A hacked account is a time-critical problem. Every minute the attacker has access, they can change recovery details, steal sensitive data, or use your account to attack others. The right response is fast and methodical, not panicked. Here is exactly what to do in 2026 for every major platform.
What changed in 2026
- Passkeys are now widely supported. Google, Apple, GitHub, and many others support passkeys as a phishing-resistant login method. After recovery, switching to passkeys prevents most future attacks.
- AI-assisted phishing got much better. Phishing emails and fake login pages are now nearly indistinguishable from real ones. This is the primary attack vector in 2026.
- Platform recovery flows improved. Video selfie verification and government ID upload are now options on Google, Meta, and Apple — useful when all recovery contact methods are compromised.
Immediate steps (first 30 minutes)
Go directly to the official recovery URL. Never use a link in an email. Type it manually:
- Google:
accounts.google.com/signin/recovery
- Facebook/Instagram:
facebook.com/login/identify / instagram.com/accounts/recovery
- Apple ID:
iforgot.apple.com
- Microsoft:
account.live.com/acsr
Use every recovery method available. Try your backup email, backup phone number, security questions, trusted devices.
If locked out completely, use the platform's identity verification:
- Google: "Try another way" → answer security questions about account history.
- Meta: Submit government ID via the Hacked Accounts form.
- Apple: Account Recovery — verified via trusted devices or Apple Support.
Check if your email account is also compromised. If the attacker has your email, they can reset every other password. Secure the email first.
After you regain access
| Action |
Why |
How |
| Change password immediately |
Revoke attacker's credentials |
Use a unique, generated password |
| Sign out all other sessions |
Kick out active attackers |
Google: Manage devices; FB: Active sessions |
| Remove unknown connected apps |
Attackers often grant app access |
Google: myaccount.google.com/permissions |
| Change recovery email/phone |
Attacker may have added theirs |
Check and remove unknown entries |
| Enable 2FA (if not already on) |
Prevent repeat attack |
Use an authenticator app, not SMS |
| Check sent mail / posts |
See what was sent in your name |
Delete or report anything malicious |
Platform-specific recovery
Google Account:
Recovery at accounts.google.com/signin/recovery. "Try another way" unlocks multiple fallback methods including account history verification. If all else fails: submit a video selfie or ID via the form.
Facebook and Instagram:
Use facebook.com/hacked or instagram.com/hacked. Both lead to Meta's Hacked Accounts flow. Meta accepts government ID for identity-verified recovery when all contact methods are changed.
Apple ID:
At iforgot.apple.com. Recovery via trusted Apple device (iPhone, iPad, Mac) is the fastest path. If no trusted device: Account Recovery takes 1–7 days but is reliable.
Microsoft / Outlook:
At account.live.com/acsr. Submit ID for account recovery if no access codes remain.
How to prevent it happening again
- Use a password manager. Reused passwords are responsible for the majority of account takeovers. Every account gets a unique generated password.
- Enable 2FA on every important account. Authenticator app (Google Authenticator, Authy) beats SMS because SIM-swap attacks bypass SMS codes.
- Switch to passkeys where available. Passkeys are phishing-resistant — a fake login page cannot capture them.
- Be suspicious of login emails. Legitimate services never ask you to confirm your password via an email link.
Common mistakes
Waiting to act. The first thing an attacker does is change the recovery email and phone number to lock you out. Speed is everything.
Using the same password on the recovery email. If your Gmail is hacked and your recovery email uses the same password, both are gone. Password manager, unique passwords.
Trusting "account recovery" services online. No third party has special backdoor access to Google or Meta accounts. These services either do nothing or install malware.
Not checking connected apps. After an attacker adds an OAuth app to your Google account, they retain access even after a password change. Check and revoke.
What to skip
- Paying for account recovery services — fraudulent in virtually all cases. The official platforms are the only recovery path.
- Sharing your current password with "support" — legitimate support never needs your password.
- Ignoring the breach after recovery — without understanding how it happened, it will happen again.
FAQ
What if the attacker changed my recovery phone and email?
Use identity verification: submit government ID through the platform's Hacked Accounts form. Google and Meta both support this. Response time is 1–5 business days.
Can I recover an account that has been deleted?
Usually not after 30 days. Most platforms hold deleted accounts for 30 days before permanent deletion — contact support immediately if this applies.
Should I report the hack to police?
For financial fraud or identity theft, yes. For a general account takeover, file a report with your national cybercrime authority (IC3 in the US) as a record.
How do I know if my password was leaked?
Check haveibeenpwned.com — it checks your email against known data breach databases. Change any password that appears in a breach.
Where to go next
See How to set up two-factor authentication in 2026, How to remove malware in 2026, and How to secure your router in 2026.