Instagram Hacked and Your Email and Phone Number Were Changed? How to Get Your Account Back

Reviewed by IT Cares technicians · Updated October 1, 2026

Smartphone with a broken padlock icon beside a laptop, illustrating a hacked social media account with changed email and phone
When an attacker changes the email and phone, the usual password reset does not work. A different recovery path does.

Quick fix (first 15 minutes)

  1. Open the original email inbox and search for messages from security@mail.instagram.com about a changed email. If one exists and it is genuine, use its link to revert the change (see the revert trick).
  2. Change the password of that inbox now and turn on an authenticator app, because the attacker may also be inside your email.
  3. On the Instagram login screen, use the account help option and request recovery with a video selfie. Do not pay anyone offering to hack it back.

What it means when the email and phone were changed

When a hacker changes both the email address and the phone number on your Instagram account, the normal "forgot password" route is dead, because every code and reset link now goes to the attacker. You need a different recovery path that does not depend on the contact details currently on the account. That is the whole reason this situation feels so much worse than a simple stolen password, and it is also why most generic advice fails you.

This guide is for one specific case: the attacker is in, the password no longer works, and the email and phone on the profile are no longer yours. You cannot receive a login code. You may not be able to open the account at all. If you still have access and just want the general checklist, read our main guide, Instagram hacked? 9 recovery steps that work, first. This article goes deeper on what to do when the attacker has already swapped your recovery details.

A note on accuracy before we start. Meta changes the Instagram interface and its recovery tools often, and the Help Center pages are rendered by script, so menu names, button labels and time windows can differ from what you see on your phone. Where this guide describes a menu or a rule that may have changed, it says so. Treat the steps as the logic of the recovery, and follow the exact wording on your own screen.

How attackers usually get to this point

Most takeovers where the contact details are swapped start in one of four ways. The first is a phishing message that looks like a copyright warning, a "verify your blue badge" notice or a login alert, which sends you to a fake sign-in page. You type your password, and sometimes a code, and the attacker uses both within seconds. The second is a reused password that leaked in an unrelated breach. The third is access to your email account, which lets the attacker request a reset and read the code. The fourth is a malicious app or browser extension that quietly captures sessions. Our guide to what phishing is and how to spot it covers the first and most common route.

Once inside, the attacker usually acts fast. They change the email, then the phone number, then the password, and often switch on their own two-factor method so you cannot get back in even if you find a reset link. Then they either sell the account, use it to message your followers with scams, or lock you out and demand payment. Speed matters because the first hours are when your options are widest.

How this page differs from our main Instagram guide

Our main guide covers the whole life cycle: spotting a hack, nine recovery steps, what hackers do, business accounts and prevention. This page focuses only on the hard case: the attacker changed your email and phone, you have no codes, and the standard reset fails. It adds the revert-email route, the video selfie flow, trusted-contact style options, the recovery-scam landscape and the Canadian reporting steps.

Your first 15 minutes: what to do right now

In the first 15 minutes, secure the email account tied to Instagram, search that inbox for an Instagram security notice, and start official recovery from the login screen. Do not pay anyone, do not click links from messages that arrived after the hack, and do not keep guessing passwords. The order matters more than speed on any single step, because a well-ordered first quarter hour often decides whether you get the account back.

First 15 minutes checklist (print or screenshot this)

  • I opened my original email inbox on a device I trust and confirmed I can still sign in.
  • I changed that email password to a new, unique one and signed out other sessions.
  • I searched the inbox, spam and trash for "instagram", "security", and "email changed".
  • I did not click any link in a message that arrived after the hack unless I can confirm the sender.
  • I took screenshots of the account page, messages and anything the attacker posted.
  • I wrote down the username, the original email, the original phone number and the date I last had access.
  • I started recovery from the Instagram login screen, not from a link someone sent me.
  • I told a friend or colleague through another channel that the account is compromised.
  • I decided that I will not pay anyone who promises to get the account back.

Step 1: secure your email before Instagram

This feels backwards, but it is the most important move. Your email address is the key to your Instagram recovery, and it may also be the way the attacker got in. If the attacker has your email, any message that Instagram sends to the old address can be read and deleted by them, including the revert link we discuss below. Change the email password from a device you trust, sign out of all other sessions, and check the forwarding rules and filters. Attackers sometimes add a rule that silently forwards or deletes messages from Instagram. If you suspect the email itself is compromised, follow our guide to recovering a hacked email account before you continue.

Step 2: search your old inbox for the security message

When the email address on an Instagram account changes, Instagram has described sending a notice to the previous address. That message can contain a way to undo the change. Search for the word "Instagram", for "email address changed" and for the sender address security@mail.instagram.com. Check spam, trash and any "Promotions" or "Updates" tab, because automated security mail is often filed there. The next section explains how to use that message safely, and how to tell a real one from a fake.

Step 3: do not make the situation worse

Some actions reduce your chances. Repeatedly entering wrong passwords can trigger rate limits. Creating a new account with the same name does not help recovery. Deleting the Instagram app does not remove anything from the attacker's side. And above all, replying to people who contact you offering "help" gives scammers the opening they want. If someone you do not know messages you after a public complaint, treat them as a risk by default.

Step 4: collect the evidence

Take screenshots of the profile as it now looks, any posts or stories the attacker published, and any messages sent to your followers. Save emails about the change, including full headers if you can. This evidence supports a platform appeal, a police report, a fraud report and, for business owners, an insurance claim. It costs a few minutes and can matter for weeks.

What a realistic first hour looks like

Realistic scenario (illustrative, not a specific client). A photographer in Gatineau wakes up to a message from a friend: "Why are you asking me for 200 dollars?" She tries to sign in and the password fails. The reset code is sent to a phone number she does not recognize. In the next hour she changes her email password, finds a security message from Instagram in her spam folder dated three hours earlier, uses the link in it, and regains access before the attacker has switched on their own two-factor method. She did nothing technical. She simply searched the right inbox in the right order, which is exactly what the checklist above is designed to make automatic.

The email revert trick: undo the change from your old inbox

When an Instagram email address is changed, Instagram has described sending a security message to the old address, typically from security@mail.instagram.com, that lets the original owner reverse the change. If you find a genuine one, using it can restore the old email and may let you reset the password, but it only works for a limited time, so check right away. This is the single highest-value action in this guide, and also the one most people never try because they do not know the message exists.

What the message is, and how to find it

The idea is simple. A change to the email on your account is a sensitive event, so Instagram notifies the address that was on file before the change. The notice says that the email was changed and offers a link to revert or to secure the account. If the attacker did not delete it, it is waiting in your old inbox. Search by sender, by the words "Instagram" and "email", and by the date you were locked out. Also check the trash and any folders that filters might have created.

Gmail, Outlook, iCloud and Yahoo all let you search all mail including spam and trash. In Gmail, for example, you can use the query from:security@mail.instagram.com and widen the search to "All Mail". If the search returns nothing, the notice may have gone to a different address (a second email you once used), or the attacker may have removed it, or the account may have been set up in a way that did not trigger one.

How to tell a real message from a fake one

Phishers know that victims are hunting for this exact message, so they send fakes. Use these checks before you click anything.

If you cannot verify the message with confidence, do not use the link. Go to the Instagram app, use the recovery options on the login screen, and treat the email as a lead rather than a command.

How long you have

Instagram describes the revert option as time limited. We have not been able to read a current, authoritative number from the Help Center for this article, because those pages are rendered by script and returned no text to our fetch. We therefore do not state a number of days. Assume the window is short, check the Help Center wording for the current figure, and act the same day. If your window has passed, the video selfie route below is your main alternative.

What to do after you click the revert link

  1. Confirm the email address on the account is your own again.
  2. Immediately request a password reset to that address and choose a long, unique password from a password manager.
  3. Remove any phone number you do not recognize, and add your own.
  4. Look for two-factor authentication methods you did not set up and remove them.
  5. Open the list of active logins and sign out every session you do not recognize. Menu names such as "Accounts Center", "Password and security" and "Where you're logged in" have appeared in Meta's interface, but the exact labels may differ on your version.
  6. Only then think about the aftermath: messages sent to followers, posts, ad accounts and linked apps.

If the revert link does not work

It may have expired, been used already, or been triggered by the attacker's own change in a second step. Do not keep clicking it. Move on to the video selfie route and the recovery options on the login screen, and keep the email as evidence for any appeal.

Which situation are you in? A quick comparison

Your best recovery route depends on what the attacker changed and whether you still hold your original email. The table below maps the four most common situations to the route with the best odds, so you can skip to the section that matches your case. It is a guide to priorities, not a promise, because Meta decides each case and can change its tools without notice.

Your situationBest first moveBackup routeOdds (rough guide)
Password changed only, you still control the original email and phoneNormal reset from the login screen, then sign out all sessionsSecurity notice from Instagram in your inboxHigh
Email changed, you still control the original emailFind and use the security message from your old inboxVideo selfie recoveryGood if you act fast
Email and phone both changed, you control the original emailRevert message if present, then recovery from the login screenVideo selfie recoveryModerate
Email and phone changed, you lost control of the original email tooRecover the email account firstVideo selfie recovery with a device you previously usedLower, depends on the email provider
Account disabled or suspended after the hackUse the appeal option shown in the appWait for review, do not file duplicatesVariable
Business or creator account with a linked Facebook PageCheck page roles and the Accounts CenterMeta Business Suite support toolsModerate to good

The odds column is deliberately rough. Nobody outside Meta has reliable statistics on recovery rates by situation, and anyone who quotes you a precise percentage is guessing. What we do see in practice is a pattern: people who protect their email first, act within a day, use their usual device and avoid scammers recover more often than people who wait, panic or pay.

Why your usual device and network matter

Instagram's systems look at signals such as the device you normally use, the network you normally connect from, and your history of logins. Attempting recovery from your usual phone, on your home Wi-Fi, from the same app you have been using for months, gives the system a reason to trust that you are the real owner. Trying from a cafe on a borrowed laptop with a VPN switched on gives it a reason to doubt you. If you have the Instagram app still signed in on an old phone or a tablet, do not log out of it, because that session may be the easiest way back in.

Look for a session that is still alive

This is a detail that many guides skip. If you have another device where Instagram is still open, for example an old phone, a tablet or a computer browser, check it before doing anything else. Sessions sometimes survive a password change for a short time. From a surviving session you may be able to see the account's login activity, to change the password again, and to remove the attacker's email and phone from within the app. Do not sign out of that device. Do not update the app if you can avoid it until you have finished recovery, in case an update forces a new sign-in.

Illustration of a phone, an email envelope and a camera connected by lines, showing the recovery paths for a hacked social account

Video selfie verification: how it works and how to pass it

The video selfie is an identity check in which Instagram asks you to record a short video of your face, turning your head as instructed, so it can compare you with the account and decide whether you are the real owner. It is the main recovery path for people who have lost access to both their email and phone, and it is free. No one can do it for you.

When you will be offered it

Instagram does not offer the selfie in every case. It tends to appear when you choose the "need more help" style option during recovery and the system decides it has enough information to try an identity check. If your account has photos of your face, a video selfie is more likely to succeed because there is something to compare. If your account is a pet, a logo or a landscape page, the comparison is harder and other evidence matters more. Menu names change, so look for wording about confirming that you are the owner, or about getting back into your account without a code.

How to start recovery the right way

  1. Open the Instagram app on the phone you normally use, or the Instagram site in the browser you normally use. Do not use a link from a message you were sent.
  2. On the login screen, choose the option for trouble signing in or forgotten password.
  3. Enter your username (not an email the attacker may have set).
  4. When Instagram offers to send a code to a contact detail you do not recognize, look for an option like "I can't access this email or phone" or "try another way".
  5. Follow the prompts. Answer honestly, and use contact details you control for the reply, such as your original email, because Instagram will use them to message you about the request.
  6. If a video selfie is offered, take it in one calm attempt.

How to record a selfie that passes

Privacy warning about the selfie

A video selfie is sensitive biometric data. Only submit it inside the official Instagram app or the official Instagram site reached by typing the address yourself. Anyone who asks you to record a video and send it to them in a chat, or to hold up your ID next to your face for a "verification agent" on Telegram or WhatsApp, is trying to steal your identity or to impersonate you.

After you submit it

Instagram reviews the video and replies by email, usually to the address you gave during recovery. It can take from minutes to days. While you wait, do not submit repeated requests, which may be treated as noise, and do not delete the thread of emails. If you are asked for more information, respond promptly from the same device. If the request is rejected, you can try again after a delay, and you should look at the other options below rather than repeating the same attempt over and over.

Meta Accounts Center, linked accounts and other ways back in

If your Instagram is linked to a Facebook profile or Page through Meta's Accounts Center, that link can be a second door back in, because you may be able to manage the Instagram account from Facebook, or review and remove the attacker's changes from there. Whether this works depends on how the accounts were linked, so check it while you still can. We describe the names Meta has used, but they change often, so treat them as hints.

Check Facebook and the Accounts Center

Meta groups settings for linked profiles under a hub it has called the Accounts Center. If your Facebook account is still yours and Instagram is linked there, open Facebook's settings, look for the Accounts Center, and check whether the Instagram account appears in the list. From there you may see login and security settings for the connected profile, and be able to remove the connection or review its activity. If the attacker has also taken your Facebook account, our guide to recovering a hacked Facebook account is the next stop.

The Business Suite angle

Creator and business accounts are often tied to a Facebook Page and to Meta Business Suite. If you are an admin of that Page, you may see the Instagram account in the Business Suite, and you may be able to remove the attacker's access from there. This is also where you can check who else has roles on the Page, which matters if the attacker added themselves as an admin. We return to the business case in a later section.

Trusted contacts and friends who can vouch

Some platforms let a few trusted people help you recover an account. Facebook has offered a trusted-contacts style feature in the past, and Meta may use similar ideas in different forms for different regions and account types. We could not confirm from the Help Center, for this article, whether Instagram currently offers a trusted-contacts recovery for personal accounts, so do not count on it. What does help in practice is a friend reporting the hacked account through Instagram's own report option, as a person who knows the real owner. A handful of reports from real people can add weight to an appeal, and the friends can warn others at the same time.

Other evidence you can prepare

Not every request will ask for these things, but having them ready saves time and shows that you are the person who created and used the account.

Passwords, passkeys and where recovery fails

Recovery fails most often for four reasons. First, the request came from an unfamiliar device or network. Second, the contact details provided did not match anything on the account's history. Third, the video selfie did not match, often because of poor lighting or because the profile has no photo of the owner. Fourth, the attacker has already completed their own verification and the system now sees them as the owner. In that last case your best path is to show history: devices, dates, and consistent evidence over time. This is also why you should not delay.

Recovery scams: fake "hacker" services, Telegram agents and paid Meta insiders

Anyone who contacts you offering to recover your Instagram account for a fee is almost certainly running a scam. Genuine recovery happens through Instagram's own tools and costs nothing, so a request for cryptocurrency, gift cards, a transfer or your ID is a signal to stop. Victims of account takeovers are targeted a second time, by a different group, within hours of posting a plea for help.

How the second scam works

When people lose an account, they search for help, post in forums, comment under creators' videos and message friends. Scammers watch all of this. They reply in comments, send direct messages, run ads for "social media recovery experts" and post fake testimonials. The pitch is always the same: they know a contact inside Meta, or they have a special tool that can reverse the hack, and they can do it in hours if you pay a fee first. After you pay, one of three things happens. They vanish. They ask for a "release fee" or "insurance deposit" and keep asking. Or they ask for your login details and your ID, then use them to take over your other accounts.

SignWhat it looks likeWhat to do
Unsolicited helpA stranger messages you minutes after you complain publiclyIgnore, block, report
Guaranteed result"100% recovery in 24 hours"No legitimate party can guarantee it
Payment firstCrypto, gift cards, wire or e-transfer demanded upfrontNever pay
Off-platform chat"Message me on Telegram or WhatsApp"Decline, stay on official channels
Meta insider claim"I work at Meta" or "my cousin works at Instagram"Meta does not sell account recovery through insiders
Request for ID or selfieSend a photo of your driver's licence or a videoNever send to a third party
Fake support phone numberA number found in search results or adsInstagram does not publish a general phone line for personal accounts

Why Telegram shows up so often

Telegram and similar apps appeal to scammers because they make it easy to create anonymous accounts, move conversations out of view of Meta's moderation and ask for payment in crypto. This is not a statement about Telegram's legitimacy as an app. It is a reminder that a recovery pitch that begins on Instagram and then says "continue on Telegram" is following a very familiar scam script. The same applies to WhatsApp and Signal.

The "hacker for hire" trap

Some victims are tempted to hire someone to hack the account back. Apart from being illegal in many places, it leaves you in a worse position: you have handed money and personal information to a criminal who has no incentive to help. If they do manage to access something, they may keep it. Treat "ethical hacker" offers aimed at recovering social accounts with the same suspicion as the others.

If you already paid

Do not send more money, even if the person says the last step needs one more payment. Keep the receipts and chat logs. Contact your bank or card issuer quickly, and for cryptocurrency, the exchange you used, because speed can matter. Report the incident to the Canadian Anti-Fraud Centre if you are in Canada. Our guide to what to do after a tech support scam covers the money side in detail.

Contacting Meta and getting a human: what works and what does not

Meta does not offer a general support phone line or live chat for personal Instagram accounts. The realistic routes are the recovery flow on the login screen, the "report a problem" or help options in the app, and the appeal forms Meta shows after a lock or suspension. Numbers and "support agents" found online are, in most cases, scams.

The routes that actually exist

What not to do

Writing a good appeal message

If a form lets you write a message, keep it short, calm and specific: your username, the date you lost access, what the attacker changed (email, phone, password), that you did not authorize it, the email and phone that were originally on the account, and that you can provide a video selfie. Add one line stating that you have secured your email. Mention nothing that is not true. A reviewer reading hundreds of cases a day will respond better to a clear case than to a long one.

Reporting the fraud in Canada: CAFC, police and the privacy angle

If you are in Canada, report the hack to the Canadian Anti-Fraud Centre through its online reporting system, and file a police report if money, extortion, harassment or impersonation is involved. A report does not recover the account, but it creates a record, supports any later claim, and helps investigators track the groups behind these takeovers.

The Canadian Anti-Fraud Centre

The CAFC is Canada's central body for collecting information on fraud and cybercrime. Its reporting page, which we opened on October 1, 2026, points victims to the online reporting system at reportcyberandfraud.canada.ca, where you can file a report, and states that victims should also contact local police. The online system allows you to file without giving your name if you prefer. We have not listed the CAFC's phone line here, since our policy is to keep this page free of other numbers, but it is on the CAFC site if you prefer to call.

When to also go to the police

If identity documents were exposed, also read our identity theft recovery guide and consider placing fraud alerts with the credit bureaus.

Privacy rights in Canada

If your personal information has been exposed because of a company's failure, such as a business account that leaked customer messages, Canadian privacy law may require the business to notify those affected in some circumstances. For a typical individual takeover through phishing, the legal angle is smaller, and the practical steps are the ones in this guide. If you are a business owner, keep a record of who was affected and consider speaking to a lawyer if customer data was involved.

Securing the account after you get it back

Getting the account back is only half the job. Within the first hour, change the password to a unique one, remove every unknown email, phone number, device and login, turn on two-factor authentication using an authenticator app or passkey rather than text messages, and review the apps connected to the account. Skip this and the same attacker, who may still hold a saved session or your old password elsewhere, can take it again.

After-recovery security checklist

  • I set a new, long, unique Instagram password using a password manager.
  • I confirmed the email and phone number on the account are mine and no others are listed.
  • I signed out of every unknown session and device in the login activity list.
  • I turned on two-factor authentication with an authenticator app, and saved the backup codes offline.
  • I checked whether passkeys are offered for my account and, if so, set one up.
  • I removed third-party apps and websites I do not recognize from the connected apps list.
  • I reviewed linked Facebook, Threads and Business Suite connections and their roles.
  • I changed the password of my email account and turned on two-step verification there.
  • I checked messages sent from the account while I was locked out and told affected contacts.
  • I reviewed what the attacker posted, changed or deleted, and restored what I could.

Two-factor authentication: use an app, not SMS

Text-message codes are better than nothing, but they are weak against SIM swaps and against attackers who convince a carrier to move your number. An authenticator app generates codes on your device and is much harder to intercept. Instagram has offered an authentication app option under its security settings, though the exact menu path may differ on your version. Save the backup codes in your password manager or print them. If you lose the phone later, our guide to recovering 2FA access after losing an authenticator will help, and our step-by-step two-factor authentication setup guide covers the general process.

Passkeys: check, do not assume

Passkeys replace passwords with a cryptographic key stored on your device and unlocked by your face, fingerprint or PIN. They resist phishing because they only work on the real site. Whether Instagram supports passkeys for your account today is something we could not confirm from the Help Center for this article, so check the security settings in your app. If it is not offered, use an authenticator app. Our explainer on passkeys covers how they work and where they apply.

Review logins, devices and connected apps

Look for a list of where you are logged in, usually under the security or Accounts Center settings. Sign out any device or location you do not recognize. Then review the list of apps and websites that have access. Attackers often keep access through an authorized app even after the password changes. Remove anything you did not set up yourself.

Check what the attacker did

Check sent messages, because many takeovers send investment, crypto or "vote for me" links to your followers. Check whether the profile bio, link, name or username changed. Check the ad account and payment methods if you use one. Check Highlights and stories for deleted content. Make a list and decide what to restore and what to explain publicly. A short post such as "my account was compromised, please ignore messages from last week" does more to protect your followers than silence.

Fix the root cause

Most repeat takeovers come from the same cause as the first. If you reused the password somewhere, change it everywhere, starting with email, banking and shopping. If you clicked a phishing link on your computer, scan the device and review browser extensions. If the attacker got in through your email, secure that first. A password manager makes unique passwords painless, and our password manager guide compares the options. If you suspect malware on your phone or computer, our guide on what to do if your phone is hacked shows the checks.

If you used the account for business: clients, ads and brand

If Instagram was part of your income, treat the takeover as a business incident. Tell your clients, pause advertising, check who has admin roles on the linked Facebook Page and Business Suite, and document the losses, because the attacker may have run ads on your card or sent scam messages in your name.

The first business steps

  1. Pause ads. If the account was linked to an ad account, check for new campaigns and unknown payment methods. Pause anything you did not create and tell your card issuer about charges you did not authorize.
  2. Check roles. In the Business Suite or Page settings, look at who is an admin, editor or advertiser. Remove anyone you do not know.
  3. Notify clients and followers. Use your website, email list and other social channels. Be short and clear: the account was compromised, ignore any message that asks for money, and do not click links sent from it.
  4. Preserve evidence. Screenshots of fake posts and messages, ad spend reports, and timestamps support insurance and card disputes.
  5. Check customer data exposure. If direct messages contained customer information such as addresses or invoices, the legal and contractual duties may be larger than a simple scam alert. Consider legal advice.
  6. Change shared passwords. If several people post for the brand, replace shared logins with named access and a team password manager.

Building a recovery plan before the next incident

Businesses recover faster when they prepare. Keep a short document listing every social account, the email used for each, who has admin access, how to reach the platform's business support, and where backup codes are stored. Use a dedicated business email address for social accounts, not a personal address that might be shared or reused. Turn on login alerts. Keep a recent export of your content, because losing years of posts can hurt as much as the hack. If you manage a team, our guide to business password management is a good starting point.

Three realistic scenarios with numbers

These are illustrative examples based on common situations, not specific clients.

Scenario 1: the hobby photographer, recovered in an afternoon

A hobbyist with 4,200 followers loses access on a Tuesday morning after typing her password on a fake copyright notice. She finds an Instagram security message in her old Gmail spam folder within 40 minutes, uses the revert link, resets the password, and removes two unknown logins. She sets up an authenticator app and a password manager that evening. Cost: nothing but about two hours.

Scenario 2: the small shop, video selfie after the revert window

A candle shop owner in Sherbrooke notices her email and phone were changed four days earlier, so the revert window has passed. She secures her email, requests recovery from the login screen on her usual phone and records a video selfie in daylight. The reply arrives in two days with a path to reset the account. Meanwhile an attacker ran 380 dollars of ads on her saved card, which she disputes with the card issuer and documents with screenshots. Total out-of-pocket loss after the dispute: zero, but about a week of lost sales visibility.

Scenario 3: the paid "recovery expert"

A student with a 60,000 follower meme page posts a plea for help. Within minutes, an account offers recovery for 250 dollars in cryptocurrency, "guaranteed, 24 hours". He pays, is told a further 150 dollar "bypass fee" is needed, then is blocked. The real recovery path, a video selfie from his usual phone, would have been free. He loses 250 dollars and has to explain to his followers why a second scam used his name. The lesson is simple: the only legitimate recovery tools are in Instagram itself.

If recovery fails: what to do when the account does not come back

If every official route fails, you can still limit the damage. Keep appealing at a sensible pace, warn your audience, protect your other accounts, report the fake account, and decide whether to rebuild under a new handle. Losing an Instagram account is painful, but it does not have to cost you your email, your money or your identity.

Recovery does not always work, and honest guides should say so. If the attacker has completed their own verification, if your profile has no photo of you for the selfie to match, or if the account was already flagged for violations, Meta may decline. In that situation, follow a short sequence.

  1. Wait, then appeal again. Space your attempts by days, not minutes, and add new evidence each time.
  2. Warn your audience. Post from another channel that the old account is compromised, and give your new handle once you have it.
  3. Report the impersonation. Ask friends to report the hijacked account. If the attacker is using your name and photos, use Instagram's impersonation report option.
  4. Secure everything else. Change passwords on accounts that shared the old password, starting with email.
  5. Rebuild carefully. A new account with a similar name will attract impersonators too, so enable two-factor authentication and a unique password from day one.
  6. Keep the evidence. If you later get an answer from Meta, the dates and screenshots will help.

What it costs: doing it yourself versus getting help (CAD)

Recovering a hacked Instagram account yourself costs nothing in fees, because every official recovery tool is free. The real costs are time, stress, and any losses from ad fraud or scams. Paying a technician is only worth considering for the surrounding work, such as securing your email and devices, not for "getting the account back".

ItemDIYWith a technicianComment
Instagram recovery flow and video selfie$0, 1 to 3 hours$0 platform feeA technician cannot bypass Meta, but can guide you through the flow
Securing your email and checking forwarding rules$0, 30 to 60 minIncluded in a single sessionMost important step, easy to miss a rule
Checking your phone and computer for malware$0 to a free scan tool, 1 hourIncluded in a single sessionMatters if you installed something before the hack
Password manager and 2FA setup across accounts$0 to roughly $50 per yearIncluded in a single sessionFree tiers exist, family plans cost more
Expert Consultation (IT Cares)n/a119.99$ CAD for 60 minutesRemote, you watch the screen
Paid "recovery service" found onlinen/aTypically a scam, costs you hundreds plus more feesDo not pay
Fraudulent ad spendDispute with card issuerDocumentation help includedReport within the dispute window of your card

A reasonable rule: if you are comfortable with settings menus, do the steps in this guide yourself. If you are locked out of your email too, if you manage several accounts or a business, or if you suspect malware, one focused session with a technician is cheaper than the cost of a second takeover.

When to call a professional

Call a technician when the attacker may have reached beyond Instagram: your email is also compromised, you clicked a link on a work computer, money has been spent or stolen, or you manage business accounts and cannot afford a repeat. A technician cannot override Meta's decisions, but can secure everything around the account, which is where repeat attacks usually come from.

IT Cares has provided remote and on-site IT support in Quebec and across Canada since 2014. In a remote session we connect to your computer while you watch, check for malware and risky browser extensions, secure your email and forwarding rules, set up a password manager and authenticator, and walk you through the official Instagram recovery screens so you submit a clean request. We do not sell account recovery, we do not claim any special access to Meta, and we will tell you plainly if an account cannot be recovered. Our Expert Consultation is 119.99$ CAD for 60 minutes. Our Google rating is 4.9 stars from 78 reviews.

To talk to someone now, call 1 (888) 711-9428 or book a remote session. If you want a broader view of how attackers target your accounts, our guide to AI-generated phishing emails explains the messages that cause most takeovers.

How to stop the next takeover

Most Instagram takeovers are prevented by four habits: a unique password in a manager, an authenticator app or passkey for sign-in, an email account that is itself well protected, and the discipline to never log in through a link in a message.

Official resources

For the current wording of Instagram's own recovery steps, use the Instagram Help Center at help.instagram.com and search for hacked accounts, since the exact steps change. For reporting in Canada, use the Canadian Anti-Fraud Centre online system and the Government of Canada's reporting portal, both listed in the sources below. For our own deeper reading, start with our main Instagram recovery guide, email recovery and what phishing is.

A note on how we wrote this

Instagram's Help Center pages load through script, and our automated fetch returned no readable text on October 1, 2026. We therefore describe Instagram's flows in general terms and flag menu names, sender addresses and time windows as things to confirm on your own screen. The CAFC reporting details were read directly from the CAFC page.

Still stuck? Get a technician on it now

Remote support from IT Cares: we connect to your device, fix it with you watching, and explain what happened.

Frequently asked questions

Can I recover my Instagram if the hacker changed my email and phone number?
Often yes, but not through the normal password reset, because the reset message now goes to the attacker. Your best options are the security email Instagram may have sent to your original address, the video selfie recovery flow, and the recovery tools Meta offers from the login screen. Results are not guaranteed, and the earlier you act the better.
Does Instagram send an email when the email address on my account is changed?
Instagram has described sending a security notice to the old address when the email on an account is changed, usually from security@mail.instagram.com, with a link to undo the change. Check your inbox, spam and trash. Only trust the message if it is genuine, and check the exact sender address and the link before you click.
How long do I have to revert the email change?
Instagram says the revert link works for a limited time, but this guide does not state a specific number of days because Meta can change it. Treat it as urgent and check the current Help Center wording. If the link has expired, move to the video selfie and recovery options.
What is the Instagram video selfie and how do I pass it?
It is an identity check where Instagram asks you to record a short video of your face from different angles so it can compare you with your account. Use good light, remove glasses and hats, keep your face in frame and use the same phone and network you normally use if possible. Never send the video to anyone else.
Is it safe to pay someone to recover my hacked Instagram account?
No. Services that promise to hack the account back, or to bribe an insider at Meta, are scams in nearly every case. They ask for payment by cryptocurrency, gift cards or transfer, then disappear or ask for more. Recovery only happens through Instagram's own flows.
Why is a stranger on Telegram offering to recover my account?
Because scammers monitor public complaints and comments and then contact victims directly. A genuine recovery never needs a paid middleman. Block the profile, do not share codes or your ID, and report the account.
Should I report a hacked Instagram account to the Canadian Anti-Fraud Centre?
Yes if you are in Canada, especially if money, extortion or impersonation of your contacts is involved. The CAFC accepts reports through its online reporting system and the report helps track patterns. You can also file a police report, which some insurers and platforms ask for.
What if the hacker is posting scams to my followers?
Warn your followers through another channel such as a message from a different account or a story on another platform, because they may be targeted by messages that appear to come from you. Report the posts as the account owner if you still can, and ask friends to report the account.
Can I recover a business or creator Instagram account the same way?
The same recovery flows apply, but you should also check who has admin access in Meta Business Suite or the Accounts Center, alert clients and pause ad spend if you can. Business accounts often have a connected Facebook Page, which may give you another way in.
After I get the account back, what should I change first?
Change the Instagram password to a unique one from a password manager, remove unknown devices and logins, set two-factor authentication using an authenticator app or passkey, and check the email and phone listed on the account. Also change the password of the email account linked to Instagram.
What if Instagram says the account was disabled after it was hacked?
A disabled or suspended status after a hack usually means automated systems flagged abuse. Use the appeal option shown on the screen, describe what happened without exaggerating, and complete any verification offered. Do not create several appeals at once.
Is there an Instagram phone number or live chat I can call?
Instagram does not publish a general support phone line for personal accounts, so numbers found in search results are typically scams. Use the in-app help, the Help Center and the recovery options on the login screen.

Sources and official references

Last verified: October 1, 2026

Need Help?