Account recovery: proving ownership to a system that has stopped believing you
Hijacked and wrongly disabled accounts are recovered through the platform's own verification and appeal channels. The work is evidence assembly and correct escalation — never credential attacks, which are illegal and end in a permanent ban.
How does hacked account recovery work? Account recovery works by proving to the platform that you are the legitimate owner, using evidence its automated system already holds: the original signup email or phone, a device or location with a successful login history, billing records, and government photo ID where the platform verifies identity. The request goes through the platform's official recovery form. There is no back channel, and no legitimate provider has one.
Act on the first day — the reversal window is the whole game
Most major platforms keep a window during which a recent change of email address or phone number can be reversed from the original contact details. The window is commonly a few days to about a month depending on the platform. Inside it, recovery is often a single form. Outside it, the case escalates to full identity verification, which is slower and fails more often.
This is the one variable entirely within a victim's control, and it is routinely lost to the instinct to try passwords repeatedly first. Repeated failed logins from a new device add risk signals to the account, which makes the later verification review harder, not easier.
What evidence do platforms actually require?
Recovery forms are scored, not read. Supplying four strong data points in one submission beats five separate submissions with one each — and repeated submissions are themselves a negative signal.
-
Original signup details
The email address and phone number used to create the account, plus the approximate creation date. Month and year is usually enough; an exact date is stronger.
-
Device and location history
Submit the recovery request from a device and network you have used successfully before. A familiar device fingerprint carries more weight in automated scoring than anything typed into the form.
-
Government photo ID
Required by identity-verified platforms. The name must match the account name. A mismatch — a maiden name, a nickname, a business name on a personal account — is one of the most common rejection reasons and needs to be explained in the same submission.
-
Billing evidence
The last four digits of a card on file, an invoice number, or a transaction date. Paid accounts have an independent financial record tying them to a person, which is why they recover more reliably than free ones.
-
A contact channel the attacker never held
Recovery correspondence must go to an address outside the compromise. Using an email that shares a password with the hijacked account restarts the entire problem.
Containing what was posted during the compromise
Recovery and cleanup are separate problems, and the cleanup often matters more. An attacker with control of a business account typically posts scam links, messages the contact list, or changes public profile details. Those actions keep generating harm after control is restored.
- Screenshot everything the attacker posted before deleting it — this becomes the evidence package if a takedown or a fraud report is needed later.
- Revoke every third-party app authorisation. Restoring the password does not revoke tokens issued to connected applications, and an attacker-authorised app keeps its access.
- Check forwarding rules and filters on the connected email account. A forwarding rule is the most common persistence mechanism and it survives a password change silently.
- Notify contacts who were messaged, directly rather than only via a public post.
- Where scam content was indexed by search engines, the leftover cached results are handled as a content removal matter.
When recovery is not possible
Some accounts are gone, and knowing which ones early saves months. Recovery odds collapse when several of these are true at once:
- Every recovery contact detail was changed and the reversal window has closed.
- The account was created with details that no longer exist — a dead email domain, a discontinued phone number.
- There is no billing history and no verified identity on file.
- The account name never matched any ID the owner holds.
- The platform has already rejected multiple appeals with identical evidence.
In that situation the honest advice is to secure everything connected to the lost account, publicly disown it so contacts are not defrauded, and rebuild elsewhere — not to keep paying someone to re-file the same appeal.
One situation sits outside recovery altogether. Where the account holder has died, the question is disposition rather than access, and Meta runs a separate documented route with its own evidence standard — set out in memorializing or deleting a deceased person’s Facebook account.
What we will not do
Providers advertising guaranteed recovery of any account are describing credential attacks. Unauthorised access statutes in the US, UK and EU turn on authorisation from the service, not on who owns the profile, so "it's my account" is not a defence. Beyond the criminal exposure, platforms detect the intrusion and terminate the account permanently — the client pays to lose the account for good.
We also do not run report campaigns against anyone else's account, which is the same trade viewed from the other end: our audit of what mass reporting an Instagram account actually does covers the tools sold for it, the theft economy they feed, and the appeal ladder the accounts they disable arrive here needing. Facebook cases arrive on a clock the other platforms do not publish, and the strike ladder Facebook actually restricts on sets out what an appeal has 180 days to answer. Telegram cases arrive with a different problem, because the tooling there takes a session file rather than a password: what a Telegram report campaign really costs the sender sets out which of Telegram's four contact addresses answers which restriction. Snapchat cases turn on a figure the other platforms do not publish, and the two-minute median Snap enforces on sets out why a report burst there costs the filer more standing than the target.
Related reading
- Content removal — for material posted during the compromise that is still live.
- How long content removal takes — timelines for cleaning up after a hijack.
- Reputation management — where an impersonation account has already been indexed under your name.
- Mass reporting an Instagram account — the audited tool supply, and the only appeal stage on the path with a published deadline.
- Instagram spam report bots — for a restriction that followed coordinated false reports rather than a compromise.
- Instagram ban services — what the paid ban trade actually sells, and the appeal evidence for a targeted account.
- Twitter mass report bots — why X sanctions the sender, and how to appeal a suspension that followed a report campaign.
- TikTok mass report bots — TikTok's own removal and reinstatement figures, and what they mean for an appeal after a coordinated wave.
- WhatsApp mass report bots — the published grievance figures behind a WhatsApp number ban, and how the Request a Review appeal is judged.
- YouTube mass report bots — what Google publishes about excluded flag volume, and the one-year window for appealing a channel termination.
- Snapchat mass reporting — the repositories audited against Snap's enforcement data, and what an appeal needs after a campaign.
- Facebook takedowns and appeals — the 30-day and 14-day windows on your own objects, and the three appeal tiers when Facebook removes something of yours.
- Instagram account takedown routes — the five report routes, the evidence each one demands, and the two that bind Meta to a deadline.
- Removing a TikTok video — which route runs on a legal deadline, which sits in a queue, and what to do when the report is refused.
- Removing personal information from Google — the three request types, for details exposed while the account was in someone else's hands.
- Telegram ban services — what the paid trade quotes per target, and the route that actually removes a channel.
- TikTok ban services — the price ladder, the legality question, and what TikTok's own enforcement data shows.
- Twitter ban services — documented prices, and why no independent record verifies a result on X.
- WhatsApp ban services — the routes sold against a number, and the published grievance data behind the real odds.
- YouTube ban services — the thresholds YouTube publishes for ending a channel, against what the trade promises.
Questions we are asked in the first call
Can a hacked account always be recovered?
No. Recovery depends on whether you can still prove ownership through evidence the platform accepts. If the attacker changed the email, phone number, and password, removed two-factor authentication, and enough time has passed for the platform's change-reversal window to close, some accounts cannot be recovered at all. Accounts with a payment history or a verified identity on file have materially better odds because there is independent evidence tying the account to a real person.
How fast do I need to act after an account is hacked?
Within hours, not days. Most major platforms operate a reversal window — commonly a few days to about a month — during which a recent email or phone change can be undone from the original address. After that window closes the case moves to full identity verification, which is slower and has a lower success rate. Acting on the same day is the single largest controllable factor in the outcome.
Is it legal to pay someone to recover a hacked account?
Yes, when the recovery uses the platform's own verification and appeal channels with the account owner's authorisation. It is not legal for anyone to access the account by guessing, resetting, or bypassing credentials, including on your behalf and including for an account you own — unauthorised access statutes turn on authorisation from the platform, not ownership of the profile. Any provider offering to hack the account back is offering a criminal act that also results in a permanent ban.
If it happened today, start today
Send what you still have access to. You will get the recovery path for that specific platform and an honest read on the odds.