Skip to content

Social media account takeover

In plain terms

Your account becomes a tool against the people close to you: it's your name, your photo, and your history that are used to write to them. The harm isn't losing the account, it's what's done with it.

Definition

Social media account takeover is gaining control of a person's authentic account, then used to approach their contacts, spread content in their name, or resell their audience.

How it works

Entry happens through the usual paths: a reused password, a fake login page reached from a message, a verification code shared over the phone. What's specific to this account is the use it's put to. The attacker has something no imitation provides: the trust already granted by hundreds of people. They write to contacts reusing the tone of previous conversations, which they can read, making their messages more credible than any fake profile. The requests resemble those of a friend or relative — a vote to support, a link to open, a code received by mistake to forward — and that last one serves precisely to hijack the contact's account in turn. The attacker's first move is to change the email address and password, which makes recovery harder as time passes.

Warning signs

  • Messages sent from your account that you didn't write
  • Contacts flagging an unusual request supposedly from you
  • An email about an address or password change you didn't request
  • Posts, follows, or mentions appearing without your action
  • A sudden logout, with a password that's no longer accepted

How to verify

Check the login history and the list of devices in the account's settings, then verify the associated email address: it's the first element changed during a takeover. Also look at sent messages, which the attacker rarely deletes entirely.

What to do

Use the social network's recovery procedure without delay, since these procedures become harder once the email address has been changed. Warn your contacts through another channel — a messaging group, a call, another network — so that requests sent in your name find no one.

If it already happened

Regain the account, then revoke sessions and authorized third-party apps, and restore the email address and recovery number. Enable two-factor authentication. Post a message flagging the requests sent during the affected period: that's what protects your contacts, and it works better than individual apologies. If someone close to you sent money, they should contact their bank immediately and file a police report of their own.

Frequently asked questions

A contact is asking me to forward a code I received by SMS.
Don't send anything. That code is the one that lets someone take control of your own account: the request comes from your contact's account, already compromised, and it's meant to compromise you in turn. Call the person to let them know.
What's the difference with a fake account under my name?
Here, your genuine account is in a third party's hands: your messages, contacts, and history are accessible to them. A fake account just copies what's public, without reading anything. The two situations are handled differently — see "social media profile impersonation" for the second.

Official sources

This article is part of the Credentials and accounts family. Last updated: 2026-09-02.