Utilities

Instagram Account Hacked? How to Recover & Secure Your Account

Instagram account hacked or compromised? Step-by-step guide to recover your account, secure it with 2FA, and report to Instagram.

CitizenNest Editorial Team7 min read
โš ๏ธ
Disclaimer: This is an independent informational guide. We are NOT affiliated with any government body. Always verify on official websites.

Instagram Account Hacked? Here's How to Recover It

Instagram hacking is alarmingly common in India. Hackers gain access through phishing links, password leaks, third-party apps, or SIM swap attacks. If your Instagram account has been hacked โ€” email changed, password changed, posts you didn't make โ€” follow this guide immediately to recover and secure it.

Signs Your Instagram Account Has Been Hacked

  • You receive an email from Instagram about an email or password change you didn't make
  • You're logged out and can't log back in
  • You see posts, stories, or DMs you didn't send
  • Your profile photo, name, or bio has been changed
  • Your friends receive suspicious messages from your account
  • You get a notification about a login from an unknown device or location

Step-by-Step Recovery

Step 1: Check Your Email Immediately

When a hacker changes your email, Instagram sends a notification to your original email:

  1. Open the email from security@mail.instagram.com (make sure it's not a phishing email โ€” check the sender carefully)
  2. If you see "Your email address was changed," click "Revert this change" or "Secure your account"
  3. This will undo the email change and let you regain access

Act fast! This reversal link expires. Check your email as soon as you notice the hack.

If you can't log in:

  1. On the Instagram login screen, tap "Forgot password?"
  2. Enter your username, email, or phone number
  3. Tap "Send Login Link"
  4. Check your email or phone for the link and use it to log in
  5. Immediately change your password after logging in

Step 3: Use Facebook/Meta Account Recovery

If your Instagram is linked to a Facebook account:

  1. Open the Instagram login page
  2. Tap "Log in with Facebook"
  3. Log into your Facebook account
  4. This may let you bypass the hacked Instagram credentials
  5. Once in, change your Instagram password immediately

Step 4: Request Support from Instagram (Identity Verification)

If all the above fail:

  1. Go to instagram.com/hacked on a browser
  2. Select "My account was hacked"
  3. Follow the prompts โ€” Instagram will ask you to verify your identity
  4. For accounts with your photos: Instagram may send a video selfie verification โ€” you'll be asked to record a short video of your face from different angles
  5. For accounts without photos: You'll need to provide the email/phone used to sign up and the device you used

Step 5: Fill the Instagram Support Request Form

  1. Go to help.instagram.com
  2. Search for "hacked account"
  3. Follow the link to the support request form
  4. Provide:
    • Your username
    • The email address originally linked to the account
    • The type of device you originally signed up on (Android/iPhone)
    • A detailed description of what happened
  5. Instagram support typically responds within 3-7 business days

How to Secure Your Account After Recovery

Enable Two-Factor Authentication (2FA)

This is the single most important step to prevent future hacks:

  1. Open Instagram โ†’ Settings โ†’ Accounts Center โ†’ Password and security
  2. Tap Two-factor authentication
  3. Choose your method:
    • Authentication app (recommended) โ€” Google Authenticator, Microsoft Authenticator
    • SMS โ€” less secure but better than nothing
  4. Follow the setup steps
  5. Save your backup codes โ€” store them securely offline

Change Your Password

  1. Go to Settings โ†’ Accounts Center โ†’ Password and security โ†’ Change password
  2. Create a strong, unique password (at least 12 characters, mix of letters, numbers, symbols)
  3. Don't reuse passwords from other accounts
  4. Consider using a password manager

Review Login Activity

  1. Go to Settings โ†’ Accounts Center โ†’ Password and security โ†’ Where you're logged in
  2. Check all active sessions
  3. Log out from any device or location you don't recognize

Revoke Third-Party App Access

  1. Go to Settings โ†’ Website permissions โ†’ Apps and websites
  2. Remove any app you don't recognize or no longer use
  3. Many hacks happen through malicious third-party apps that were given access to your account

Check and Update Your Email & Phone

  1. Go to Settings โ†’ Accounts Center โ†’ Personal details
  2. Make sure your email and phone number are correct and belong to you
  3. If the hacker changed them, update them back to yours

How to Report a Hacked Instagram Account

If someone is using your hacked account to scam others:

  1. Ask a friend to go to your hacked profile
  2. Tap the three dots (โ‹ฏ) โ†’ Report โ†’ Report Account
  3. Select "It's pretending to be someone else" โ†’ "Me"
  4. This helps Instagram prioritize the recovery

Important Tips

  • Never click suspicious links in DMs โ€” even from friends (their accounts may be hacked too)
  • Don't enter your password on any website other than instagram.com or the official app
  • Enable login alerts in Settings โ†’ Security to get notified of new logins
  • Use a unique password for Instagram โ€” don't reuse passwords from other services
  • Be wary of "Instagram support" DMs โ€” Instagram will NEVER contact you via DM

Frequently Asked Questions

Can I recover my Instagram account if the hacker changed my email and phone?

Yes. Use the video selfie verification via instagram.com/hacked or fill the support request form with your original details.

How long does Instagram take to respond to hacked account reports?

Typically 3-7 business days, but it can take up to 2-3 weeks during high volumes.

Will I lose my followers and posts if my account is recovered?

No, your followers, posts, and DMs remain intact after recovery โ€” unless the hacker deleted them.

Is SMS-based 2FA safe for Instagram?

It's better than no 2FA, but an authentication app (Google Authenticator) is more secure as it protects against SIM swap attacks.

Someone is impersonating me on Instagram. What do I do?

Report the fake account: go to their profile โ†’ three dots โ†’ Report โ†’ "It's pretending to be someone else" โ†’ "Me." Instagram usually removes impersonation accounts within a few days.

Can I recover an Instagram account I haven't used in years?

Yes, try the forgot password flow with your old email or phone number. If those no longer work, use the support request form.

My Instagram was hacked and the hacker is asking for ransom. Should I pay?

No. Never pay a hacker. Use the official recovery methods described above. Report the hacker to cybercrime.gov.in if they're threatening you.


This is an independent guide and is not affiliated with Instagram or Meta. For official support, visit help.instagram.com. Information is accurate as of March 2026.