The essentials
- Start the platform's official recovery flow immediately — hijackers change recovery details fast, and the trail cools within hours.
- Check the email account behind the profile first; it is the usual way in, and if it's compromised, recovery loops back to the attacker.
- Warn your followers from any other channel you have — the hijacker's real target is usually them, not you.
- For business profiles, check the ad account and stored payment methods; fraudulent ad spend is a common cash-out.
- "Account recovery experts" advertising in replies and DMs are a second scam.
Account takeovers are rarely about your account. Your profile is a trusted voice aimed at an audience — and the hijacker monetizes that trust with scam posts, phishing DMs, and ad fraud until the platform shuts it down.
That is why the response is two-track: recover the account through official channels, and protect the audience meanwhile.
Do this now
- Launch official recovery now. Use the platform's hacked-account flow (not the normal password reset). Note case numbers; persistence through the process is normal.
- Secure the email behind it. If the linked mailbox shows unfamiliar sessions, rules, or recovery changes, fix that first — otherwise every recovery email lands with the attacker.
- Warn your audience out-of-band. Another platform, a newsletter, a colleague's account, your website: a short 'my account is compromised, ignore DMs and posts' protects the people the hijacker is hunting.
- Cut the money paths. Business account: pause ad campaigns, check billing for new spend, remove stored cards if you can reach settings, and dispute fraudulent charges.
- Document the abuse. Screenshot scam posts and DMs with timestamps before they are deleted — for the platform, your followers' disputes, and any insurance claim.
- On recovery, evict completely. New unique password, revoke all sessions, remove unknown connected apps and devices, verify recovery email and phone are yours, then enable app-based MFA or a passkey.
What not to do
- Do not pay "recovery services" that contact you or advertise under hacked-account posts.
- Do not argue with the hijacker through DMs — it burns time and warns them.
- Do not delay warning followers to avoid embarrassment; the DMs going out in your name are worse.
- Do not reuse the old password after recovery, anywhere.
- Do not skip the connected-apps check — a leftover OAuth grant re-opens the door.
Preserve the evidence
Whatever else happens, these are the artifacts the investigation — and any insurance claim, dispute, or prosecution — will be built from:
- Screenshots of scam posts, DMs, and profile changes with timestamps.
- Recovery case numbers and platform correspondence.
- Sign-in alerts and session lists from the linked email.
- Ad-account spend records if money moved.
Keep a clear head
Watching your own name push scams at people who trust you is uniquely horrible — but your followers blame the hijacker, not you, and a fast, plain warning raises their opinion of you rather than lowering it.
Recovery flows are slow and impersonal by design; frustration is normal. Keep the case moving daily and route your energy into protecting the audience meanwhile.
Questions victims ask
The platform's recovery process is going nowhere. What else can I do?
Keep the official case alive and escalate through every channel the platform offers — business support if you have it, verified-user paths, or advertising support when an ad account is attached; those queues move faster. Public tagging rarely helps; documented persistence does.
The hijacker is messaging my friends asking for money.
That is the business model. Your out-of-band warning is the countermeasure — post it everywhere you have a voice, and tell close contacts directly. Anyone who paid should dispute through their bank immediately.
How do I make this unrepeatable?
A unique password from a manager, app-based MFA or a passkey, your own recovery details, and a quarterly glance at connected apps. Takeovers overwhelmingly ride reused passwords and stale OAuth grants.