Quick answer: When your social media account is stolen, the first hour is the most critical time, because in this window the attacker tries to permanently take over the account by changing the password, email and phone number. What to do in the first hour, in order: if you still have access, immediately change the password and log out of all sessions; enable two step verification; check the email and phone linked to the account and revert them if changed; if you cannot log in, start account recovery from the platform's official recovery page; warn your contacts against money or code requests coming from your account; collect evidence with screenshots and timestamps. Panicking and clicking random links makes things worse; acting in order and calmly maximizes your recovery chance.

The moment you notice your social media account is stolen, a countdown begins. The first thing an attacker does after taking over an account is to close your return paths: they change the password, the registered email and the phone number. If you act before these changes are complete, your chance of recovering the account is much higher. This article gives the steps for the first hour in a clear order, independent of platform.

The first hour: step by step emergency response

The order below puts the most critical step first. If you still have access, start from step 1; if not, from step 4.

Minute Step Why critical
0 to 5 Change password, log out all sessions Drops the attacker's active session
5 to 10 Enable two step verification Blocks new logins
10 to 20 Check and revert email and phone Regains recovery paths
20 to 30 Revoke connected apps Closes the back door
30 to 45 Warn your contacts Stops the fraud
45 to 60 Collect evidence with screenshots and dates For recovery and legal process

The essence of this table is: first throw the attacker out, then lock the doors, and last protect the evidence. If the order breaks, the attacker can get back in.

If you still have access

If you can still log in, you are in the strongest position. Without losing time, change the password to a strong and unique one, then log out of all active sessions from settings; this instantly drops the attacker's open session. Right after, enable two step verification. An authenticator app or a passkey should be preferred over SMS, because a SIM swap attack can capture SMS codes. For choosing the right method, see the two step verification comparison.

If you cannot log in

If the attacker has already changed the password, start the process from the platform's official account recovery page. Every platform has a recovery flow and usually asks for the registered email, phone or identity verification. For platform specific steps, move to Instagram account recovery, Facebook account recovery and WhatsApp account recovery; for a general framework, see the social media account recovery guide. Key point: make recovery requests only from the platform's official address; fake recovery sites appearing in search results are a new trap.

Warn your contacts

Compromised accounts are mostly used to ask your contacts for money or a verification code in your name. Until your account is recovered, send a short warning to your circle through a trusted channel: do not respond to money or code requests coming from my account. This stops the most common form of harm after an account takeover. The same warning covers familiar messages coming to you; an urgent money request from a contact may mean their account has been compromised.

Collect evidence

While recovery is in progress, document what happened. Take screenshots with date and time of change notification emails, unfamiliar login alerts and fake messages sent from the account. These records both strengthen the request you make to the platform and, if needed, form the basis of the legal process within the digital evidence and chain of custody framework. We detailed the path to follow if the account cannot be recovered in the social media account cannot be recovered, digital evidence and legal process article.

Understand how it was stolen and close the root

Recovering the account is not the end of the job. If the same open door stays open, the account is stolen again. The most common entry path is a phishing page or a reused password from another leak. Using a unique password for each account, a password manager and a passkey closes the root cause. For the right setup, see the password, 2FA and passkey security guide.

The KAOS and DSET approach

DSET offers, more than individual account recovery consulting, a security approach that protects organizations' social media and digital assets. Our local AI engine KAOS scans an organization's external surface to detect leaked credentials, open sessions and weak configurations, and reports every finding with a working proof, without false positives. The goal is to close the root cause not after an account is stolen but before it is.

Frequently asked questions

What should I do first? If you still have access, immediately change the password and log out of all sessions; this drops the attacker's active session. Then enable two step verification. If you cannot log in, start the process from the platform's official account recovery page. Do not panic into recovery sites in search results; they are usually a second trap.

Is changing my password enough? Usually no. Changing the password is the first step but the attacker's open sessions and the apps they linked to the account may continue. So after changing the password, log out of all sessions, revoke connected apps and enable two step verification. Only these three together truly secure the account.

Am I responsible for the fraud messages sent from my account? If your account was compromised, the sent messages were not sent with your will. Still, to reduce harm it is important to warn your contacts and document the incident. Screenshots and platform notifications support both your recovery request and, if needed, your legal process.

Sources

To build your organization's social media and digital asset security and be prepared for takeover scenarios, contact DSET. We provide security and incident response consulting from our Ankara Hacettepe Teknokent laboratory.