Quick fix (first 15 minutes)
- Open the original email inbox and search for messages from
security@mail.instagram.comabout a changed email. If one exists and it is genuine, use its link to revert the change (see the revert trick). - Change the password of that inbox now and turn on an authenticator app, because the attacker may also be inside your email.
- On the Instagram login screen, use the account help option and request recovery with a video selfie. Do not pay anyone offering to hack it back.
What it means when the email and phone were changed
When a hacker changes both the email address and the phone number on your Instagram account, the normal "forgot password" route is dead, because every code and reset link now goes to the attacker. You need a different recovery path that does not depend on the contact details currently on the account. That is the whole reason this situation feels so much worse than a simple stolen password, and it is also why most generic advice fails you.
This guide is for one specific case: the attacker is in, the password no longer works, and the email and phone on the profile are no longer yours. You cannot receive a login code. You may not be able to open the account at all. If you still have access and just want the general checklist, read our main guide, Instagram hacked? 9 recovery steps that work, first. This article goes deeper on what to do when the attacker has already swapped your recovery details.
A note on accuracy before we start. Meta changes the Instagram interface and its recovery tools often, and the Help Center pages are rendered by script, so menu names, button labels and time windows can differ from what you see on your phone. Where this guide describes a menu or a rule that may have changed, it says so. Treat the steps as the logic of the recovery, and follow the exact wording on your own screen.
How attackers usually get to this point
Most takeovers where the contact details are swapped start in one of four ways. The first is a phishing message that looks like a copyright warning, a "verify your blue badge" notice or a login alert, which sends you to a fake sign-in page. You type your password, and sometimes a code, and the attacker uses both within seconds. The second is a reused password that leaked in an unrelated breach. The third is access to your email account, which lets the attacker request a reset and read the code. The fourth is a malicious app or browser extension that quietly captures sessions. Our guide to what phishing is and how to spot it covers the first and most common route.
Once inside, the attacker usually acts fast. They change the email, then the phone number, then the password, and often switch on their own two-factor method so you cannot get back in even if you find a reset link. Then they either sell the account, use it to message your followers with scams, or lock you out and demand payment. Speed matters because the first hours are when your options are widest.
How this page differs from our main Instagram guide
Our main guide covers the whole life cycle: spotting a hack, nine recovery steps, what hackers do, business accounts and prevention. This page focuses only on the hard case: the attacker changed your email and phone, you have no codes, and the standard reset fails. It adds the revert-email route, the video selfie flow, trusted-contact style options, the recovery-scam landscape and the Canadian reporting steps.
Your first 15 minutes: what to do right now
In the first 15 minutes, secure the email account tied to Instagram, search that inbox for an Instagram security notice, and start official recovery from the login screen. Do not pay anyone, do not click links from messages that arrived after the hack, and do not keep guessing passwords. The order matters more than speed on any single step, because a well-ordered first quarter hour often decides whether you get the account back.
First 15 minutes checklist (print or screenshot this)
- I opened my original email inbox on a device I trust and confirmed I can still sign in.
- I changed that email password to a new, unique one and signed out other sessions.
- I searched the inbox, spam and trash for "instagram", "security", and "email changed".
- I did not click any link in a message that arrived after the hack unless I can confirm the sender.
- I took screenshots of the account page, messages and anything the attacker posted.
- I wrote down the username, the original email, the original phone number and the date I last had access.
- I started recovery from the Instagram login screen, not from a link someone sent me.
- I told a friend or colleague through another channel that the account is compromised.
- I decided that I will not pay anyone who promises to get the account back.
Step 1: secure your email before Instagram
This feels backwards, but it is the most important move. Your email address is the key to your Instagram recovery, and it may also be the way the attacker got in. If the attacker has your email, any message that Instagram sends to the old address can be read and deleted by them, including the revert link we discuss below. Change the email password from a device you trust, sign out of all other sessions, and check the forwarding rules and filters. Attackers sometimes add a rule that silently forwards or deletes messages from Instagram. If you suspect the email itself is compromised, follow our guide to recovering a hacked email account before you continue.
Step 2: search your old inbox for the security message
When the email address on an Instagram account changes, Instagram has described sending a notice to the previous address. That message can contain a way to undo the change. Search for the word "Instagram", for "email address changed" and for the sender address security@mail.instagram.com. Check spam, trash and any "Promotions" or "Updates" tab, because automated security mail is often filed there. The next section explains how to use that message safely, and how to tell a real one from a fake.
Step 3: do not make the situation worse
Some actions reduce your chances. Repeatedly entering wrong passwords can trigger rate limits. Creating a new account with the same name does not help recovery. Deleting the Instagram app does not remove anything from the attacker's side. And above all, replying to people who contact you offering "help" gives scammers the opening they want. If someone you do not know messages you after a public complaint, treat them as a risk by default.
Step 4: collect the evidence
Take screenshots of the profile as it now looks, any posts or stories the attacker published, and any messages sent to your followers. Save emails about the change, including full headers if you can. This evidence supports a platform appeal, a police report, a fraud report and, for business owners, an insurance claim. It costs a few minutes and can matter for weeks.
What a realistic first hour looks like
Realistic scenario (illustrative, not a specific client). A photographer in Gatineau wakes up to a message from a friend: "Why are you asking me for 200 dollars?" She tries to sign in and the password fails. The reset code is sent to a phone number she does not recognize. In the next hour she changes her email password, finds a security message from Instagram in her spam folder dated three hours earlier, uses the link in it, and regains access before the attacker has switched on their own two-factor method. She did nothing technical. She simply searched the right inbox in the right order, which is exactly what the checklist above is designed to make automatic.
The email revert trick: undo the change from your old inbox
When an Instagram email address is changed, Instagram has described sending a security message to the old address, typically from security@mail.instagram.com, that lets the original owner reverse the change. If you find a genuine one, using it can restore the old email and may let you reset the password, but it only works for a limited time, so check right away. This is the single highest-value action in this guide, and also the one most people never try because they do not know the message exists.
What the message is, and how to find it
The idea is simple. A change to the email on your account is a sensitive event, so Instagram notifies the address that was on file before the change. The notice says that the email was changed and offers a link to revert or to secure the account. If the attacker did not delete it, it is waiting in your old inbox. Search by sender, by the words "Instagram" and "email", and by the date you were locked out. Also check the trash and any folders that filters might have created.
Gmail, Outlook, iCloud and Yahoo all let you search all mail including spam and trash. In Gmail, for example, you can use the query from:security@mail.instagram.com and widen the search to "All Mail". If the search returns nothing, the notice may have gone to a different address (a second email you once used), or the attacker may have removed it, or the account may have been set up in a way that did not trigger one.
How to tell a real message from a fake one
Phishers know that victims are hunting for this exact message, so they send fakes. Use these checks before you click anything.
- The message was in your inbox before the hack, or arrived just as the change happened. A new message that shows up hours later claiming "your account will be deleted unless you click" is a pressure tactic.
- Look at the full sender address, not only the display name. The domain should be an Instagram one, with no misspelling, extra words or odd subdomains.
- Hover over the link without clicking. On a computer, the destination shows in the corner of the browser. It should point to an Instagram or Meta address, not a shortened link.
- Never type your password into a page you reached through an email link unless you have verified the address bar. If in doubt, open the Instagram app or type the address yourself and look for the account's security notices there.
- A genuine message does not ask for money, gift cards or your ID by reply.
If you cannot verify the message with confidence, do not use the link. Go to the Instagram app, use the recovery options on the login screen, and treat the email as a lead rather than a command.
How long you have
Instagram describes the revert option as time limited. We have not been able to read a current, authoritative number from the Help Center for this article, because those pages are rendered by script and returned no text to our fetch. We therefore do not state a number of days. Assume the window is short, check the Help Center wording for the current figure, and act the same day. If your window has passed, the video selfie route below is your main alternative.
What to do after you click the revert link
- Confirm the email address on the account is your own again.
- Immediately request a password reset to that address and choose a long, unique password from a password manager.
- Remove any phone number you do not recognize, and add your own.
- Look for two-factor authentication methods you did not set up and remove them.
- Open the list of active logins and sign out every session you do not recognize. Menu names such as "Accounts Center", "Password and security" and "Where you're logged in" have appeared in Meta's interface, but the exact labels may differ on your version.
- Only then think about the aftermath: messages sent to followers, posts, ad accounts and linked apps.
If the revert link does not work
It may have expired, been used already, or been triggered by the attacker's own change in a second step. Do not keep clicking it. Move on to the video selfie route and the recovery options on the login screen, and keep the email as evidence for any appeal.
Which situation are you in? A quick comparison
Your best recovery route depends on what the attacker changed and whether you still hold your original email. The table below maps the four most common situations to the route with the best odds, so you can skip to the section that matches your case. It is a guide to priorities, not a promise, because Meta decides each case and can change its tools without notice.
| Your situation | Best first move | Backup route | Odds (rough guide) |
|---|---|---|---|
| Password changed only, you still control the original email and phone | Normal reset from the login screen, then sign out all sessions | Security notice from Instagram in your inbox | High |
| Email changed, you still control the original email | Find and use the security message from your old inbox | Video selfie recovery | Good if you act fast |
| Email and phone both changed, you control the original email | Revert message if present, then recovery from the login screen | Video selfie recovery | Moderate |
| Email and phone changed, you lost control of the original email too | Recover the email account first | Video selfie recovery with a device you previously used | Lower, depends on the email provider |
| Account disabled or suspended after the hack | Use the appeal option shown in the app | Wait for review, do not file duplicates | Variable |
| Business or creator account with a linked Facebook Page | Check page roles and the Accounts Center | Meta Business Suite support tools | Moderate to good |
The odds column is deliberately rough. Nobody outside Meta has reliable statistics on recovery rates by situation, and anyone who quotes you a precise percentage is guessing. What we do see in practice is a pattern: people who protect their email first, act within a day, use their usual device and avoid scammers recover more often than people who wait, panic or pay.
Why your usual device and network matter
Instagram's systems look at signals such as the device you normally use, the network you normally connect from, and your history of logins. Attempting recovery from your usual phone, on your home Wi-Fi, from the same app you have been using for months, gives the system a reason to trust that you are the real owner. Trying from a cafe on a borrowed laptop with a VPN switched on gives it a reason to doubt you. If you have the Instagram app still signed in on an old phone or a tablet, do not log out of it, because that session may be the easiest way back in.
Look for a session that is still alive
This is a detail that many guides skip. If you have another device where Instagram is still open, for example an old phone, a tablet or a computer browser, check it before doing anything else. Sessions sometimes survive a password change for a short time. From a surviving session you may be able to see the account's login activity, to change the password again, and to remove the attacker's email and phone from within the app. Do not sign out of that device. Do not update the app if you can avoid it until you have finished recovery, in case an update forces a new sign-in.

Video selfie verification: how it works and how to pass it
The video selfie is an identity check in which Instagram asks you to record a short video of your face, turning your head as instructed, so it can compare you with the account and decide whether you are the real owner. It is the main recovery path for people who have lost access to both their email and phone, and it is free. No one can do it for you.
When you will be offered it
Instagram does not offer the selfie in every case. It tends to appear when you choose the "need more help" style option during recovery and the system decides it has enough information to try an identity check. If your account has photos of your face, a video selfie is more likely to succeed because there is something to compare. If your account is a pet, a logo or a landscape page, the comparison is harder and other evidence matters more. Menu names change, so look for wording about confirming that you are the owner, or about getting back into your account without a code.
How to start recovery the right way
- Open the Instagram app on the phone you normally use, or the Instagram site in the browser you normally use. Do not use a link from a message you were sent.
- On the login screen, choose the option for trouble signing in or forgotten password.
- Enter your username (not an email the attacker may have set).
- When Instagram offers to send a code to a contact detail you do not recognize, look for an option like "I can't access this email or phone" or "try another way".
- Follow the prompts. Answer honestly, and use contact details you control for the reply, such as your original email, because Instagram will use them to message you about the request.
- If a video selfie is offered, take it in one calm attempt.
How to record a selfie that passes
- Light. Face a window or a lamp. Avoid strong light behind you.
- Remove obstructions. Take off glasses, hats and masks, and pull hair away from your face.
- Frame. Keep your whole face inside the guide and hold the phone steady at eye level.
- Follow the prompts. Turn your head slowly in the directions shown. Do not rush and do not use filters or beauty effects.
- Use your usual device. Record from the same phone, with the same network, that you normally use for Instagram.
- Be yourself. If your profile photos are from five years ago and you look different, that is fine, but do not try to mimic the old photo.
Privacy warning about the selfie
A video selfie is sensitive biometric data. Only submit it inside the official Instagram app or the official Instagram site reached by typing the address yourself. Anyone who asks you to record a video and send it to them in a chat, or to hold up your ID next to your face for a "verification agent" on Telegram or WhatsApp, is trying to steal your identity or to impersonate you.
After you submit it
Instagram reviews the video and replies by email, usually to the address you gave during recovery. It can take from minutes to days. While you wait, do not submit repeated requests, which may be treated as noise, and do not delete the thread of emails. If you are asked for more information, respond promptly from the same device. If the request is rejected, you can try again after a delay, and you should look at the other options below rather than repeating the same attempt over and over.
Meta Accounts Center, linked accounts and other ways back in
If your Instagram is linked to a Facebook profile or Page through Meta's Accounts Center, that link can be a second door back in, because you may be able to manage the Instagram account from Facebook, or review and remove the attacker's changes from there. Whether this works depends on how the accounts were linked, so check it while you still can. We describe the names Meta has used, but they change often, so treat them as hints.
Check Facebook and the Accounts Center
Meta groups settings for linked profiles under a hub it has called the Accounts Center. If your Facebook account is still yours and Instagram is linked there, open Facebook's settings, look for the Accounts Center, and check whether the Instagram account appears in the list. From there you may see login and security settings for the connected profile, and be able to remove the connection or review its activity. If the attacker has also taken your Facebook account, our guide to recovering a hacked Facebook account is the next stop.
The Business Suite angle
Creator and business accounts are often tied to a Facebook Page and to Meta Business Suite. If you are an admin of that Page, you may see the Instagram account in the Business Suite, and you may be able to remove the attacker's access from there. This is also where you can check who else has roles on the Page, which matters if the attacker added themselves as an admin. We return to the business case in a later section.
Trusted contacts and friends who can vouch
Some platforms let a few trusted people help you recover an account. Facebook has offered a trusted-contacts style feature in the past, and Meta may use similar ideas in different forms for different regions and account types. We could not confirm from the Help Center, for this article, whether Instagram currently offers a trusted-contacts recovery for personal accounts, so do not count on it. What does help in practice is a friend reporting the hacked account through Instagram's own report option, as a person who knows the real owner. A handful of reports from real people can add weight to an appeal, and the friends can warn others at the same time.
Other evidence you can prepare
- The original email address and phone number used when you signed up.
- Names of devices that you used with the account.
- Approximate date of your last successful login.
- Screenshots of your profile, your follower count and your pinned posts.
- Any email receipts from Instagram, such as ad purchases or verification confirmations.
- The original photos you posted, in case you are asked to prove ownership.
Not every request will ask for these things, but having them ready saves time and shows that you are the person who created and used the account.
Passwords, passkeys and where recovery fails
Recovery fails most often for four reasons. First, the request came from an unfamiliar device or network. Second, the contact details provided did not match anything on the account's history. Third, the video selfie did not match, often because of poor lighting or because the profile has no photo of the owner. Fourth, the attacker has already completed their own verification and the system now sees them as the owner. In that last case your best path is to show history: devices, dates, and consistent evidence over time. This is also why you should not delay.
Recovery scams: fake "hacker" services, Telegram agents and paid Meta insiders
Anyone who contacts you offering to recover your Instagram account for a fee is almost certainly running a scam. Genuine recovery happens through Instagram's own tools and costs nothing, so a request for cryptocurrency, gift cards, a transfer or your ID is a signal to stop. Victims of account takeovers are targeted a second time, by a different group, within hours of posting a plea for help.
How the second scam works
When people lose an account, they search for help, post in forums, comment under creators' videos and message friends. Scammers watch all of this. They reply in comments, send direct messages, run ads for "social media recovery experts" and post fake testimonials. The pitch is always the same: they know a contact inside Meta, or they have a special tool that can reverse the hack, and they can do it in hours if you pay a fee first. After you pay, one of three things happens. They vanish. They ask for a "release fee" or "insurance deposit" and keep asking. Or they ask for your login details and your ID, then use them to take over your other accounts.
| Sign | What it looks like | What to do |
|---|---|---|
| Unsolicited help | A stranger messages you minutes after you complain publicly | Ignore, block, report |
| Guaranteed result | "100% recovery in 24 hours" | No legitimate party can guarantee it |
| Payment first | Crypto, gift cards, wire or e-transfer demanded upfront | Never pay |
| Off-platform chat | "Message me on Telegram or WhatsApp" | Decline, stay on official channels |
| Meta insider claim | "I work at Meta" or "my cousin works at Instagram" | Meta does not sell account recovery through insiders |
| Request for ID or selfie | Send a photo of your driver's licence or a video | Never send to a third party |
| Fake support phone number | A number found in search results or ads | Instagram does not publish a general phone line for personal accounts |
Why Telegram shows up so often
Telegram and similar apps appeal to scammers because they make it easy to create anonymous accounts, move conversations out of view of Meta's moderation and ask for payment in crypto. This is not a statement about Telegram's legitimacy as an app. It is a reminder that a recovery pitch that begins on Instagram and then says "continue on Telegram" is following a very familiar scam script. The same applies to WhatsApp and Signal.
The "hacker for hire" trap
Some victims are tempted to hire someone to hack the account back. Apart from being illegal in many places, it leaves you in a worse position: you have handed money and personal information to a criminal who has no incentive to help. If they do manage to access something, they may keep it. Treat "ethical hacker" offers aimed at recovering social accounts with the same suspicion as the others.
If you already paid
Do not send more money, even if the person says the last step needs one more payment. Keep the receipts and chat logs. Contact your bank or card issuer quickly, and for cryptocurrency, the exchange you used, because speed can matter. Report the incident to the Canadian Anti-Fraud Centre if you are in Canada. Our guide to what to do after a tech support scam covers the money side in detail.
Contacting Meta and getting a human: what works and what does not
Meta does not offer a general support phone line or live chat for personal Instagram accounts. The realistic routes are the recovery flow on the login screen, the "report a problem" or help options in the app, and the appeal forms Meta shows after a lock or suspension. Numbers and "support agents" found online are, in most cases, scams.
The routes that actually exist
- Recovery from the login screen. The official path and the one that connects to your account history.
- Help and report options inside the app. If you still have a signed-in device, look under Settings for help, report a problem, or security checkup. Labels vary.
- The Help Center. Gives the official steps for hacked accounts and is where Meta updates its wording. It is worth reading the current "hacked account" article before you start.
- Reports from friends. Followers who report the account as hacked or as impersonating you can contribute to a review.
- Meta Verified support, where it applies. Meta has offered a paid verification subscription in some regions that includes access to account support. Availability, pricing and what it covers change, and we could not verify the current terms for this article, so check Meta's own page and treat it as an option, not a promise.
- Business tools. If you run ads, the ad account and Business Suite have their own support routes. Look in your Business Suite help area.
What not to do
- Do not file the same appeal five times in an hour.
- Do not write an angry essay. A short, factual description of what happened, when, and what evidence you have works better.
- Do not claim things you cannot prove, such as a legal threat or a contact at Meta.
- Do not accept help from accounts that "found your case" on social media.
Writing a good appeal message
If a form lets you write a message, keep it short, calm and specific: your username, the date you lost access, what the attacker changed (email, phone, password), that you did not authorize it, the email and phone that were originally on the account, and that you can provide a video selfie. Add one line stating that you have secured your email. Mention nothing that is not true. A reviewer reading hundreds of cases a day will respond better to a clear case than to a long one.
Reporting the fraud in Canada: CAFC, police and the privacy angle
If you are in Canada, report the hack to the Canadian Anti-Fraud Centre through its online reporting system, and file a police report if money, extortion, harassment or impersonation is involved. A report does not recover the account, but it creates a record, supports any later claim, and helps investigators track the groups behind these takeovers.
The Canadian Anti-Fraud Centre
The CAFC is Canada's central body for collecting information on fraud and cybercrime. Its reporting page, which we opened on October 1, 2026, points victims to the online reporting system at reportcyberandfraud.canada.ca, where you can file a report, and states that victims should also contact local police. The online system allows you to file without giving your name if you prefer. We have not listed the CAFC's phone line here, since our policy is to keep this page free of other numbers, but it is on the CAFC site if you prefer to call.
When to also go to the police
- The attacker is asking you for money to return the account or threatening to publish private images.
- The attacker used your account to ask your contacts for money.
- The account is tied to your business, your ads or your income.
- Your identity documents were involved, for example you sent your ID to a fake support agent.
If identity documents were exposed, also read our identity theft recovery guide and consider placing fraud alerts with the credit bureaus.
Privacy rights in Canada
If your personal information has been exposed because of a company's failure, such as a business account that leaked customer messages, Canadian privacy law may require the business to notify those affected in some circumstances. For a typical individual takeover through phishing, the legal angle is smaller, and the practical steps are the ones in this guide. If you are a business owner, keep a record of who was affected and consider speaking to a lawyer if customer data was involved.
Securing the account after you get it back
Getting the account back is only half the job. Within the first hour, change the password to a unique one, remove every unknown email, phone number, device and login, turn on two-factor authentication using an authenticator app or passkey rather than text messages, and review the apps connected to the account. Skip this and the same attacker, who may still hold a saved session or your old password elsewhere, can take it again.
After-recovery security checklist
- I set a new, long, unique Instagram password using a password manager.
- I confirmed the email and phone number on the account are mine and no others are listed.
- I signed out of every unknown session and device in the login activity list.
- I turned on two-factor authentication with an authenticator app, and saved the backup codes offline.
- I checked whether passkeys are offered for my account and, if so, set one up.
- I removed third-party apps and websites I do not recognize from the connected apps list.
- I reviewed linked Facebook, Threads and Business Suite connections and their roles.
- I changed the password of my email account and turned on two-step verification there.
- I checked messages sent from the account while I was locked out and told affected contacts.
- I reviewed what the attacker posted, changed or deleted, and restored what I could.
Two-factor authentication: use an app, not SMS
Text-message codes are better than nothing, but they are weak against SIM swaps and against attackers who convince a carrier to move your number. An authenticator app generates codes on your device and is much harder to intercept. Instagram has offered an authentication app option under its security settings, though the exact menu path may differ on your version. Save the backup codes in your password manager or print them. If you lose the phone later, our guide to recovering 2FA access after losing an authenticator will help, and our step-by-step two-factor authentication setup guide covers the general process.
Passkeys: check, do not assume
Passkeys replace passwords with a cryptographic key stored on your device and unlocked by your face, fingerprint or PIN. They resist phishing because they only work on the real site. Whether Instagram supports passkeys for your account today is something we could not confirm from the Help Center for this article, so check the security settings in your app. If it is not offered, use an authenticator app. Our explainer on passkeys covers how they work and where they apply.
Review logins, devices and connected apps
Look for a list of where you are logged in, usually under the security or Accounts Center settings. Sign out any device or location you do not recognize. Then review the list of apps and websites that have access. Attackers often keep access through an authorized app even after the password changes. Remove anything you did not set up yourself.
Check what the attacker did
Check sent messages, because many takeovers send investment, crypto or "vote for me" links to your followers. Check whether the profile bio, link, name or username changed. Check the ad account and payment methods if you use one. Check Highlights and stories for deleted content. Make a list and decide what to restore and what to explain publicly. A short post such as "my account was compromised, please ignore messages from last week" does more to protect your followers than silence.
Fix the root cause
Most repeat takeovers come from the same cause as the first. If you reused the password somewhere, change it everywhere, starting with email, banking and shopping. If you clicked a phishing link on your computer, scan the device and review browser extensions. If the attacker got in through your email, secure that first. A password manager makes unique passwords painless, and our password manager guide compares the options. If you suspect malware on your phone or computer, our guide on what to do if your phone is hacked shows the checks.
If you used the account for business: clients, ads and brand
If Instagram was part of your income, treat the takeover as a business incident. Tell your clients, pause advertising, check who has admin roles on the linked Facebook Page and Business Suite, and document the losses, because the attacker may have run ads on your card or sent scam messages in your name.
The first business steps
- Pause ads. If the account was linked to an ad account, check for new campaigns and unknown payment methods. Pause anything you did not create and tell your card issuer about charges you did not authorize.
- Check roles. In the Business Suite or Page settings, look at who is an admin, editor or advertiser. Remove anyone you do not know.
- Notify clients and followers. Use your website, email list and other social channels. Be short and clear: the account was compromised, ignore any message that asks for money, and do not click links sent from it.
- Preserve evidence. Screenshots of fake posts and messages, ad spend reports, and timestamps support insurance and card disputes.
- Check customer data exposure. If direct messages contained customer information such as addresses or invoices, the legal and contractual duties may be larger than a simple scam alert. Consider legal advice.
- Change shared passwords. If several people post for the brand, replace shared logins with named access and a team password manager.
Building a recovery plan before the next incident
Businesses recover faster when they prepare. Keep a short document listing every social account, the email used for each, who has admin access, how to reach the platform's business support, and where backup codes are stored. Use a dedicated business email address for social accounts, not a personal address that might be shared or reused. Turn on login alerts. Keep a recent export of your content, because losing years of posts can hurt as much as the hack. If you manage a team, our guide to business password management is a good starting point.
Three realistic scenarios with numbers
These are illustrative examples based on common situations, not specific clients.
Scenario 1: the hobby photographer, recovered in an afternoon
A hobbyist with 4,200 followers loses access on a Tuesday morning after typing her password on a fake copyright notice. She finds an Instagram security message in her old Gmail spam folder within 40 minutes, uses the revert link, resets the password, and removes two unknown logins. She sets up an authenticator app and a password manager that evening. Cost: nothing but about two hours.
Scenario 2: the small shop, video selfie after the revert window
A candle shop owner in Sherbrooke notices her email and phone were changed four days earlier, so the revert window has passed. She secures her email, requests recovery from the login screen on her usual phone and records a video selfie in daylight. The reply arrives in two days with a path to reset the account. Meanwhile an attacker ran 380 dollars of ads on her saved card, which she disputes with the card issuer and documents with screenshots. Total out-of-pocket loss after the dispute: zero, but about a week of lost sales visibility.
Scenario 3: the paid "recovery expert"
A student with a 60,000 follower meme page posts a plea for help. Within minutes, an account offers recovery for 250 dollars in cryptocurrency, "guaranteed, 24 hours". He pays, is told a further 150 dollar "bypass fee" is needed, then is blocked. The real recovery path, a video selfie from his usual phone, would have been free. He loses 250 dollars and has to explain to his followers why a second scam used his name. The lesson is simple: the only legitimate recovery tools are in Instagram itself.
If recovery fails: what to do when the account does not come back
If every official route fails, you can still limit the damage. Keep appealing at a sensible pace, warn your audience, protect your other accounts, report the fake account, and decide whether to rebuild under a new handle. Losing an Instagram account is painful, but it does not have to cost you your email, your money or your identity.
Recovery does not always work, and honest guides should say so. If the attacker has completed their own verification, if your profile has no photo of you for the selfie to match, or if the account was already flagged for violations, Meta may decline. In that situation, follow a short sequence.
- Wait, then appeal again. Space your attempts by days, not minutes, and add new evidence each time.
- Warn your audience. Post from another channel that the old account is compromised, and give your new handle once you have it.
- Report the impersonation. Ask friends to report the hijacked account. If the attacker is using your name and photos, use Instagram's impersonation report option.
- Secure everything else. Change passwords on accounts that shared the old password, starting with email.
- Rebuild carefully. A new account with a similar name will attract impersonators too, so enable two-factor authentication and a unique password from day one.
- Keep the evidence. If you later get an answer from Meta, the dates and screenshots will help.
What it costs: doing it yourself versus getting help (CAD)
Recovering a hacked Instagram account yourself costs nothing in fees, because every official recovery tool is free. The real costs are time, stress, and any losses from ad fraud or scams. Paying a technician is only worth considering for the surrounding work, such as securing your email and devices, not for "getting the account back".
| Item | DIY | With a technician | Comment |
|---|---|---|---|
| Instagram recovery flow and video selfie | $0, 1 to 3 hours | $0 platform fee | A technician cannot bypass Meta, but can guide you through the flow |
| Securing your email and checking forwarding rules | $0, 30 to 60 min | Included in a single session | Most important step, easy to miss a rule |
| Checking your phone and computer for malware | $0 to a free scan tool, 1 hour | Included in a single session | Matters if you installed something before the hack |
| Password manager and 2FA setup across accounts | $0 to roughly $50 per year | Included in a single session | Free tiers exist, family plans cost more |
| Expert Consultation (IT Cares) | n/a | 119.99$ CAD for 60 minutes | Remote, you watch the screen |
| Paid "recovery service" found online | n/a | Typically a scam, costs you hundreds plus more fees | Do not pay |
| Fraudulent ad spend | Dispute with card issuer | Documentation help included | Report within the dispute window of your card |
A reasonable rule: if you are comfortable with settings menus, do the steps in this guide yourself. If you are locked out of your email too, if you manage several accounts or a business, or if you suspect malware, one focused session with a technician is cheaper than the cost of a second takeover.
When to call a professional
Call a technician when the attacker may have reached beyond Instagram: your email is also compromised, you clicked a link on a work computer, money has been spent or stolen, or you manage business accounts and cannot afford a repeat. A technician cannot override Meta's decisions, but can secure everything around the account, which is where repeat attacks usually come from.
IT Cares has provided remote and on-site IT support in Quebec and across Canada since 2014. In a remote session we connect to your computer while you watch, check for malware and risky browser extensions, secure your email and forwarding rules, set up a password manager and authenticator, and walk you through the official Instagram recovery screens so you submit a clean request. We do not sell account recovery, we do not claim any special access to Meta, and we will tell you plainly if an account cannot be recovered. Our Expert Consultation is 119.99$ CAD for 60 minutes. Our Google rating is 4.9 stars from 78 reviews.
To talk to someone now, call 1 (888) 711-9428 or book a remote session. If you want a broader view of how attackers target your accounts, our guide to AI-generated phishing emails explains the messages that cause most takeovers.
How to stop the next takeover
Most Instagram takeovers are prevented by four habits: a unique password in a manager, an authenticator app or passkey for sign-in, an email account that is itself well protected, and the discipline to never log in through a link in a message.
- Unique passwords everywhere. One reused password is how a gaming forum breach becomes an Instagram hack.
- Protect the email first. Your email can reset almost everything. Give it the strongest password and app-based two-step verification.
- Treat urgent messages as suspect. Copyright warnings, "verify your account" notices and "someone tagged you in a photo" links are the standard hooks. Open the app and look for the notice there instead.
- Review logins monthly. It takes a minute and catches unfamiliar sessions early.
- Keep recovery details current. An old phone number or unused email on the account turns a small incident into a lockout.
- Be careful with third-party tools. Follower trackers and "see who unfollowed you" apps ask for access and sometimes misuse it.
- Update your phone. Software updates close the holes that malware uses.
Official resources
For the current wording of Instagram's own recovery steps, use the Instagram Help Center at help.instagram.com and search for hacked accounts, since the exact steps change. For reporting in Canada, use the Canadian Anti-Fraud Centre online system and the Government of Canada's reporting portal, both listed in the sources below. For our own deeper reading, start with our main Instagram recovery guide, email recovery and what phishing is.
A note on how we wrote this
Instagram's Help Center pages load through script, and our automated fetch returned no readable text on October 1, 2026. We therefore describe Instagram's flows in general terms and flag menu names, sender addresses and time windows as things to confirm on your own screen. The CAFC reporting details were read directly from the CAFC page.
Still stuck? Get a technician on it now
Remote support from IT Cares: we connect to your device, fix it with you watching, and explain what happened.
Frequently asked questions
Related guides
- Instagram hacked? 9 recovery steps that work (our main guide)
- Facebook account hacked: recovery guide
- Email account hacked: how to recover it
- How to set up two-factor authentication
- Passkeys explained
- Password manager guide
- Lost your authenticator app? Recover 2FA access
- What is phishing
- Identity theft recovery guide
- Phone hacked: what to do
Sources and official references
Last verified: October 1, 2026
