Your Facebook or Instagram got hacked: the recovery checklist (and how to spot the scam next time)

You can't log in, or friends are messaging to say your account is sending them strange links. Either way, someone else is in your Facebook or Instagram. Work through the steps below in order. Speed matters early: the sooner you lock the attacker out and undo their changes, the less damage they can do with your account and your contacts.

Last reviewed: 21 July 2026

First, don't panic, but move now

Losing an account feels awful, especially if it's years of photos or a page you run for work. The account usually isn't gone. Meta has an official recovery path for exactly this, and most people get back in. What you don't want to do is thrash: trying random resets from a device you're not sure is clean, or handing your details to the first "recovery expert" who DMs you (that's a second scam, aimed at people who've just been hacked).

Step 1: Use the official recovery flow

Go straight to Meta's own recovery pages. Don't search for a "Facebook support phone number": Meta doesn't offer phone support for this, and the numbers you'll find are scams.

  • Facebook: open facebook.com/hacked and follow the "My account has been compromised" flow. It walks you through securing the account and reversing changes the attacker made.
  • Instagram: on the login screen tap "Forgot password?", and if that fails use the "Get more help" or "I can't log in" option to report the account as hacked. Instagram can send a recovery link or ask you to record a short video selfie to prove it's you.

If the attacker has already changed your password, use the "no longer have access to these" options so recovery goes to a channel you still control. For a full, platform-specific walkthrough, see our step-by-step guides to recovering a hacked Facebook account and recovering a hacked Instagram account.

Step 2: Check what the attacker added, and remove it

Getting back in is only half the job. Attackers usually add their own details so they can re-take the account after you reset the password. Once you're logged in, go through your security settings and remove anything you don't recognise:

  1. Email addresses: remove any email you didn't add.
  2. Phone numbers: same.
  3. Two-factor or authenticator apps: if there's an authenticator or backup method you didn't set up, remove it.
  4. Password: change it to something new and unique (not one you use anywhere else).

Skip this and you can be locked out again within minutes.

Step 3: Log out every other session

Both platforms have a "Where you're logged in" screen (Facebook: Password and security; Instagram: Accounts Centre, then Password and security). Log out of any session or device you don't recognise. This kicks the attacker off immediately, even if they still know your old password.

Step 4: Turn on two-factor authentication

With the attacker out, turn on two-factor authentication (2FA) so a stolen password alone can't get anyone back in. An authenticator app is stronger than SMS. Save your backup codes somewhere safe and offline.

Step 5: Warn your contacts

A hijacked account is valuable because it can scam the people who trust you, and that's often the whole point. While they had access, the attacker may have DMed your friends fake "investment" tips, giveaways, or "help, I'm locked out, can you grab a code for me?" messages. Post a quick note or message close contacts: ignore anything odd from you lately, and never share a login code.

How this usually happens (so it doesn't happen again)

Almost all of these takeovers start with phishing, where you're tricked into typing your password on a fake page:

  • A DM from a hacked friend with a link ("is this you in this video?").
  • A fake "copyright violation" or "your account will be disabled" notice linking to a login page that looks like Facebook or Instagram but isn't. You log in, and you've handed over your password.
  • A fake "verify your account" or paid-blue-tick message.

The tell is almost always the same: an urgent message pushes you to log in via a link. Don't. Open the app yourself and check for notices there: real security alerts show up inside the app, not only in a link someone sent you.

Report it (Australia)

Recovering the account and reporting the crime are two different jobs, so do both.

  • Scamwatch: report the scam so it's tracked. Run by the National Anti-Scam Centre.
  • ReportCyber at cyber.gov.au: the national police-referral tool for cybercrime, run by the Australian Signals Directorate's ACSC. Use this especially if money was involved or a business account was hit.
  • IDCARE (1800 595 160): Australia and New Zealand's free identity and cyber support service, if you're worried your identity has been misused.

The short version: go to facebook.com/hacked or Instagram's "I can't log in" flow; once you're in, remove any email, phone or authenticator you didn't add; log out all sessions; turn on 2FA; and warn your contacts before the attacker scams them. It almost always starts with a phishing link, so never log in through a link someone sent you.

This is general guidance, not a guaranteed recovery; outcomes depend on your account and how far the attacker got. safe2recover doesn't take over or log in to your accounts and can't recover them for you; the official Meta process is the only path back in. If money moved, contact your bank first.