What to Do if My X Account Got Hacked
X Account Hacked? What to Do First, How to Secure It and Which Posts Made by the Attacker Should Be Deleted Before They Spread.
Immediate Steps to Regain Access
Step 1: Reset Your Password If your X Account Is Hacked Have a look at your login page and click on Forgot password; then fill in your email or mobile phone number. If the password was changed by the attacker, X will email you a reset link to that account's associated phone number/email. You'll have to contact X using its account recovery form, which requires listing your old email address and a number you once used for two-factor authentication, if they also changed the email or phone on file.
If you have an active session on any device then logout straight away and log back in after reseting the password. This will force the attacker to be disconnected from their sessions. Once access is regained, immediately turn on two-step verification. Opt for an Authenticator app instead of SMS — as SIM swapping is one common method that attackers use to bypass text codes. Revoke access to any other third-party apps you recognize as not belonging under Settings and privacy > Security and account access > Connected apps.
What the Attacker Might Have Posted
When an attacker gains access to your account, the intent is generally there. Some send out spammy links in posts, some do it through direct messages to your followers trying to get them to click something, and others change the profile picture and display name or handle altogether. And all of these actions are traceable. You may not even see the posts, they may come down quickly or stay in your timeline until you notice. You can recreate what the attacker posted to see how far it has spread and if your followers have seen it already.
Visit your profile and look at the posts you made when you lost access to see what the attacker posted. Any posts that they published using the account are likely clustered fairly closely around that time window, at least if they were using it for more than a few minutes. Use X (yes Im going to call it that for the indefinite future) search with from:your handle and since: date as filters to get all the content they made while you where locked out. That gives you a full list of what the attacker said, as well as replies and retweets that may be absent from your main timeline.
Deleting A Post From The Hacker
When you regain control, deleting what the attacker published is simple. To delete posts one-by-one, open each post and go to the three-dot menu > Delete. If the attacker published a lot of posts, manual deletion is slow and cumbersome. And this is where a tool like TweetSweep can help you bulk delete. If, say, you know precisely when an attacker was active, you can select the time frame and delete everything they posted during that period in one go.
If you need proof first, do not delete. If the attack is harassment, threats or a money scam make sure you screen capture or save those posts before removing them. You might need them for a police report or if you make a report to X support. Saving the posts also keeps records of what your followers are viewing. Once you got your hands on what you need, delete the posts with maximum speed. Spam or fraudulent posts are unlikely to be seen and reported if they stay up for a long time.
What They Saw From You and What You Should Share With Them
Extetnded descriptionIf they post links in spam or result message to your supporters, those supporters may now have engaged with the content. Spam links usually direct you to a phishing page or another false offer, therefore this practice puts followers who clicked them in danger. When you have gained access to the account, put a short update explaining to followers that this is a hacked account and that any odd messages or posts were not from you. Keep it short and factual. Do not give specifics on how the attack took place—because that tells attackers how your defenses worked as they are trying to give you up.
It is one of the most informative posts that are listed in your timeline, and they will remain there for as long as you do not delete them later. Even if you are not going to keep it, post it here for the warning and delete it in a week or two. With that, most of your attentive followers will have already noticed it. If your attack reaches a large number of followers, keep the notice up for a while longer. If a warning disappears right away, it can be confusing as to whether the account is still compromised.
Looking for Changes in Your Account History
More Than Your Password Can be Changed by an Attacker This allows them to edit your email address, phone number, display name, handle, bio and profile picture as well as the privacy of your account. They could have even limited posts to friends only if they sought to cover their tracks. Once you have the account, review each of the settings which controls visibility. Look for Account information where email and phone numbers are listed and confirm they belong to you. Check the Profile tab and revise any updates to your name, bio, profile picture.
Have a look at your mute and block lists too. They sometimes block followers who might see the hack in under eight seconds and they may mute people who would respond to the spam posts. For example, if you had a private account before the attacked and find it has since become public. If Yes, change it to protected. Lastly, verify the logged-in sessions you see under Security and account access. Of course, you should only see your own devices. To the right of that, you will see a list of the current sessions where your account is logged in; delete any that you don't recognise and then reset your password again if unnecessary items still appear in the session list.
Avoiding Future Hacks & The Other Side That Cannot Be Reversed
You can only reverse the posts the attacker made with your account. After someone deletes tweets, they further disappear from your timeline; however after deleting all tweets during the time frame that a hacker had access to period are depleted eternally and always susceptible to recovery attempts. Those old posts are gone if the attacker deleted them in the course of their work. The full history only lives in your archive, which you can ask X for in the app under Settings, and it only updates if we download our datas.
You are now the one controlling the settings that prevent a similar attack to happen again. Select any solid and unprecedented password ever have present in a break. Use two-factor authentication with an authenticator app. Periodically check the list of applications you have connected to Google and cancel any that are obsolete. Enable login alerts (Security) so you get a message from X every time someone signs in with a new device. Making hacking impossible, however high these levels of change are certainly not, high to the point that most attackers go on to an easier target.