Hacked or taken-over account

Two-factor authentication changed by a hacker: getting past the code you no longer receive

Said Media Agency guide cover: 2FA changed by a hacker

The login screen asks for a six-digit code. The code goes to a phone or an app you do not have, because the person who took your account enabled two-factor authentication on their own device. Every recovery article says “use your backup codes”, and the backup codes were regenerated when they did it. This is the point where most people conclude the account is gone.

It is not. Two-factor is a lock on the door; the identity routes go through the wall.

What the attacker did, and why it looks final

After a takeover, attackers change the email, the phone and the password, and then enable two-factor authentication on their own authenticator app or number. Their reason is the same as yours would be: to stop the other person getting back in. From the outside it looks like the platform is now protecting the thief. In practice, Meta’s recovery flows are built for exactly this, because it is the standard endgame of every takeover.

Three things to try in the first ten minutes

  1. Backup codes. If you saved them when you set up two-factor, try them. They may have been invalidated, but a working code ends the problem instantly.
  2. A device that is still logged in. A tablet, an old phone, a browser session. If any device still has the account open, go to Settings, Security, and change the password and two-factor from there before the attacker’s session logs it out.
  3. The security email. When two-factor and contact details change, Meta sends a notice to the previous email with a link to secure the account or revert the change. Check that inbox, including spam, immediately. Those links do not stay valid long.

If none of these works, the code route is closed and the identity route opens.

The identity route

Go to instagram.com/hacked from the app or a browser on a device and network you normally use. Enter the account name and a contact you control now. The flow then verifies you without the two-factor code, through one of:

  • A login code sent to the original email or phone, if either is still attached.
  • A video selfie compared against the faces on the account, for accounts that show a person. The conditions that make it pass are in our selfie verification guide.
  • Identity document verification, for business accounts and where the selfie does not apply.

A successful identity check restores access, removes the attacker’s contact details, and disables their two-factor. You then set up your own.

Secure the email account before you start this. If the attacker also has your email, the recovery codes go to them, and the loop continues. New email password, two-factor on the email, forwarding rules checked, other sessions logged out.

If the identity route fails

Rejections at this stage are usually about the check itself: an unreadable selfie, an ID whose name does not match, a business account attempting the selfie route. Fix the specific failure and resubmit once; do not retry the same submission repeatedly. If the account was stripped of every photo before you began, state that in the submission; it routes the case to the fallback checks. Meta’s Account Recovery Hub gathers the official recovery tools in one place, and support access through paid verification can confirm the case is in a queue. The full order of channels is in our hacked account recovery guide.

What not to do

Do not pay the attacker for the code. Some send a message offering to “return” the account for a fee; paying confirms you will pay again, and the account rarely comes back. Do not pay anyone else who claims they can remove two-factor; the scripts are catalogued in our recovery scam guide. Do not create a replacement account before the recovery is decided. And do not request code after code from the login screen; each request notifies the attacker’s device and changes nothing.

Setting it up so it protects you next time

Two-factor is the setting that would have stopped the takeover, and the same setting the attacker used to lock you out. The difference is whose device it is on and whether the email behind it is secure.

  • Authenticator app, not SMS. SMS codes are intercepted by phishing kits and SIM swaps; app codes are not.
  • Backup codes generated and stored offline, in a password manager or on paper, and regenerated after any security incident.
  • A unique password for Instagram and another for the email account.
  • Trusted devices reviewed in Settings, Security, Login Activity every few months; anything unfamiliar logged out.
  • No phone number in the public bio, which is how SIM-swap targets are chosen.

When to get help

If a backup code or a logged-in device works, you do not need anyone. Help is worth it when the identity check has failed and you cannot see why, when the account is a business with ad assets attached, when the attacker stripped the photos or is actively using the account for scams, or when a disable has been added on top of the takeover. That is the work in our hacked account recovery service: the right route past the code, evidence prepared for a one-pass identity review, official channels only, and a written record. No hacks back, no insider contacts, no guaranteed outcomes, and a free case review first.

Frequently asked questions

The hacker enabled two-factor on my Instagram. How do I log in?

You cannot get the code, so the code is not the route. Use a backup code if you saved any, a device where you were still logged in, or the hacked-account flow at instagram.com/hacked, which verifies identity through your original contact details, a video selfie or an ID instead of the code.

Do I still have backup codes if the hacker changed 2FA?

Usually not. Enabling new two-factor typically regenerates codes. Codes you saved before the takeover may no longer work, but it costs nothing to try them first.

Can Instagram turn off two-factor for me?

Not on request. Meta disables the attacker's two-factor as part of a successful identity-based recovery, which is why the hacked-account flow, not support chat, is the route.

How do I stop this happening again?

Two-factor through an authenticator app on your own device, backup codes stored offline, a unique password, and a secured email account. Attackers change 2FA after getting in; the setting that matters is the one that keeps them out.

Get your case reviewed. It is free.

Send us what happened and hear back within 5 business days. If the ban looks deserved, we decline and say why. If there is a real path through Meta’s official channels, we map it for you.

Cannot wait 5 days? Priority chat, first reply within 6 hours, US$2.99

Free case review

Priority chat

Launch price, 40% off · ends 31 October

Account hacked or taken over?

Don’t wait 5 days. A case specialist replies within 6 hours.

Free case reviewReply within 5 business days
Priority chat, US$5 US$2.99First reply within 6 hours, then a one-hour live text chat
Get priority chat, US$2.99What the chat covers

Not started within 24 hours? Full refund. We never ask for passwords or login codes.