INSTAGRAM · BRANDS · CREATORS · META
How to check a hacked Instagram account: the Meta security assessment guide
An Instagram account takeover involves more than lost photos. For a brand, business or creator, unauthorised access can expose private messages, spread scams to followers and harm reputation. Advertising budgets may also be affected depending on linked accounts and permissions in Meta Business Suite.
Here is how to perform an Instagram account assessment and organise your response. If unauthorised actions are visible, secure access without waiting to finish the guide.
1. Warning signs of an Instagram intrusion
An unrecognised sign-in
An unexpected alert warrants checking in the app opened directly. Location may be approximate, particularly with a VPN or mobile network. A password reset request or a single sign-out does not alone prove hacking.
Unauthorised profile changes
Your biography, photo, name or external link changed without your approval. Check with authorised account managers to distinguish a team action from an intrusion.
Suspicious posts or DMs
Followers report fake giveaways, crypto investments or requests for money sent from your profile. Preserve useful evidence and alert account owners promptly.
Changed access or recovery details
Your password no longer works, or recovery details changed without your involvement. Use official recovery, without giving codes to anyone offering to “recover” the account through direct messages.
2. Assess the account without exposing access
Never share your password, a 2FA code or a backup code with a third-party assessment tool. Perform checks in official interfaces opened directly.
Review sign-ins
From a trusted device, open Accounts Centre, then Password and security and the section showing where you are logged in. Select the correct Instagram profile. Compare devices, dates and activity; log out of sessions you do not recognise. Labels may vary by app version.
Check recent emails
In security settings, review recent emails sent by Instagram: the history covers the last 14 days. A missing notification needs checking; an older message may simply be outside that period. The displayed sender name alone does not authenticate a message.
Review recovery and linked access
Review email, phone, 2FA methods and linked accounts. Also examine authorised apps and remove unfamiliar access. Secure the recovery email account. For a business profile, have an administrator review people, partners and permissions on Meta Business assets.
3. Secure an account you can still access
Change the password and log out of unfamiliar sessions
From the official app or website on a trusted device, choose a long, unique password stored in a password manager. Change it elsewhere if reused. Log out of unrecognised devices and review sign-ins again. Do not assume all linked access or app permissions have disappeared.
Restore contact details and strengthen 2FA
Correct altered details and methods added without approval. Enable an authenticator app rather than relying only on SMS. Keep backup codes away from a compromised device and replace them if potentially exposed. An authenticator reduces dependence on the mobile number but does not make phishing impossible.
Contain the impact on your brand
Alert your communications team and IT support. Preserve useful screenshots and times, report fraudulent content and warn followers through a trusted channel if needed. Depending on linked accounts and affected permissions, have campaigns, spending and advertising administrators reviewed; report unauthorised activity to the relevant service.
4. Locked out: use official recovery
Open instagram.com/hacked directly or the Instagram app’s login help. Follow the flow matching your situation; Meta may request identity verification. Do not pay a supposed account recovery specialist who approaches you in DMs.
If your email was changed, Meta states that a message from security@mail.instagram.com may offer to reverse the change. Verify authenticity before using its link; if uncertain, go directly to official recovery. The displayed address alone does not guarantee authenticity.
Break the attack chain through prevention
Fake copyright, verification or partnership messages can be used as bait. Checking a suspicious Instagram account, limiting team access and reviewing authorised apps complement device and recovery email security. Monitor the account after an incident: no checklist alone guarantees that all unauthorised access is removed.
Deploy SecurCheck Business to support your teams every day