Skip to main content

SEO & Digital Marketing Services

Instagram Account Hacked? Here’s Exactly What To Do Right Now

Table of Contents

Finding out someone else is running your Instagram account is a specific kind of stomach-drop. Maybe a friend messaged asking why you’re suddenly promoting a crypto investment scheme, or you tried to log in and your password no longer works, or your profile photo and bio have quietly changed to something you don’t recognise. Whatever tipped you off, the next hour matters more than anything else you’ll do this week to fix it.

If you’re in the UK and believe someone has gained access to your Instagram account, follow these steps in order. This guide is designed to help you secure your account as quickly and safely as possible.It covers Instagram’s own recovery tools, who to actually contact in this country (not just generic “report it to the platform” advice), and what to do once you’re back in so it doesn’t happen again a fortnight later.

How to tell it’s a genuine hack and not something else

Before diving into recovery, it’s worth ruling out the less dramatic explanations, because they need different fixes.

A forgotten password looks identical to a hack at first glance: you type your usual password and it doesn’t work. If nothing else has changed (no strange posts, no new login location, your email address on the account is still yours), you might just need a straightforward reset rather than a hacked-account recovery flow.

A genuine takeover usually shows several of these signs together:

  • Your login email or phone number has been changed without you doing it.
  • You receive an email from Instagram or Meta about a login from a device or location you don’t recognise, often naming a specific city.
  • Direct messages have gone out to your contacts, frequently pushing an investment “opportunity” or asking friends for a verification code.
  • Your bio, name, or profile picture has been altered.
  • Posts or Stories appear that you didn’t create.
  • You’re logged out everywhere and the app won’t let you back in with the correct password.

If you can still access your account, don’t panic-close the app to “sort it later.” That active session is your biggest advantage, because it lets you lock the attacker out immediately rather than fighting your way back in through Instagram’s recovery process, which can take anywhere from a day to several weeks depending on how much of your account access the hacker has changed.

The first ten minutes: act in this order

Speed and sequence both matter here. A lot of people make the mistake of changing their Instagram password first and stopping there, not realising the attacker may still have access to the email account tied to Instagram, which lets them simply reset the password again five minutes later.

If you can still log in to Instagram:

  1. Go to Settings and privacy > Accounts Centre > Password and security, and change your password immediately. Use a password you haven’t used anywhere else, ideally generated rather than something memorable, since memorable passwords are usually guessable or reused.
  2. In the same menu, turn on two-factor authentication, and choose an authenticator app such as Google Authenticator or Authy over SMS codes if you have the choice. SMS codes can be intercepted through SIM-swap fraud, which has been a growing problem with UK mobile networks in recent years.
  3. Check Accounts Centre > Password and security > Where you’re logged in and log out of every session you don’t recognise. Do this even for sessions that look plausible but you’re not sure about.
  4. Review linked apps and websites under Apps and websites in settings, and remove anything unfamiliar. This is a common entry point: people grant access to a “free follower growth” tool or an Instagram analytics app, and that third-party app is what actually gets breached.
  5. Secure the email account linked to your Instagram profile before doing anything else with the app itself. Reset its password, add two-factor authentication if it doesn’t already have it, and check the mail forwarding settings, because attackers sometimes set up a quiet forwarding rule that copies your incoming mail to themselves.

If you’ve already been locked out entirely, skip to the recovery flow below, because you won’t be able to complete most of the steps above until you’re back in.

Getting your account back through Instagram’s official recovery tools

Instagram has a dedicated recovery pathway separate from a normal password reset, and it’s the one you want if your login details have been altered.

Step one: use the “my account was hacked” flow

On the Instagram login screen, tap Get help logging in, or go directly to instagram.com/hacked in a browser. Choose the option along the lines of “my account was hacked,” rather than the standard forgotten password route, because this triggers a different verification process designed for compromised accounts.

Enter your username, the email address, or the phone number originally associated with the account. If you’ve changed devices recently and Instagram doesn’t recognise your browser or app, it may ask for extra identity checks even at this stage.

Step two: verify through whichever contact method still belongs to you

If the attacker changed your email but left your phone number untouched, or vice versa, Instagram will usually be able to send a recovery code to whichever one is still genuinely yours. This is the fastest route back in and, in my experience helping friends through this, tends to resolve within a day or two when it works.

Step three: if both were changed, expect an identity verification request

When the hacker has changed both your email and phone number, Instagram falls back on asking you to confirm you’re the real account holder. Depending on your account, this might mean:

  • Submitting a short video selfie that Instagram checks against your existing profile photos, a method it rolled out more widely as an anti-bot and anti-hacking measure.
  • Providing a photo of a government-issued ID such as a passport or UK driving licence, alongside a handwritten code Instagram gives you to hold up in the photo, which proves the image was taken specifically for this request rather than pulled from somewhere else.

This route is slower. Realistically, budget for anywhere between a couple of days and a few weeks, and don’t be surprised if you need to submit the request more than once. Support ticket volume fluctuates, and accounts with very little history (few posts, no clear prior profile photo) sometimes take longer because there’s less for Instagram’s systems to match against.

If the form-based recovery doesn’t work

If you’ve been through the hacked-account flow properly and haven’t heard back after a reasonable wait, Instagram’s Support Requests inbox (accessible from within the app, or via the Help Centre) is the next stop. It’s also worth trying the Meta Account Recovery & Support Hub at meta.com/account-recovery-support, which consolidates recovery tools across Facebook, Instagram, and Threads and includes an in-app assistant that can walk you through account-specific troubleshooting.

Be honest with yourself about what “hasn’t worked” actually means here. Submitting the form once and getting no reply within 24 hours isn’t a dead end, it’s just how the queue works. Persistence, not creativity, is usually what gets these resolved.

Should you pay for Meta Verified to speed things up?

This comes up a lot, so it’s worth addressing directly. Meta Verified is a paid subscription that includes proactive account protection and access to a human support channel, rather than the automated forms everyone else uses. Pricing in the UK has moved around since it launched here in 2023 at £9.99 a month, and currently sits somewhere in the £10 to £15 range per month depending on whether you sign up via the web or the app, so it’s worth checking the current price on Meta’s site before assuming a figure.

If you’re already locked out of your account, you obviously can’t subscribe to Meta Verified on the compromised profile itself. What some people do instead is contact Meta Verified support from a different, connected account in the same Accounts Centre, in the hope of reaching a human who can help escalate the hacked account. This works for some people and not others, and it’s genuinely a gamble rather than a guaranteed fix, so I wouldn’t recommend paying purely as a recovery tactic. It’s more sensible as an ongoing safeguard for a business account you rely on for income, where faster support access has clear future value beyond this one incident.

Reporting the hack properly in the UK

This is the part a lot of generic advice skips, or gets vague about, and it matters more than people assume, especially if money changed hands or your identity documents were exposed during recovery.

Report it to Action Fraud. If you’re in England, Wales, or Northern Ireland, Action Fraud is the national reporting centre for cybercrime and fraud, run in partnership with the City of London Police. You can report online at actionfraud.police.uk or call 0300 123 2040. This isn’t just box-ticking: Action Fraud data showed 35,434 reports of social media and email account hacking in 2024, up from 22,530 the year before, with victims losing close to £1 million between them. Reporting contributes to that picture and can support wider investigations even when your individual case doesn’t get a follow-up call. If you’re in Scotland, report instead to Police Scotland by calling 101.

Forward phishing emails. If you can trace the hack back to a phishing email, forward it to report@phishing.gov.uk, a service run by the National Cyber Security Centre (NCSC). If you received a scam text message, forward it to 7726, which routes it to your mobile network for analysis.

Contact your bank if payment details are involved. If your Instagram account has a linked shop, ad account, or saved card details, or if the hacker used your account to run a scam that led anyone to send money, get in touch with your bank promptly. UK banks have dedicated fraud teams and, depending on the circumstances, some losses may be covered under the Contingent Reimbursement Model (CRM) code for authorised push payment fraud, though eligibility depends heavily on the specifics.

Consider whether the ICO is relevant. If personal data connected to your business or a large following was exposed as part of the breach, and you’re operating in any kind of professional or commercial capacity, it’s worth reading the Information Commissioner’s Office guidance on personal data breaches at ico.org.uk. This is more relevant for business accounts than personal ones, but worth a quick check if you run a shop or manage other people’s data through the account.

Once you’re back in: locking the account down properly

Getting your account back is only the first step. A surprising number of people regain their account, breathe a sigh of relief, and get hacked again within a month because they never closed the actual gap the attacker used.

Go back through the five steps under “the first ten minutes” above if you skipped any of them while locked out. Beyond that:

  • Check your linked accounts. If Instagram is connected to Facebook, WhatsApp, or a Meta Business Suite account, check each one individually. A hacker who got into Instagram via a shared login sometimes has access to more than just the one app.
  • Review your recovery contact details. Confirm the email and phone number on file are correct and belong to you, not a lingering entry the attacker added.
  • Look at your Story archive and post history. Attackers occasionally post content and then delete it quickly, but it can still show up briefly in your archive. Worth a scan so you know exactly what your followers may have seen.
  • Check any linked ad accounts. If you or your business ever ran Instagram ads, check Meta Ads Manager for unfamiliar campaigns. This is a common way hackers monetise a stolen account quietly, running ads billed to a saved card while the owner is still trying to log back in.

Cleaning up the damage and telling your followers

Once you’ve secured things, post a short Story or feed post letting people know the account was compromised and giving a rough window of when. It doesn’t need to be dramatic. My account was hacked sometime between [date] and [date]. If you got any messages from me during that time asking for money, codes, or crypto investments, please ignore and report them, that wasn’t me.”

If the attacker DMed people asking for a verification code or money, some of your contacts may have already acted on it. A heads-up gives them the chance to check their own accounts and reverse any transactions while there’s still time.

How these hacks usually happen, so you can avoid a repeat

Understanding the entry point matters, because “change your password” alone doesn’t fix the underlying weakness if the real problem was somewhere else.

Phishing links disguised as Instagram notifications are probably the most common route. These often arrive by email or DM, claiming a copyright violation, a failed login attempt, or an account review, and link to a fake login page that captures your password the moment you type it in.

Verification code sharing is the mechanism behind a lot of “my friend’s account hacked me” stories. Someone impersonating a friend messages you asking for a code that was “accidentally” sent to your number, when in reality that code is Instagram’s own two-factor code for your account, and sharing it hands over access directly.

Third-party apps promising followers, likes, or analytics frequently request account permissions that go far beyond what they need, and a fair number are poorly secured or outright malicious.

Reused passwords from other, less secure sites are a quieter but very common cause. If a smaller website you signed up for years ago gets breached and your password leaks, and you used that same password for Instagram, you’re exposed even though Instagram itself was never touched.

What if Instagram won’t give the account back at all

For a small number of people, especially those with limited account history or accounts created a long time ago with an email that no longer exists, official recovery genuinely stalls. If you’ve submitted the hacked-account form multiple times, tried the Support Requests inbox, and attempted the Account Recovery Hub without success over several weeks, a few realistic options remain.

You can keep resubmitting the recovery request periodically, since queue processing and priority can shift over time. If the account is tied to a registered business, escalating through Meta Business Help Centre sometimes moves faster than the personal account route. Be very wary of anyone in your DMs or on freelance marketplaces offering guaranteed recovery for a fee, particularly upfront payment. Legitimate help looks like advisory support walking you through Meta’s own tools, not a stranger claiming they can “unlock” your account through some backdoor, since no such backdoor exists and this is a common secondary scam targeting people who are already stressed and vulnerable.

The one thing to do today, even if you haven’t been hacked

If you’re reading this because your account is currently compromised, the practical next step is simple: secure your email first, then start Instagram’s hacked-account flow, then report to Action Fraud once you’re moving through recovery. Don’t wait for the recovery process to finish before reporting; the two can run in parallel.

If you’re reading this because you got nervous after seeing a friend go through it, do one thing before you close this tab: turn on two-factor authentication through an authenticator app, not SMS. It’s the single change that would have stopped most of the hacks described above, and it takes about ninety seconds to set up.