SecurCheckCyber Centre

INSTAGRAM · BRANDS · CREATORS · META

How to check a hacked Instagram account: the Meta security assessment guide

Secur Cloud ·

An Instagram account takeover involves more than lost photos. For a brand, business or creator, unauthorised access can expose private messages, spread scams to followers and harm reputation. Advertising budgets may also be affected depending on linked accounts and permissions in Meta Business Suite.

Here is how to perform an Instagram account assessment and organise your response. If unauthorised actions are visible, secure access without waiting to finish the guide.

1. Warning signs of an Instagram intrusion

  1. An unrecognised sign-in

    An unexpected alert warrants checking in the app opened directly. Location may be approximate, particularly with a VPN or mobile network. A password reset request or a single sign-out does not alone prove hacking.

  2. Unauthorised profile changes

    Your biography, photo, name or external link changed without your approval. Check with authorised account managers to distinguish a team action from an intrusion.

  3. Suspicious posts or DMs

    Followers report fake giveaways, crypto investments or requests for money sent from your profile. Preserve useful evidence and alert account owners promptly.

  4. Changed access or recovery details

    Your password no longer works, or recovery details changed without your involvement. Use official recovery, without giving codes to anyone offering to “recover” the account through direct messages.

2. Assess the account without exposing access

Never share your password, a 2FA code or a backup code with a third-party assessment tool. Perform checks in official interfaces opened directly.

  1. Review sign-ins

    From a trusted device, open Accounts Centre, then Password and security and the section showing where you are logged in. Select the correct Instagram profile. Compare devices, dates and activity; log out of sessions you do not recognise. Labels may vary by app version.

  2. Check recent emails

    In security settings, review recent emails sent by Instagram: the history covers the last 14 days. A missing notification needs checking; an older message may simply be outside that period. The displayed sender name alone does not authenticate a message.

  3. Review recovery and linked access

    Review email, phone, 2FA methods and linked accounts. Also examine authorised apps and remove unfamiliar access. Secure the recovery email account. For a business profile, have an administrator review people, partners and permissions on Meta Business assets.

3. Secure an account you can still access

  1. Change the password and log out of unfamiliar sessions

    From the official app or website on a trusted device, choose a long, unique password stored in a password manager. Change it elsewhere if reused. Log out of unrecognised devices and review sign-ins again. Do not assume all linked access or app permissions have disappeared.

  2. Restore contact details and strengthen 2FA

    Correct altered details and methods added without approval. Enable an authenticator app rather than relying only on SMS. Keep backup codes away from a compromised device and replace them if potentially exposed. An authenticator reduces dependence on the mobile number but does not make phishing impossible.

  3. Contain the impact on your brand

    Alert your communications team and IT support. Preserve useful screenshots and times, report fraudulent content and warn followers through a trusted channel if needed. Depending on linked accounts and affected permissions, have campaigns, spending and advertising administrators reviewed; report unauthorised activity to the relevant service.

4. Locked out: use official recovery

Open instagram.com/hacked directly or the Instagram app’s login help. Follow the flow matching your situation; Meta may request identity verification. Do not pay a supposed account recovery specialist who approaches you in DMs.

If your email was changed, Meta states that a message from security@mail.instagram.com may offer to reverse the change. Verify authenticity before using its link; if uncertain, go directly to official recovery. The displayed address alone does not guarantee authenticity.

Break the attack chain through prevention

Fake copyright, verification or partnership messages can be used as bait. Checking a suspicious Instagram account, limiting team access and reviewing authorised apps complement device and recovery email security. Monitor the account after an incident: no checklist alone guarantees that all unauthorised access is removed.

Read also: has my account been hacked?

Deploy SecurCheck Business to support your teams every day

Official Instagram and Meta references