All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
If hackers access your Instagram, they can see your account details, attack your contacts, and post harmful content. They can also pinpoint your exact location. As stressful and damaging as this might seem, it's far from the worst thing they can do. With all that data, criminals can steal your identity.
Impersonating you allows them to potentially steal your money, health benefits, and even your home. Lastly, they can commit crimes in your name and leave you with hefty fines or an arrest warrant. Identity theft is extremely difficult to roll back, so it's best to prevent it altogether.
Using a solid antivirus program is the crucial first step. Keep reading to learn how to block scams and other attacks and what to do with a hacked Instagram account.
What to do if you can still access your hacked Instagram account
What to do if you're locked out of your hacked Instagram account
How to protect your Instagram account from hackers
Instagram account hacked: What to do FAQ
Bottom line
Is your Instagram account hacked? Here’s how to tell
Recognizing common Instagram scams and acting quickly is essential for your account recovery. Here are some of the major red flags that could indicate a hack.
- You can’t log in to your Instagram account: If you can’t get past the login screen, something is obviously wrong with your account. It doesn’t necessarily indicate a takeover, but it’s a very strong possibility.
- You receive an unrequested password reset email: If this happens without your prompt, it is a major red flag. A hacker is likely trying to change your account password and lock you out.
- Your contacts are reporting strange messages from you: Criminals will try to branch out by contacting and even attacking your friends and followers from your account. They’ll send phishing messages prompting your contacts to share info or click on malicious links.
- You notice unauthorized changes on your account: Changes you didn’t make are a clear sign of a hack. For example, criminals can change your username, profile picture, or linked email address.
- You see posts and comments you didn’t write: If your account starts posting “on its own,” someone else probably has access to it.
- You see unrecognized active sessions: Instagram allows you to see active sessions on different devices. Hopefully, all of them belong to you. You should immediately revoke access to any device you don’t recognize.
What to do if you can still access your hacked Instagram account
Recovering from an Instagram hack is much easier if you can still log in. At this point, you’re racing the scammer who’s trying to lock you out. Follow these steps as soon as you identify an external presence.
Change your Instagram password
Given the successful hack, we’ll presume the attacker has your password. Therefore, you should change it as quickly as possible. We recommend creating a strong password with upper and lowercase letters, symbols, and numbers.
Go to your profile page, open the hamburger menu at the top-right corner (the ☰ symbol), and tap Accounts Center.
Scroll to Account Settings > Password and Security and tap Change password.
To boost your account’s security even further, you can enable two-factor authentication (2FA). This feature sends a security code to your device that you’ll have to use to log in. The attacker won’t have access to this security code, so they’ll be cut off from your account.
Close the sessions you don’t recognize
- Go to your profile page and open the hamburger menu.
- Tap Accounts Center at the top.
- Scroll to Account Settings and tap Password and Security.
- Tap Where You’re Logged In.
- You can review logins on different devices here. If you see something suspicious, tap Select devices to log out.
Inform your contacts
Use different third-party messaging apps to inform your friends and family of the hack. Advise them to ignore your Instagram messages, posts, and comments. If they interact with the scammer, they could share private information or click on malicious links.
Report the hack to Instagram
Instagram’s Hacked page can help you with some specific problems. It can address minor issues like a forgotten password to major risks like online impersonation and hacks. We’re currently interested in the My account was hacked option.
After you click it, you’ll have to identify your account. This step will prompt you to provide your username, phone number, or email address linked to your Instagram profile. From here, you can follow the steps that apply to this situation and hopefully regain control of your account.
What to do if you’re locked out of your hacked Instagram account
Things become exponentially more complicated when a hacker locks you out. There’s still hope, but recovering from here can be a long and painful process that can ultimately fail. In other words, there’s no guarantee you’ll get your account back once the criminal takes full control.
Here’s what you can do.
- Report the hack to Instagram using the steps outlined above.
- Check for a message from Instagram from its official email address, security@mail.instagram.com.
- Request a login link from Instagram to confirm you’re the rightful account holder.
- Verify your identity by providing the email address or phone number associated with your account and take a video selfie to confirm your identity.
How to protect your Instagram account from hackers
Preventing Instagram hacks is always better than dealing with the fallout. There are several ways to secure your account.
- Use strong and unique passwords and enable 2FA. As mentioned, use a variety of letters and symbols. Also, avoid adding personal details scammers can easily find online (your birthday, for example). We recommend using a good password manager to keep all your passwords in one secure place.
- Enable suspicious login notifications. These alerts will let you know if someone tries to log in to your Instagram account from an unknown device. They’ll give you enough time to change your password and protect your profile from attacks.
- Don’t link payment methods to your account. Your billing info can do a lot of damage in the wrong hands. If someone hacks your Instagram account, they could also use linked payment methods to make purchases.
- Use a backup email address. Adding a backup email can help if your primary address is compromised.
- Use a reliable virtual private network (VPN). Secure services like NordVPN can mask your IP address, encrypt your Instagram activity, and even protect you from malware and phishing attacks.
- Use a reliable antivirus program. These tools can block malware attacks but also remove existing infections.
The best antivirus software to protect your Instagram account
A solid anti-malware tool can protect your Instagram profile against most threats in real-time. Here are some of our top picks.
- TotalAV offers top-tier protection against malware, phishing, ransomware, and other online threats. It can even detect malicious apps after installation. Depending on the plan, you’ll also have access to system tune-up tools, a disk cleaner, a browser manager and cleaner, a secure VPN, and more.
Get TotalAV | Read TotalAV Review - Bitdefender provides excellent malware protection (including ransomware), a privacy firewall, parental controls, and a device optimizer. Depending on your subscription, you can secure up to five devices at the same time.
Get Bitdefender | Read Bitdefender Review - McAfee offers solid malware protection and can leverage AI to detect scams and malicious websites. It also provides a VPN and password manager. The highest subscription plan has identity protection features, including $1 million identity theft coverage.
Get McAfee | Read McAfee Review
Instagram account hacked: What to do FAQ
How long does it take Instagram to respond to a report of a hacked account?
Instagram doesn’t provide an exact answer on its site, but according to users, the initial response takes about 24-48 hours. If the problem requires further action, timelines can vary greatly. From start to finish, the process can take days or weeks.
Can hackers access my phone through Instagram?
According to Meta, this issue was fixed, and hackers can no longer access your phone through a hacked Instagram account. However, a few years ago, hackers could steal users' photos, messages, phone contacts, and location data through Instagram hacks.
Can your Instagram account get a virus?
A computer virus can’t infect your Instagram account directly. Instead, it will target the devices you use to access your profile. You can pick up malware by clicking malicious links or images. The best advice here is to avoid clicking on Instagram links altogether.
How do I protect my Instagram account from being hacked?
You can secure your Instagram account by avoiding suspicious links, refusing to share sensitive information, using a strong password and two-factor authentication, and installing a reliable antivirus program. Also, you should only enter your login information in the official Instagram app or website.
Bottom line
Losing your account is one of the minor consequences of an Instagram hack. Major consequences could be as dangerous as criminals using your private info to destroy your life. Apart from emptying your bank accounts, they can actually impersonate you while committing crimes. Just think about it — a “simple” thing like losing your Instagram profile can potentially land you in jail.
Each form of identity theft is extremely difficult to prove and correct. It could take years to mitigate the damage, and full recovery is never guaranteed. That’s why we recommend securing your Instagram account as much as possible.
You can use a strong password, activate 2FA, create a backup email, avoid linking any payment methods to Instagram, and enable suspicious login alerts. Finally, we advise learning to recognize phishing attacks and installing a solid antivirus program.