If your Instagram account was hacked and the attacker changed the email, phone number and password, you are not locked out for good. Meta runs an official, identity-based recovery process for exactly this situation, and it works in most cases where the real owner acts quickly and in the right order. What loses accounts is not the hack itself; it is the week of panic that follows it, spent on the wrong buttons and the wrong people.
This guide lays out the official path in 2026, step by step, with the evidence each stage needs and the mistakes that turn a recoverable takeover into a permanent loss.
First hour: what actually happened
A takeover almost always starts with one of three things: a phishing message that looked like it came from Instagram, a password reused from another leaked service, or a session stolen through a fake “verification” or “copyright appeal” link. Within minutes the attacker changes the email, then the phone number, then the password, and often enables two-factor authentication on their own device so the recovery codes go to them.
You do not need to know which one happened to start recovery, but you do need to know one thing: Meta notified you. Every change to email, phone or password triggers a security email to the address that was on the account before the change. That email is the fastest way back.
Step 1: find the security emails from Meta
Search the inbox that was attached to the account before the hack, including spam and promotions, for messages from Instagram or Meta with subjects like “Your Instagram email was changed” or “Your password was changed”. Each one contains a line offering to secure the account or revert the change.
Use it immediately. The link reverses the attacker’s edit and lets you set a new password. The exact validity window is not published, so treat it as hours, not days. If the link works, go straight to the “secure the account” section below; you may not need anything else.
Step 2: the official hacked-account flow
If the emails are gone, expired, or never arrived, Meta’s dedicated route is the hacked-account flow at instagram.com/hacked (and facebook.com/hacked for linked Facebook profiles). It asks for the account name, a contact you control now, and then runs an identity check. Depending on the account, the check is one of:
- A login code sent to the original email or phone, if the attacker left either one attached.
- A video selfie, compared against the photos on the account, for accounts that show a person’s face.
- Identity verification with a government ID, for business or brand accounts and for cases where the selfie route does not apply.
Do the selfie in good, even lighting with a plain background, without glasses or filters, and make sure the face matches the photos already posted on the account. Blurry or mismatched submissions are the most common reason this stage fails.
Step 3: secure the email account first
This is the step people skip, and it is why recoveries loop. If the attacker got into your Instagram through your email, or still has access to that inbox, every recovery code you request goes straight to them. Before or alongside step 2:
- Change the email account’s password to a new, unique one.
- Turn on two-factor authentication for the email itself.
- Check the email’s forwarding rules and recovery addresses; attackers add silent forwards so they keep receiving your codes after you change the password.
- Sign out all other sessions.
Only then does an Instagram recovery code have a safe place to land.
Step 4: escalate through the right channel, once
If the hacked-account flow rejects you or stalls, the next official options are:
- The Help Center contact forms for compromised accounts, with a short statement: when the takeover happened, what changed, which recovery steps you have completed, and what evidence you can provide (original email, phone, device, photos that only the owner would have).
- Support access through a paid verification subscription, if the account had one. Human agents can confirm the case is in the right queue and flag a stuck verification; they cannot override the identity check itself.
- For business accounts, the Business Help Center, especially when a Business Manager, ad account or Page is attached. The route is different and the evidence is different: business documents and admin history matter more than selfies.
Submit once per channel with complete evidence, then wait for the response. Filing the same form ten times does not create ten reviews; it creates noise.
What the attacker does while you wait, and how to limit it
A hijacked account is usually used within days: scam posts, “investment” stories, DMs to your followers asking for money, or a rename and sale. You cannot stop that from outside, but you can limit the damage:
- Post from another channel you control (a second platform, an email list, a friend’s account) telling people the account is compromised and that no message from it is you.
- Ask close contacts to report the account for being hacked through the in-app report, which adds signal to your recovery case. Do not organise mass reports; a handful of genuine reports is enough.
- Screenshot the scam content with dates. It supports both the recovery case and any later disable appeal.
If the account gets disabled during the takeover
Attackers often trigger a disable themselves: they post banned content, run scams, or change the account into something that violates policy. You may then face two problems at once. The order is fixed: recovery first, disable second. Meta needs to establish that you are the rightful owner before it reviews a disable that happened under someone else’s control. Complete the hacked-account flow, keep the confirmation, and then file the disable appeal referencing it. Our ecommerce takeover case followed exactly this sequence and was resolved in six days.
After you get it back: the security reset
Recovery without hardening is a repeat waiting to happen. In this order:
- New password, unique to Instagram, stored in a password manager.
- Two-factor authentication with an authenticator app, not SMS. Save the backup codes somewhere offline.
- Settings, Security, Login activity: log out every session you do not recognise.
- Settings, Security, Apps and websites: remove every third-party app you did not add yourself.
- Check the email addresses, phone numbers and any “backup” or connected accounts on the profile; remove anything that is not yours.
- If a Facebook profile or Business Manager is linked, repeat the checks there, including admin roles.
Mistakes that lock people out for good
- Paying a “recovery expert” who slid into your DMs. After a hack, your account’s followers, and you, are targeted by people promising recovery for a fee. It is a second scam layered on the first.
- Creating a new account with the same name right away. It can be treated as impersonating the compromised account, and it fragments your audience.
- Requesting codes before securing the email. The attacker reads them.
- Submitting a selfie that does not match the account’s photos. Different hair, heavy filters, or a face that never appeared on the account will fail the check.
- Waiting. Every day gives the attacker more time to strip the account of the details Meta uses to verify you.
Timelines, honestly
The revert link in the security email works instantly. The hacked-account flow typically resolves in hours to a few days when the identity check passes on the first try. Cases that need the contact forms or business channels take longer, often one to three weeks. In our accepted takeover cases, resolution has ranged from two days to about three weeks. No one can promise a result: the decision and the identity check belong to Meta, and any service guaranteeing recovery is not being straight with you.
When to get help
Most owners can run steps one to four alone. Help is worth it when the account is the business, when the selfie or ID check has already failed, when a Business Manager or ad account is caught up in the takeover, or when the account was disabled while hijacked. Legitimate help means diagnosis, evidence prepared for a one-pass review, filing through the official channels in the right order, and a written record of every submission. It never means hacks, insider contacts or guaranteed outcomes.
That is how we handle hacked account recovery for creators and businesses, starting with a free case review that tells you honestly whether there is a path.
Frequently asked questions
The hacker changed my email and phone. Can I still recover the account?
Usually yes. Meta keeps a record of the previous contact details and sends a security email to the old address when they change, with a link to revert the change. If that window has passed, the identity-based recovery flow at instagram.com/hacked is the next official route.
How long is the 'revert this change' link valid?
Meta's security emails have historically stayed usable for a limited period, and the exact window is not published. Treat it as hours, not days: check the old inbox, including spam, immediately.
Should I pay a recovery service that messaged me on Instagram or Telegram?
No. Unsolicited recovery offers after a hack are scams, almost without exception. Nobody legitimate sells access to someone inside Meta, and paying often leads to a second loss.
Is it safe to keep using the account after I get it back?
Only after you secure it: new unique password, two-factor authentication with an authenticator app, removal of unknown linked devices and third-party apps, and a check that the attacker did not add themselves as a backup contact or connected account.
My account was hacked and then disabled. Which appeal comes first?
Recovery first, disable second. Meta needs to establish that you are the rightful owner before it will review a disable that happened while the attacker controlled the account. Use the hacked-account flow, then the disable appeal with the recovery record attached.
Need this handled?
Hacked Account Recovery
This guide connects to our hacked account recovery service. If you would rather have the process managed for you, start with a free case review.