Instagram account takeovers rarely involve anything exotic. They come down to a password that was weak or already leaked somewhere else, a login from a device you never noticed, a message that looked official but wasn't, or an app you handed your credentials to and forgot about.
The nine steps below each close one of those doors, ordered so the biggest risk reduction comes first.
About the sources on this page. The settings, paths and rules below come from Instagram's Help Centre and Meta's own newsroom, and every section links to the exact page it came from. Two claims come from outside Meta and are labelled where they appear: Check Point Research, for how often Instagram is impersonated, and Masaryk University's cybersecurity team, for what a password manager actually does. SocialGuardian is our own product — where it appears it is marked as a promotion, and the only thing it claims to do is back up your content.
The 30-second version
- Turn on two-factor authentication and save your backup codes.
- Make your Instagram password long, unique, and not one you've used anywhere else.
- Look at every device currently logged in, and evict the ones you don't recognise.
- Run Security Checkup if anything looks wrong.
- Assume any DM about your account is a scam — Instagram doesn't send those.
- Revoke third-party apps you don't trust.
- Keep a copy of your content somewhere Instagram can't lock you out of.
What actually gets Instagram accounts taken over
Instagram itself flags an account as at risk in three situations: your password is weak, your password may have been exposed or compromised by an outside source, or your account is synced with an unauthorised third-party app. The password-reuse case is the common one — you used the same password on another site, and that site had the breach, according to Instagram.
The other big vector is phishing: a suspicious message or link asking for your personal information, often claiming your account will be banned or deleted if you don't act, as Instagram describes it.
That isn't hypothetical. In Check Point Research's Q2 2024 Brand Phishing Report, Instagram re-entered the top 10 most impersonated brands in phishing attacks — 10th place, 0.7% of brand-phishing events — for the first time since 2022, with researchers observing fake Instagram login pages built specifically to harvest credentials.
Every step on this page protects the account. None of them protects the work inside it — for that you need a copy that doesn't live on Instagram. SocialGuardian backs up your posts, stories and videos automatically, from just your public @handle. Start a 30-day free trial
Step 1 — Turn on two-factor authentication
Instagram calls two-factor authentication "the single most effective step to protect your account from hackers," and says it turned 2FA on by default for creator accounts — so if you have one, check that you didn't turn it off at some point, per Instagram's security guidance.
Here's the part that trips people up: 2FA does not ask you for a code every time you open the app. It requires a code if there's a login attempt from a device Instagram doesn't recognise, according to Instagram's Help Centre. Day to day, on your own phone, you won't notice it.
To set it up: More → Settings → See more in Accounts Center → Password and security → Two-factor authentication.
There's a second benefit that isn't obvious from the settings screen. With 2FA on, you get an alert whenever someone tries to log in from a device or web browser Instagram doesn't recognise. The alert tells you which device tried and where it's located, and you can approve or deny the request immediately from a device you're already logged in on, as Meta explains. That turns an attempted takeover into a notification you can kill with one tap.
Which 2FA method should you choose?
When you set up two-factor authentication, Instagram asks you to choose one of three security methods — and email is not one of them, per Instagram.
| Method | What Instagram says | Worth knowing |
|---|---|---|
| Authentication app | Recommended by Instagram | Apps like Duo Mobile or Google Authenticator; multiple devices can receive the codes |
| Text message (SMS) | Supported | Codes arrive by text to your confirmed number |
| Supported | You have to turn on the text message method first |
If you have no strong preference, take Instagram's own recommendation and use an authentication app.
Step 2 — Save your backup codes
If you lose access to your phone or email address and can't get login codes, a backup code is what gets you back in, says Instagram. Generate them when you enable 2FA and store them somewhere that isn't the phone they're protecting.
Don't mark "Trust this device" on a public or shared computer. Trusted devices skip the 2FA code on later logins — which is exactly the protection you just turned on.
Step 3 — Fix your password
Instagram's published password rules are specific, so here they are without embellishment. Your password must be at least six characters, but Instagram recommends at least eight for higher security, using a combination of numbers, letters and special characters. It should be different from the passwords you use for other accounts, like your email or bank account, and you should avoid easily guessable information such as your birthday or phone number — that's Instagram's own guidance.
Instagram's security page adds two more rules: use a combination of at least six numbers, letters and special characters (like !$@%) and try to avoid repetition, and never give your password to someone you don't know and trust. It also recommends using a third-party password manager, naming LastPass and 1Password, in the same help article.
If you're not sure why a password manager helps: it stores and encrypts your login credentials so you only need to remember one strong master password, generates secure passwords, and fills them in automatically at login — according to Masaryk University's cybersecurity team, a source outside Instagram. That's the practical cure for the password reuse that gets accounts flagged in the first place.
Changing your password does more than change your password: once you update it, you're logged out of all other devices, per Instagram. If someone else had a session open, that session dies.
Step 4 — Check where you're logged in
You can view a list of devices that have recently logged into your Instagram account at any time. If you don't recognise a recent login, you can log out of that location or device and tell Instagram the login wasn't you, as the Help Centre describes.
Two routes to the same list:
- Settings → Accounts Center → Password and security → "Where you're logged in"
- Settings → Login Activity
For each login you can confirm This Was Me or mark This Wasn't Me — and marking a login as "This Wasn't Me" triggers a password reset. You can also log out of any device remotely. Do this before you change your password, so you know what you're looking at.
Step 5 — Run Instagram's Security Checkup
Security Checkup is a dedicated flow for accounts that may have been hacked. Launched in July 2021, it walks you through checking login activity, reviewing profile information, confirming the accounts that share login information, and updating account recovery contact information such as phone number or email, according to Meta's newsroom.
It's the fastest way to cover Steps 1, 4 and 6 in a single pass if you suspect something already happened.
Step 6 — Learn what a real Instagram message looks like
This is the single most useful thing on this page, because it makes most phishing fail on sight:
Instagram will never send you a DM about your account. Messages claiming your account is at risk of being banned or is violating policies are scams. If Instagram wants to reach you about your account, it does so via the "Emails from Instagram" tab in your settings — the only place you'll find direct and authentic communication from Instagram in the app, per Meta.
That gives you a one-step verification for any alarming message: open Settings, check the "Emails from Instagram" tab, and see whether the message is there. If it isn't, it isn't from Instagram.
For emails, you can confirm the sender is affiliated with Meta by checking the address, which may include [email protected], [email protected], @fb.com, @meta.com or @account.meta.com. Don't trust messages demanding money, offering gifts or threatening to delete or ban your account, and never click suspicious links or reply with your password, social security number or credit card information — Instagram's phishing guidance covers all of this.
If you've already been phished: reset your password, log out of devices you don't own, and report the strange email to [email protected].
Step 7 — Revoke third-party apps you don't trust
Be careful when you authorise any third-party app, and never share your login information with an app you don't trust. If you give an app your login information — whether with an access token or by handing over your username and password — it can gain complete access to your account, Instagram warns.
To clear out the ones you're unsure about, revoke access to any suspicious third-party apps at instagram.com/accounts/manage_access, which is the route Instagram gives for hacked and at-risk accounts.
Services that promise followers, likes or "growth" in exchange for your Instagram login are asking for exactly the access Instagram warns about. A legitimate tool never needs your password.
Step 8 — Log out on devices you share
Log out of Instagram when you use a computer or phone you share with other people, and don't check the "Remember me" box when logging in from a public computer — it keeps you logged in even after you close the browser window, says Instagram.
Step 9 — Keep a copy of your content outside Instagram
Steps 1 through 8 protect access to the account. None of them protects the thing that actually took you years to make.
Instagram does let you take your data with you: go to Accounts Center → Your information and permissions → Export your information and export to your device or to an external service. Exporting is a password-protected process — and it may take up to 30 days for Instagram to email you the export link, according to Instagram.
Up to 30 days is fine for a planned archive. It is not fine as your recovery plan on the day you get locked out, because you request the export after you've lost access, which is exactly when you can't.
A standing backup runs before the bad day, not after it. SocialGuardian automatically backs up your posts, stories and videos — plus Reels, captions, metadata and follower lists — from Instagram and seven other networks, using nothing but your public @handle: no password, no OAuth, no "log in with Instagram." Set it up in about a minute
If your account is already hacked
Start at instagram.com/hacked on your desktop or mobile browser to secure the account, and make sure your email account is secure too — anyone who can read your email can probably also access your Instagram account, per Instagram.
From there, Instagram's recovery guidance gives you several routes, and it's worth knowing all of them before you need them:
- Check your email for a message from
[email protected]. If the attacker changed the email on your account, that message may let you undo the email change. - Request a login link to your email address or phone number via "Forgot password" so Instagram can confirm you own the account.
- Request a security code or support if the login link doesn't reach you.
- Verify your identity with a video selfie. If you request support for an account with photos of you, you'll be asked to record a video selfie turning your head in different directions. The video is never visible on Instagram and is deleted within 30 days.
If you can still log in, work through this list instead — same source:
- Change your password, or send yourself a password reset email (instagram.com/accounts/password/change/).
- Turn on two-factor authentication.
- Confirm your phone number and email address in account settings are correct.
- Check Accounts Center and remove any linked accounts you don't recognise.
- Revoke access to any suspicious third-party apps.
Recovering an account is one problem. Getting your posts back is another — and if the account is gone, so are they, unless a copy exists elsewhere. SocialGuardian keeps a safe, independent copy so you can download or restore in one click. Protect your archive free for 30 days
High-risk accounts: Instagram's Advanced Protection
Some Instagram accounts are treated as particularly vulnerable to fraud and hack attempts — Meta Verified subscribers, business owners, politicians, journalists and advertisers. For these, two-factor authentication isn't optional: Instagram's Advanced Protection makes it mandatory, and if you haven't enrolled within the given grace period, your account will be locked until you complete enrolment, according to Instagram. The available methods are the same three: authentication app (recommended), SMS, or WhatsApp.
If you're in one of those categories, enrol before the grace period runs out rather than discovering the lock.
Quick reference: where every setting lives
| What you want to do | Where to go | Source |
|---|---|---|
| Turn on two-factor authentication | More → Settings → See more in Accounts Center → Password and security → Two-factor authentication | |
| See devices logged into your account | Settings → Accounts Center → Password and security → "Where you're logged in", or Settings → Login Activity | |
| Check whether a message is really from Instagram | Settings → "Emails from Instagram" tab | Meta |
| Revoke third-party app access | instagram.com/accounts/manage_access | |
| Change your password | instagram.com/accounts/password/change/ | |
| Export your Instagram data | Accounts Center → Your information and permissions → Export your information | |
| Secure a hacked account | instagram.com/hacked | |
| Report a phishing email | [email protected] |
The one habit worth keeping
Security settings are a one-time job you should re-check twice a year: 2FA still on, no unfamiliar devices in the login list, no third-party apps you don't recognise, password still unique to Instagram.
The backup is the part that has to keep running on its own, because the day you need it is the day you can't set it up.
SocialGuardian has backed up 50M+ posts for 1,200+ creators, brands and agencies — private to your account, exportable anytime, with end-to-end SSL and EU/GDPR compliance. No password. No OAuth. No "log in with Instagram." Start your free trial