Skip to content
Account Takeover

Your social account is hijacked and messaging your followers

You are locked out, the profile is posting crypto scams, and your followers are getting DMs "from you". Recovery and damage control have to run in parallel.

Your social account is hijacked and messaging your followers — Response Red advisory illustration

The essentials

  • Start the platform's official recovery flow immediately — hijackers change recovery details fast, and the trail cools within hours.
  • Check the email account behind the profile first; it is the usual way in, and if it's compromised, recovery loops back to the attacker.
  • Warn your followers from any other channel you have — the hijacker's real target is usually them, not you.
  • For business profiles, check the ad account and stored payment methods; fraudulent ad spend is a common cash-out.
  • "Account recovery experts" advertising in replies and DMs are a second scam.

Account takeovers are rarely about your account. Your profile is a trusted voice aimed at an audience — and the hijacker monetizes that trust with scam posts, phishing DMs, and ad fraud until the platform shuts it down.

That is why the response is two-track: recover the account through official channels, and protect the audience meanwhile.

Do this now

  1. Launch official recovery now. Use the platform's hacked-account flow (not the normal password reset). Note case numbers; persistence through the process is normal.
  2. Secure the email behind it. If the linked mailbox shows unfamiliar sessions, rules, or recovery changes, fix that first — otherwise every recovery email lands with the attacker.
  3. Warn your audience out-of-band. Another platform, a newsletter, a colleague's account, your website: a short 'my account is compromised, ignore DMs and posts' protects the people the hijacker is hunting.
  4. Cut the money paths. Business account: pause ad campaigns, check billing for new spend, remove stored cards if you can reach settings, and dispute fraudulent charges.
  5. Document the abuse. Screenshot scam posts and DMs with timestamps before they are deleted — for the platform, your followers' disputes, and any insurance claim.
  6. On recovery, evict completely. New unique password, revoke all sessions, remove unknown connected apps and devices, verify recovery email and phone are yours, then enable app-based MFA or a passkey.

What not to do

  • Do not pay "recovery services" that contact you or advertise under hacked-account posts.
  • Do not argue with the hijacker through DMs — it burns time and warns them.
  • Do not delay warning followers to avoid embarrassment; the DMs going out in your name are worse.
  • Do not reuse the old password after recovery, anywhere.
  • Do not skip the connected-apps check — a leftover OAuth grant re-opens the door.

Preserve the evidence

Whatever else happens, these are the artifacts the investigation — and any insurance claim, dispute, or prosecution — will be built from:

  • Screenshots of scam posts, DMs, and profile changes with timestamps.
  • Recovery case numbers and platform correspondence.
  • Sign-in alerts and session lists from the linked email.
  • Ad-account spend records if money moved.

Keep a clear head

Watching your own name push scams at people who trust you is uniquely horrible — but your followers blame the hijacker, not you, and a fast, plain warning raises their opinion of you rather than lowering it.

Recovery flows are slow and impersonal by design; frustration is normal. Keep the case moving daily and route your energy into protecting the audience meanwhile.

Questions victims ask

The platform's recovery process is going nowhere. What else can I do?

Keep the official case alive and escalate through every channel the platform offers — business support if you have it, verified-user paths, or advertising support when an ad account is attached; those queues move faster. Public tagging rarely helps; documented persistence does.

The hijacker is messaging my friends asking for money.

That is the business model. Your out-of-band warning is the countermeasure — post it everywhere you have a voice, and tell close contacts directly. Anyone who paid should dispute through their bank immediately.

How do I make this unrepeatable?

A unique password from a manager, app-based MFA or a passkey, your own recovery details, and a quarterly glance at connected apps. Takeovers overwhelmingly ride reused passwords and stale OAuth grants.

When the first hour is over, we take it from there.

Scoping, containment, forensics, and recovery — expert-led and evidence-safe, with AI removing the waiting. Engage a responder or talk to us about readiness.