Account Security

Instagram Account Security: What to Do If You're Hacked

What to do right now if your Instagram is hacked, plus how to set up two-factor authentication and passkeys and spot scam messages.

20 min read
Instagram Account Security: What to Do If You're Hacked

Can you still log into Instagram? That answer decides what to do next: secure an account you can still reach, or use Instagram's recovery flow for one you can't.

Two-factor authentication matters on either path. Instagram calls it "the single most effective step to protect your account from hackers" (Instagram Help). This guide covers securing an accessible account, recovering a locked one, choosing a two-factor method, spotting fake security messages, and reducing the odds of a repeat.

Scams that start on social media are a large problem in their own right. US consumers reported losing $2.1 billion to scams that started on social media in 2025, an eightfold increase since 2020, according to the FTC (FTC). That figure covers reported US losses only, and most scams go unreported (FTC).

This guide is about account security, not the separate blue-check verification process. If that's what you're looking for, see our guide to Instagram verification.

Key Takeaways

  • Can you still log in? That decides your path: secure the account now, or start recovery at instagram.com/hacked.
  • Instagram says it "will never reach out to you about account security through Direct Messaging." Check Recent emails in Accounts Center instead.
  • Instagram recommends an authentication app over text messages; the FTC says app codes aren't susceptible to SIM-swap attacks the way SMS codes can be.
  • Passkeys work on Instagram for accounts that have moved to a Meta Account, a rollout Meta says will happen gradually. Meta presents them as an alternative to passwords; its pages don't call them a replacement for two-factor authentication, so our advice is to keep 2FA on.
  • Never give your login code to anyone who asks for it, or your password to an app you don't trust; Instagram's Terms ban collecting other users' credentials.

Guide Contents

First, Can You Still Log In?

Start here. Can you log in with your normal password?

Situation Next step
You can still log in Secure the account
You can still log in, but your email or phone changed without you Secure the account; step 3, confirming your phone and email, is the priority check
You can't log in Use the hacked-account flow

Among the signs of a hack, the FTC lists: "You get a notification that your email address or phone number changed. Or that your password was reset." (FTC) If either happened and you didn't make the change, treat the account as compromised.

If You Can Still Log In: Secure the Account in This Order

Instagram's hacked-account page lists these actions for an account you can still reach (Instagram Help). The order below, and the login-activity and Security Checkup steps, are our editorial sequence:

  1. Change your password. FTC guidance: "Aim for 12 to 15 characters." (FTC)
  2. Log out unknown devices. Go to Accounts Center, then Password and security, then Where you're logged in (Instagram Help). On the older Settings menu, use Login Activity and "This Wasn't Me" (same link). Instagram notes: "Not everyone will be able to access this setting in Meta Account or Accounts Center at this time." Your labels may differ during the rollout.
  3. Confirm your phone number and email still belong to you (Instagram Help).
  4. Check Accounts Center for linked accounts you don't recognize (same link). Removing any you don't recognize is our editorial suggestion, not an Instagram instruction.
  5. Remove unknown apps and websites under Settings, then Website permissions, then Apps and Websites, then Active. A removed app "can only access public information on your Instagram account" (Instagram Help).
  6. Turn on two-factor authentication. The next section covers which method to pick.
  7. Run Security Checkup at Settings, then Accounts Center, then Password and security, then Security Checkup (labels may differ under Meta Account). It covers "setting a strong password, enabling two-factor authentication and updating account recovery contact information" (Instagram Blog, 29 February 2024). An earlier 2021 post described it as also covering login activity and profile information.

None of these steps guarantees an attacker won't try again. See the Instagram hub for the wider picture of managing your account.

If You Are Locked Out: Use Instagram's Hacked-Account Flow

If you can't log in at all, start at instagram.com/hacked: "For accounts without recovery access, visit instagram.com/hacked/" (Instagram Help).

If an attacker changed your email, look for a message from security@mail.instagram.com about that change, and use the option to secure the account where it's offered (same link). Sender addresses can be faked (see how to tell a real message from a scam), so act on it only if the change it describes matches what happened.

Instagram's general order is: check your email, request a login link, request mobile support with a secure email, then verify your identity with your details or a video selfie. Instagram adds: "Some of these recovery steps may not be available to you depending on the type of account you're trying to recover, but we recommend trying them all." (same link) Meta separately says it has expanded recovery to include "an optional selfie video to further verify your identity" (Meta Newsroom, 4 December 2025).

This is the shape of the flow, not the full walkthrough. See our guide to recovering a hacked Instagram account for the screen-by-screen version.

The UK's National Cyber Security Centre also recommends telling your contacts what happened and checking your bank statements (UK NCSC).

Two-Factor Authentication: Which Method to Choose

Method How it works Note
Authentication app (recommended) "Download an authentication app, such as Duo Mobile or Google Authenticator to get login codes." Instagram's recommended method
Text message "We'll send a login code to your mobile number." FTC: app codes are safer against SIM-swap attacks
WhatsApp "Turn on the text message security method first. Then, you can turn on the WhatsApp security method to get login codes from WhatsApp." Requires text message to be on first

Source: Instagram Help, retrieved September 2026; FTC note from the FTC link below.

An app is the stronger pick: "using an app is safer because the passcode isn't susceptible to a SIM card swap attack or to someone hacking your email" (FTC). CISA adds: "any MFA is better than no MFA" (CISA).

Trusted devices and backup codes

Trusted devices skip the code prompt: "you won't have to enter a security code when you log in again," though Instagram advises against marking public devices as trusted. Once 2FA is on, "you'll be able to see login requests and remove trusted devices." (Instagram Help)

Backup codes cover one case: "If you lose access to your phone or email address and are unable to get login codes, you can use a backup code to log in." (Instagram Help) Find them at Accounts Center, then Password and security, then Two-factor authentication, then your account, then Additional methods, then Backup codes. You "must be logged into your Instagram to access the list of backup codes," so generate and save them before you need them, not after. Storing a copy offline is a sensible precaution; that's our own editorial judgment, not an Instagram rule.

What outside studies show

Two studies outside Instagram show why a second factor helps, without measuring Instagram accounts. Microsoft's 2023 study of Azure Active Directory work accounts found MFA "reduces the risk of compromise by 99.22% across the entire population" and "by 98.56% in cases of leaked credentials." It also found that "dedicated MFA applications, such as Microsoft Authenticator, outperform SMS-based authentication" (Microsoft Research). Google's 2019 study looked at Google Accounts facing Google-triggered challenges. It found an "SMS code sent to a recovery phone number helped block 100% of automated bots, 96% of bulk phishing attacks, and 76% of targeted attacks" (Google Security Blog). In the same study, on-device prompts helped block 100% of automated bots, 99% of bulk phishing attacks, and 90% of targeted attacks. Neither study measured Instagram accounts.

A real incident: the 2026 support-tool takeovers

A real example (reported, based on Meta's filing): a bug in the password-reset workflow behind Meta's AI-assisted support tool let attackers take over 20,225 Instagram accounts. Meta says the tool itself worked as intended and the bug was in a separate code path. According to the filing, as reported by Gizmodo, the breach began on 17 April 2026 and was discovered on 31 May. Meta's explanation: "the system did not properly verify that the email address provided by the individual requesting a password reset matched the email address associated with that user's Instagram account" (Help Net Security). Gizmodo observed that the attack "only appears to have worked on accounts that did not have two-factor authentication enabled" (Gizmodo). Help Net Security reports that Meta "disabled the affected AI-assisted support tool and invalidated password reset links generated through the vulnerable workflow" (Help Net Security).

Passkeys on Instagram: What Changed in 2026

Meta extended passkeys to Instagram in April 2026: "With your Meta Account, passkeys will now work on Instagram, in addition to Facebook and Messenger, with more apps coming soon." (Meta Newsroom, 23 April 2026) Meta calls a passkey "a more secure alternative to traditional passwords," one that lets you log in "with your fingerprint, face recognition, or device password." (same link)

Passkeys arrive with a new account layer replacing Accounts Center gradually: "This rollout will happen gradually over the next year." (same link) Create one at Settings, then Meta Account Settings, then Login and security, then Passkey, then Create passkey (Meta Help Center). If your app still shows Accounts Center rather than Meta Account, this option may not appear yet (our inference from the gradual rollout). Meta caps the total at five passkeys and warns: "Do not create a passkey on a public or shared device." (same link) Passkeys don't cover WhatsApp.

Instagram came later than Facebook and Messenger. Meta's June 2025 announcement covered Facebook's mobile app, and a September 2025 update added Messenger. Neither mentioned Instagram (Meta Newsroom).

Meta describes a passkey as an alternative to a password. Neither the announcement nor the help page we cite presents it as a replacement for two-factor authentication, so our editorial advice is to keep 2FA switched on. When Meta launched passkeys on Facebook it said "You'll still be able to use other authentication methods, such as your password" (Meta Newsroom); the Instagram pages we cite don't repeat that line.

How to Tell a Real Instagram Message From a Scam

Instagram states: "Instagram will never reach out to you about account security through Direct Messaging." (Instagram Help) So treat any security DM that claims to come from Instagram as a scam.

Check email authenticity in-app rather than by sender name: "you can view official Instagram emails sent within the last 14 days from your Settings." (same link) Go to Accounts Center, then Password and security, then Recent emails, and check the Security and Other tabs. Instagram lists its sending domains as @support.facebook.com, @support.instagram.com, @facebookmail.com, @mail.instagram.com, and @global.metamail.com (same link), but addresses can be spoofed, so Recent emails is the more reliable test.

Meta's broader guidance for its apps lists similar domains and warns: "Don't trust messages demanding money, offering gifts or threatening to delete or ban your account." It adds: "Don't answer messages asking for your password, social security number, or credit card information." (Meta Help Center)

The same rule covers login codes: "Anyone who asks you for your account verification code is a scammer." (FTC)

Instagram said in February 2024 that it flags suspicious senders: "we'll show you a warning if an account we suspect to be deceptive sends you a direct message (DM)." (Instagram Blog, 29 February 2024) Our reading: that's a detection system, not a guarantee, so treat it as a strong signal rather than the only check you rely on.

Across all 2025 FTC scam reports with a loss, not only those involving Instagram, social media was the second most common way contact started (FTC Data Spotlight).

How scams with reported losses started, by first contact method, US, 2025 Horizontal bar chart of the share of all 2025 FTC scam reports with a loss, by first contact method. Website or app 31 percent, social media 28 percent, phone 11 percent, email 10 percent, text message 7 percent. These five categories do not sum to 100; other contact methods are not shown. Source: FTC Data Spotlight, April 2026, retrieved September 2026. How scam contact started (US, 2025) Share of all scam reports with a loss, by how contact started Website or app 31% Social media 28% Phone 11% Email 10% Text 7% Other contact methods are not shown, so the bars do not total 100%. Source: FTC Data Spotlight, April 2026, retrieved September 2026
Source: FTC Data Spotlight, "Reported losses to scams on social media are eight times higher than in 2020", retrieved September 2026.

Third-Party Apps That Ask for Your Instagram Login

If any third-party app or website asks for your Instagram password, Instagram's advice applies: "Never share your login information with an app you don't trust." (Instagram Help)

Instagram's Terms go further: they say users can't "solicit, collect, or use login credentials or badges of other users; or request or collect Instagram usernames, passwords, or misappropriate access tokens" (Instagram Terms, via Instagram Help). The same Terms also ban buying, selling, or transferring accounts.

Already shared access? Remove it at Settings, then Website permissions, then Apps and Websites, then Active, then Remove. A removed app "can only access public information on your Instagram account" (Instagram Help), and for a personal, private account, unused non-public access "automatically expires" after 90 days (same link). Instagram doesn't say whether removal deletes data an app already collected.

The Scale of the Problem, With Its Limits

Platform claim, no published methodology: "new account hacks decreased by more than 30% globally on Facebook and Instagram" in the past year (Meta Newsroom, 4 December 2025). Meta also says "the relative success rate of hacked account recovery has increased by more than 30% in the US and Canada" (same link). Treat both as directional claims from the platform, not independently verified rates.

Separately, Meta says that in 2025 it "removed over 159 million scam ads, 92% of which we took down before anyone reported them." It also "took down 10.9 million accounts on Facebook and Instagram, associated with criminal scam centers" (Meta Newsroom, 11 March 2026). Those accounts are scam-center accounts Meta removed, not hacked user accounts, and the figure spans both platforms.

US reported losses to scams that started on social media rose each year from 2020 through 2025, based on the FTC's chart (FTC Data Spotlight).

FTC reported social media scam losses, US, 2020 to 2025, in millions of dollars Column chart. Reported losses in millions: 2020, 261. 2021, 789. 2022, 1200. 2023, 1500. 2024, 1900. 2025, 2100. These are reported losses only, not total losses, since most scams go unreported. The FTC did not collect reports during the 2025 government shutdown, so the 2025 figure is likely understated. The 2020 through 2024 figures were read from an FTC chart rather than taken from an exact published number. Source: FTC Data Spotlight, April 2026, retrieved September 2026. Reported social media scam losses, US 2020 to 2025, in millions of dollars $261M 2020 $789M 2021 $1.2B 2022 $1.5B 2023 $1.9B 2024 $2.1B* 2025* * Reports were not collected during the 2025 government shutdown, so 2025 is likely understated. 2020-2024 figures read from an FTC chart. Reported losses only; most scams go unreported. Source: FTC Data Spotlight, April 2026, retrieved September 2026
Source: FTC Data Spotlight, "Reported losses to scams on social media are eight times higher than in 2020", retrieved September 2026. Figures for 2020-2024 read from the FTC's own chart; 2025 reporting was interrupted by a government shutdown.

In the UK, Action Fraud recorded 35,434 reports of social media and email hacking in 2024, up from 22,530 in 2023. Victims reported nearly £1 million in losses in 2024 (Action Fraud release, republished by Wired-Gov, 18 March 2025).

Action Fraud UK, social media and email hacking reports, 2023 vs 2024 Simple two-bar chart. 2023, 22,530 reports. 2024, 35,434 reports, an increase of nearly 13,000 reports year over year. Victims reported nearly one million pounds in losses in 2024. Source: Action Fraud release, cited via a Wired-Gov republication, retrieved September 2026. UK hacking reports: 2023 vs 2024 Social media and email hacking, Action Fraud 22,530 2023 35,434 2024 2024 victims reported nearly £1 million in losses Source: Action Fraud release via Wired-Gov, 18 March 2025
Source: Action Fraud release, republished by Wired-Gov, 18 March 2025.

The sources measure different things. Meta reports fewer new hacks on its platforms, while reported US losses to scams that started on social media, and UK hacking reports, rose, so no single number describes the trend.

Reporting a Hack in Saudi Arabia

The steps above come mainly from Instagram's global Help Center and US and UK government guidance. Saudi Arabia also has local resources alongside them.

Saudi Arabia's National Cybersecurity Authority runs a "Social Media Account Protection" awareness campaign with a downloadable guide on account protection and recovery (NCA). We couldn't verify the guide's specific contents, only that the campaign exists.

Unconfirmed (2020 news report): Arab News reported that Saudi Arabia's Public Security runs the Kollona Amn app for reporting cybercrimes, including hacked social media accounts (Arab News). We couldn't independently verify the app's current features from an official source.

Neither replaces Instagram's own recovery flow at instagram.com/hacked. Our editorial suggestion: use local reporting channels for harm beyond account access, such as blackmail or a financial loss.

FAQ

How do I know if my Instagram was hacked?

Watch for the FTC's signs of a hacked account: a notification that your email or phone number changed, or that your password was reset, when you didn't make that change. Losing access with your usual password is another sign. A drop in reach with no login changes is a different problem; see the shadowban guide under Related Guides.

Will Instagram DM me about my account's security?

No. Instagram's Help Center says Instagram will never reach out to you about account security through Direct Messaging. Any DM claiming to be Instagram support about a security issue isn't genuine. Check Recent emails in Accounts Center instead.

Is SMS two-factor authentication safe enough?

It's better than having no two-factor authentication at all, according to CISA guidance. Instagram recommends an authentication app over text messages, and the FTC says SMS codes can be exposed to SIM-swap attacks in a way app-based codes aren't. Use an app if your phone supports one.

What are Instagram backup codes?

Backup codes are listed in your two-factor settings and let you log in if you lose access to your phone or email and can't get login codes. Instagram requires you to be logged in to see them, so save them before you need them. Keeping an offline copy is our editorial suggestion.

Does a passkey replace my password or 2FA?

It can replace typing your password when you log in, using your fingerprint, face recognition, or device password. Meta added passkeys to Instagram through the gradual Meta Account rollout in 2026. Meta's pages don't describe passkeys as a replacement for two-factor authentication, so our advice is to keep 2FA on.

Is it safe to give my Instagram password to a third-party app?

No. Instagram's Terms of Use prohibit soliciting or collecting other users' login credentials, and Instagram's help pages say never to share login information with an app you don't trust. If you already have, remove that app's access and change your password.

Bottom Line

Whether you can log in decides your first move: secure the account if you can, or start recovery at instagram.com/hacked if you can't. Two-factor authentication, ideally through an authentication app, remains the step Instagram calls the single most effective one. Passkeys add a login option in 2026, but the Meta pages we cite don't present them as a replacement for two-factor authentication.

The clearest scam signals are simple: Instagram says it won't contact you about account security by DM, and Meta says not to answer messages asking for your password. Check Recent emails before trusting any message claiming to be from Instagram, and never give your password or a login code to anyone who asks for it, or to an app you don't trust.

Related Guides

About This Guide

This guide is maintained by the D3M Follow editorial team. Accepted sources for this page are the Instagram Help Center and Instagram Blog, Meta's Help Center and Newsroom, the US FTC, CISA, the UK's NCSC and Action Fraud, and Saudi Arabia's National Cybersecurity Authority. Non-Instagram MFA studies come from Microsoft Research and Google's Security Blog. Attributed news reports come from Gizmodo, Help Net Security, Arab News and Wired-Gov.

Menu labels quoted here, including Accounts Center and Meta Account, are changing. Meta says its rollout will happen gradually over the year following its 23 April 2026 announcement, so your app may show different labels. Last reviewed 15 September 2026.

Questions or a correction: contact us. See also our FAQ and terms.

Share this article: