Account recovery: proving ownership to a system that has stopped believing you
Hijacked and wrongly disabled accounts are recovered through the platform's own verification and appeal channels. The work is evidence assembly and correct escalation — never credential attacks, which are illegal and end in a permanent ban.
How does hacked account recovery work? Account recovery works by proving to the platform that you are the legitimate owner, using evidence its automated system already holds: the original signup email or phone, a device or location with a successful login history, billing records, and government photo ID where the platform verifies identity. The request goes through the platform's official recovery form. There is no back channel, and no legitimate provider has one.
Act on the first day — the reversal window is the whole game
Most major platforms keep a window during which a recent change of email address or phone number can be reversed from the original contact details. The window is commonly a few days to about a month depending on the platform. Inside it, recovery is often a single form. Outside it, the case escalates to full identity verification, which is slower and fails more often.
This is the one variable entirely within a victim's control, and it is routinely lost to the instinct to try passwords repeatedly first. Repeated failed logins from a new device add risk signals to the account, which makes the later verification review harder, not easier.
What evidence do platforms actually require?
Recovery forms are scored, not read. Supplying four strong data points in one submission beats five separate submissions with one each — and repeated submissions are themselves a negative signal.
-
Original signup details
The email address and phone number used to create the account, plus the approximate creation date. Month and year is usually enough; an exact date is stronger.
-
Device and location history
Submit the recovery request from a device and network you have used successfully before. A familiar device fingerprint carries more weight in automated scoring than anything typed into the form.
-
Government photo ID
Required by identity-verified platforms. The name must match the account name. A mismatch — a maiden name, a nickname, a business name on a personal account — is one of the most common rejection reasons and needs to be explained in the same submission.
-
Billing evidence
The last four digits of a card on file, an invoice number, or a transaction date. Paid accounts have an independent financial record tying them to a person, which is why they recover more reliably than free ones.
-
A contact channel the attacker never held
Recovery correspondence must go to an address outside the compromise. Using an email that shares a password with the hijacked account restarts the entire problem.
Containing what was posted during the compromise
Recovery and cleanup are separate problems, and the cleanup often matters more. An attacker with control of a business account typically posts scam links, messages the contact list, or changes public profile details. Those actions keep generating harm after control is restored.
- Screenshot everything the attacker posted before deleting it — this becomes the evidence package if a takedown or a fraud report is needed later.
- Revoke every third-party app authorisation. Restoring the password does not revoke tokens issued to connected applications, and an attacker-authorised app keeps its access.
- Check forwarding rules and filters on the connected email account. A forwarding rule is the most common persistence mechanism and it survives a password change silently.
- Notify contacts who were messaged, directly rather than only via a public post.
- Where scam content was indexed by search engines, the leftover cached results are handled as a content removal matter.
When recovery is not possible
Some accounts are gone, and knowing which ones early saves months. Recovery odds collapse when several of these are true at once:
- Every recovery contact detail was changed and the reversal window has closed.
- The account was created with details that no longer exist — a dead email domain, a discontinued phone number.
- There is no billing history and no verified identity on file.
- The account name never matched any ID the owner holds.
- The platform has already rejected multiple appeals with identical evidence.
In that situation the honest advice is to secure everything connected to the lost account, publicly disown it so contacts are not defrauded, and rebuild elsewhere — not to keep paying someone to re-file the same appeal.
What we will not do
Providers advertising guaranteed recovery of any account are describing credential attacks. Unauthorised access statutes in the US, UK and EU turn on authorisation from the service, not on who owns the profile, so "it's my account" is not a defence. Beyond the criminal exposure, platforms detect the intrusion and terminate the account permanently — the client pays to lose the account for good.
Related reading
- Content removal — for material posted during the compromise that is still live.
- How long content removal takes — timelines for cleaning up after a hijack.
- Reputation management — where an impersonation account has already been indexed under your name.
Questions we are asked in the first call
Can a hacked account always be recovered?
No. Recovery depends on whether you can still prove ownership through evidence the platform accepts. If the attacker changed the email, phone number, and password, removed two-factor authentication, and enough time has passed for the platform's change-reversal window to close, some accounts cannot be recovered at all. Accounts with a payment history or a verified identity on file have materially better odds because there is independent evidence tying the account to a real person.
How fast do I need to act after an account is hacked?
Within hours, not days. Most major platforms operate a reversal window — commonly a few days to about a month — during which a recent email or phone change can be undone from the original address. After that window closes the case moves to full identity verification, which is slower and has a lower success rate. Acting on the same day is the single largest controllable factor in the outcome.
Is it legal to pay someone to recover a hacked account?
Yes, when the recovery uses the platform's own verification and appeal channels with the account owner's authorisation. It is not legal for anyone to access the account by guessing, resetting, or bypassing credentials, including on your behalf and including for an account you own — unauthorised access statutes turn on authorisation from the platform, not ownership of the profile. Any provider offering to hack the account back is offering a criminal act that also results in a permanent ban.
If it happened today, start today
Send what you still have access to. You will get the recovery path for that specific platform and an honest read on the odds.