Recovering a Hacked X Account: 5 Frequently Asked Questions
Start here if you still have access
If you can log in, do four things in order: change the password, restore the recovery email and phone to ones you control, revoke every third-party app permission, and turn on two-factor authentication. That sequence stops the attacker from walking back in.
If you are fully locked out
Use the account recovery flow and verify your identity. Have former emails and your signup period ready. Manual review can take a few days, so start it as early as you can and avoid paying any scam that promises instant recovery.
After you get it back
Review what was posted during the takeover and delete the attacker's ads. Audit authorized apps, confirm the recovery email and phone were not changed away, then enable two-factor authentication if it is still off.
Lower the odds next time
A unique strong password plus two-factor authentication removes most takeover risk. Add two habits: do not click unfamiliar login links, and review authorized apps every few months. For a wider plan, our guide to backup codes and the passkey FAQ cover the stronger options.
When to contact X support directly
If recovery stalls for more than a week, or if the attacker changed the account email to an address you cannot reach, open a support ticket with the former login email and any purchase receipts. Proof of past activity shortens the wait far more than vague descriptions ever will, so gather screenshots of old tweets and billing emails before you write in.
Put this on a calendar
Recovery is easier when you notice fast. Set a recurring reminder to check login devices and authorized apps every quarter. The first sign of trouble is usually a device you do not recognize, and catching it early turns a nightmare into a ten-minute fix. Worried about what the attacker saw? Run a free on-device footprint check to see what personal details your old tweets already expose.
Frequently Asked Questions
How do I know if my account was hacked?
Typical signs: ads or links you never posted, unfamiliar locations in the login devices list, a suddenly invalid password, or a changed recovery email or phone number. Any one of these is a warning.
What is the first thing to do if I can still log in?
Change the password immediately, restore the recovery email and phone to ones you control, revoke all third-party app permissions, and turn on two-factor authentication.
What if I am completely locked out?
Use X account recovery to verify your identity and reset access. Have former emails and the signup period ready; manual review can take a few days.
What should I do after recovery?
Review posted content, delete anything the attacker sent, audit authorized apps, confirm the recovery email and phone were not changed away, then enable two-factor authentication.
How do I lower the odds of being hacked again?
Use a unique strong password, turn on two-factor authentication, avoid unfamiliar login links, and review authorized apps regularly. Those steps stop most account takeovers.
Check your own X/Twitter footprint
Free on-device scan. Your archive never leaves your computer.
Start Free CheckRelated Reads
How to Enable Two-Factor Authentication on X (2026 Guide)
Turning on two-factor authentication on X is the first line of defense for your account. This guide covers why 2FA matters, how to enable it, authenticator app vs SMS, and how it fits your digital footprint cleanup.
Phishing DMs That Pretend to Be X Support: Seven Signals and What to Do
These messages do not attack your technical setup. They attack your sequence. You follow the steps once and the account is gone. Seven signals you can check one by one, why the messages look credible, and what to do after you clicked.
Logging Out Everywhere Is Not Enough: X Session Revocation Explained
Logging out of all devices only clears one kind of credential. Browser sessions, OAuth grants to third-party apps and legacy API tokens are three separate things, and access survives as long as any one of them is live. Here is how to tell them apart, the order to revoke in, and what to re-check afterwards.