Instagram Just Got Hacked: What to Do Now

Thousands of Instagram users have reported that their accounts have been hijacked over the past few weeks. The attacks involve users being locked out of their accounts with their email addresses changed to .ru domains, Mashable reports. 

Credit: Shutterstock

(Image credit: Shutterstock)

The account hijackers seem to have been able to disable two-factor authentication (2FA) on at least one user's account. The user told Mashable that Instagram alerted him to this change via email, but that he didn't see the email message in time to take action.

The account hijackers have changed many of the victims' avatars to animated characters from Disney and Pixar films, and deleted their bios. However, there haven't been reports of deleted photos or other suspicious activity on the compromised accounts, an indication that the attackers may plan to use them as spam bots or as components of a future attack.

MORE: Here's the One Gmail Setting You Should Activate Now

What should you do? Because the Mashable piece didn't specify whether this was happening to iPhones, or to Android phones, or both, we don't really know exactly how these account takeovers are happening. It may be that the affected users reused their Instagram credentials for other accounts, and that those accounts had their credentials exposed in the massive LinkedIn or Yahoo data breaches of the past few years.

The best thing to do right now to is to change your Instagram password to something strong and unusual and — this is very important — to make sure that password is not used for any other account. A password manager will help a lot with that.

In any case, it's a very good idea to have two-factor authentication enabled on your Instagram account, and to keep a close eye out for any email message saying that 2FA has been disabled — and to try to lock down the account right away if you get that message.

The bad news is that Instagram's 2FA implementation at the moment uses only SMS text-based notification messages, which is the weakest kind and the kind most likely to be stolen by SIM hijackers who, well, seem to be interested mainly in stealing Instagram accounts right now. (It's getting worse, though — Reddit itself was hacked earlier this month via a SIM hijack that targeted site administrators.)

Frankly. this is pretty sloppy on Instagram's part. It should let users have more secure forms of 2FA, such as authenticator apps or USB security keys. Facebook lets you do both — there's no reason its corporate cousin Instagram shouldn't as well.

Even though Instagram's 2FA is kind of weak, though, it's better than not having 2FA. You should also make sure that you aren't providing your Instagram credentials to any suspicious third-party apps or websites.

A number of affected Instagram users have had trouble getting their accounts back. One user told Mashable that the email Instagram sent in response to their complaint led to broken links. The account recovery process, once an email has been changed, is largely automated, and users are reporting being locked out for days, unable to contact Instagram.

Instagram stated in a blog post that it has "dedicated teams helping people secure their accounts," and that it is working on implementing a more secure method of two-factor authentication.

TOPICS

Monica Chin is a writer at The Verge, covering computers. Previously, she was a staff writer for Tom's Guide, where she wrote about everything from artificial intelligence to social media and the internet of things to. She had a particular focus on smart home, reviewing multiple devices. In her downtime, you can usually find her at poetry slams, attempting to exercise, or yelling at people on Twitter.

Latest in Social Media
Elon Musk next to the X logo for the social media network that used to be called Twitter
X was down — live updates on outage Musk blames on ‘massive cyberattack’
Bluesky logo with X logo in the background
Flashes is a brand new Instagram alternative — and it’s basically Bluesky for images
Instagram app on iPhone
Instagram was down — live updates on the quick outage
elon musk in front of image of earth from space
Elon Musk reportedly exploring buying TikTok — Bytedance says 'pure fiction'
Instagram logo on iPhone with Instagram website in background.
Instagram now lets you schedule DMs — here's how to do it
TikTok displayed on a smart phone with a USA flag in the background
Google and Apple warned by Congress to be ready to remove TikTok from app stores — here's the date
Latest in News
iPhone 16 Pro vs iPhone 16 Pro Max in hand showing displays
Forget iPhone 17 — iPhone 18 could get this huge upgrade
The new Husqvarna iQ series robot lawn mower.
Husqvarna’s new robot mowers offer GPS for less
Rendered images of rumored foldable iPhone.
Foldable iPhone report just revealed key details — here's what we know
NYTimes Connections
NYT Connections today hints and answers — Sunday, March 23 (#651)
NYT Strands on a cellphone
NYT Strands today — hints, spangram and answers for game #385 (Sunday, March 23 2025)
Nintendo Switch 2
Nintendo Switch 2 rumored specs — here’s what we know so far
  • shanah_backman
    I was one of these accounts that got hacked they changed my email so I couldn't reset my password and disabled my facebook log in option facebook support took a week to send me a link to reset my password after a week of communicating with them only for the link not to work I finally got a message from Instagram today with my account restored I have a private profile not sure why they would want anything on my account kind of feel iffy about using Instagram now I have already stated to take down photos which I'm sure were copied by who ever hacked my account good luck to those trying to get theirs back up and running
    Reply