My X (Twitter) Account Was Stolen: Recovery Guide
When your X (formerly Twitter) account is stolen the recovery path is the password reset and the hacked account recovery form. Password and removing connected apps if you have access, ownership proof if you cannot log in, protecting against crypto scams and closing API access.
Quick answer: When your X, formerly Twitter, account is stolen, the way to recover it is the password reset flow on the login screen and X's account recovery support form. If you still have access, immediately change the password, remove unfamiliar sessions and connected apps in the apps and sessions section of security settings, and enable two step verification with an authenticator app. If the attacker also changed the email, fill in X's hacked account recovery form; X verifies your identity with your old email or phone. X accounts are especially targeted to spread crypto scams, so after recovery it is critical to revoke connected apps and review API access; otherwise the account is taken over again through an app.
X, formerly Twitter, causes large harm when taken over because of its fast and broad reach: your account can instantly be used to spread a crypto scam or phishing. This article explains the way to recover an X account and to secure it again afterward, step by step. Read it together with the first hour guide for general emergency response.
X account recovery steps
| Situation | What to do | Channel |
|---|---|---|
| You still have access | Change password, remove sessions, enable 2FA | Settings, Security |
| Password changed, email intact | Password reset email | Login screen |
| Email also changed | Hacked account recovery form | X support form |
| Connected app back door | Revoke app permissions | Apps and sessions |
The essence of this table: if you have access you drop the attacker in seconds; if not, X's support form is the only correct recovery path.
If you still have access
If you can log in, act fast. From settings and security, change the password to a strong and unique one. Then go to the apps and sessions section under security and account access; close all unfamiliar sessions and revoke unfamiliar connected apps. In X takeovers the attacker often leaves access through a third party app. Right after, enable two step verification with an authenticator app; it is more secure than an SMS code because a SIM swap attack can capture the SMS.
If you cannot log in
If the attacker changed the password, use the password reset flow on the login screen; X sends a reset link to the email or phone linked to the account. If the attacker also changed the email, fill in X's hacked account recovery support form. X asks for your old email or phone and account information to verify the account is yours. This process follows the same account takeover and recovery logic: first ownership is proven, then access is given back.
Crypto scams and protecting your audience
X accounts are especially valuable for spreading crypto scams: the attacker shares a fake giveaway or investment opportunity from your account and redirects your followers to a wallet or link. So until you recover your account, warn your audience from another channel. This trap increasingly combines with deepfake fake video and the QR code trap. For brand accounts this is a corporate incident; see the corporate social media account takeover article.
After recovery, close the root
Recovering the account is half the job. Review connected apps and API access; on X a broad permission given to an app can remain a back door even after the password changes. Assume the entry likely came from a phishing page or a reused password, and switch to a unique password and a passkey. For the right setup, see the password, 2FA and passkey security guide.
If it cannot be recovered
If the X support form yields no result, you need to collect evidence and prepare for the legal path. Document change notifications, login alerts and fake posts. You can find the path to follow in the social media account cannot be recovered, digital evidence and legal process article, and the chain of custody rules in the digital evidence and chain of custody article.
The KAOS and DSET approach
DSET offers a security approach that protects organizations' brand and social media assets. Our local AI engine KAOS scans the external surface, leaked credentials and over privileged connected apps to detect takeover risks, and reports every finding with a working proof, without false positives. The goal is to close the root cause before an account is taken over and turned into a crypto scam.
Frequently asked questions
Where do I recover my X account? Start from the password reset flow on the login screen; X sends a reset link to the email or phone linked to the account. If the attacker also changed the email, fill in X's hacked account recovery support form. X asks for your old email or phone and account information to verify ownership.
I changed my password but the account still posts strange things, why? Most likely the attacker left access to a third party app. On X a permission given to an app stays valid even after the password changes. From the apps and sessions section in settings, revoke all unfamiliar apps; only after this is the account truly secured.
Why are X accounts a target for crypto scammers? Because X provides fast and broad reach; a fake giveaway or investment opportunity shared from a compromised account reaches many people quickly. So after recovery, closing connected apps and warning your audience is critical. Tell your audience not to trust any crypto call coming in your name.
Sources
- X Help Center, hacked accounts: https://help.x.com
- DSET Cyber Security and Digital Forensics Services: https://dset.com.tr/hizmetler
To protect your X and corporate social media assets against takeover, contact DSET. We provide security consulting from our Ankara Hacettepe Teknokent laboratory.
Kimliğinizi doğrulayın
Yetkilendirilmiş erişim alanı. Tüm giriş denemeleri kayıt altına alınır.