainly. These automated systems fail regularly, and when they do, there’s no phone number to call. Meta does not offer live phone support for personal account recovery, and any “Facebook support number” you find in a search result or a comment is a scam. Calling it hands your information to another attacker.
If the standard flow keeps looping you back to a dead end, a few things genuinely help. Submit the recovery request from a device and location you’ve used before, on the same Wi-Fi network if you can. Meta’s systems weigh familiar devices heavily. Try again after 24 hours rather than resubmitting five times in an hour, which can flag the attempts as suspicious. And if you have a professional or business account, the Meta Business Help Center sometimes offers a support-chat option that personal accounts don’t.
What doesn’t help: paying a “recovery service” that DMs you offering to get your account back for a fee. Those are scams built to exploit exactly the moment you’re in right now. No legitimate service has a back door into Meta.
What the Attacker Is Doing While You Wait
This isn’t to alarm you. It’s so you know what to check and warn people about, because the account is being used while you fight to get it back.
Most social-media takeovers are financial, not personal. The attacker isn’t reading your messages for blackmail. They want to reach your contacts with something that pays. That usually means posting crypto or investment scams to your followers, messaging your friends with a fake “emergency” asking for money or gift cards, running a fake giveaway that harvests other people’s logins, or using your familiar-looking account to lend credibility to a marketplace scam.
While you’re locked out, message a few close contacts from another channel, text or a different app, and tell them your account is compromised and to ignore anything it sends. That single step prevents most of the real damage, which lands on the people who trust you, not on you.
After You’re Back In: Lock It Down So This Doesn’t Repeat
Getting back in is only half of it. If you change nothing else, the same weakness that let them in the first time is still there. Three changes matter most.
Turn on two-factor authentication, but not the SMS kind if you can avoid it. Text-message codes are better than nothing, but they can be defeated by SIM swapping, where an attacker convinces your carrier to move your number to their phone and then receives your codes. Use an authenticator app instead. It generates codes on your device, with nothing to intercept. Our guide on which kind of two-factor authentication actually protects you walks through the trade-offs. Save the backup codes both platforms give you somewhere offline.
Change the password everywhere you reused it. These accounts usually get taken not through some clever hack of Facebook, but because your password leaked in an unrelated breach and you’d used it in more than one place, or because you clicked a phishing link and typed it into a fake login page. A password manager fixes this permanently by giving every account its own long, random password you never have to remember.
Review connected apps and logged-in devices one more time. Attackers sometimes leave behind a connected third-party app that keeps its own access even after you change your password. Remove anything you don’t actively use.
If You Truly Can’t Get It Back
Sometimes recovery fails. The attacker locked it down completely, or the account had no recovery email, phone, or two-factor to begin with. It happens, and it’s worth knowing when to stop pouring hours into it.
If you’re genuinely locked out for good, do three things. Warn your contacts across other channels that the account is no longer yours and anything from it is a scam. Report the account as compromised so the platform flags it, which limits how long the attacker can use it. And if any real money moved, a fraudulent purchase, a linked payment method, a scammed friend, treat that as its own problem and contact the relevant bank or card issuer directly. If your identity itself was exposed, the FTC’s IdentityTheft.gov gives you a step-by-step recovery plan.
Then rebuild on a clean account with an authenticator app and a unique password from day one. It’s not the answer anyone wants, but a fresh account you control beats an old one an attacker does.
The Bottom Line
Which recovery path works depends entirely on how far the takeover went, so your first move is always to figure out whether you still have access somewhere and whether your email and phone are still yours. Catch the “this wasn’t me” email in time and one link can undo everything. Get fully locked out with your contact info changed, and you’re into slow identity verification, which does work but tests your patience.
The version of this that never happens is the one where you’d already turned on app-based two-factor and stopped reusing passwords. If you take one thing from a bad day, take that. And if the same break-in reached your inbox, our guide on what to do if your email account is hacked covers that side of the cleanup.
Tom Reardon spent over 20 years in product and operations at major identity protection providers. He writes at MyScamGuide.com to give consumers the honest picture the industry’s marketing never did.
Recommended resources:
- facebook.com/hacked: Facebook’s official compromised-account recovery flow
- instagram.com/hacked: Instagram’s official hacked-account recovery flow
- IdentityTheft.gov: the FTC’s official identity-theft recovery planner
- ReportFraud.ftc.gov: report an account takeover or online scam to the FTC