X-Autopilot

X account hacked? How to get it back

X account hacked: secure your email first, reset the password, then revoke the sessions and app tokens the attacker still holds. The order matters.

X-Autopilot Team··7 min read
On this page · 9 sections

The short version

  • Secure the inbox first. Password resets land in your email, so if the attacker still controls that mailbox they will simply reset your X account back.
  • Try Forgot password at x.com from a device and network you have signed in from before. If the email was changed, try the reset by phone number instead.
  • If self-service fails, file X's hacked-or-compromised form under Regain access. There is no phone support, and reported waits run days to weeks.
  • Changing your password does not end live sessions or revoke third-party app tokens. Kill both under Settings, Security and account access, Apps and sessions, or you can get posted from again.
  • Nobody can guarantee recovery. Treat any DM or ad offering a paid 'X recovery service' as the second attack, not the fix.

Quick answer

If your X account was hacked, work in this order: secure the email inbox attached to the account, then reset your X password at x.com from a device you have used before, then log out of all other sessions and revoke every connected app you do not recognise. If the password reset fails because the attacker changed your email, file X's hacked-or-compromised form under Regain access. Skipping the sessions-and-apps step is why people get their account back and lose it again a week later.

Last updated: September 2026

The order matters more than the steps

Most guides to a hacked X (formerly Twitter) account hand you the same four bullets: reset the password, check your email, contact support, turn on 2FA. The bullets are right. The sequence is what people get wrong, and the wrong sequence costs you the account twice.

Two things drive that. First, your X password reset is only as strong as the mailbox it goes to, so resetting X while the attacker still reads your email is a race you lose. Second, a password change does not sign anybody out or cut off an app that already holds a token for your account. Here is the version that accounts for both.

Step 1: lock the email and phone before you touch X

Go to the email account attached to your X profile and change its password now. Turn on two-factor authentication there. Check the mail rules and forwarding settings while you are in, because a common trick is a filter that quietly forwards or deletes anything from X so you never see the reset and alert messages.

Do the same for the phone number if you can. SIM-swap attacks exist, and a carrier PIN is a cheap defence. Only once the inbox is genuinely yours again does an X reset stick.

Step 2: get back in

Three routes, in order of how likely they are to work.

SituationWhat to do
You are still logged in somewhereChange the password immediately from that session, before the attacker locks you out. Settings and privacy, Your account, Change your password.
You are locked out, email still yoursGo to x.com, click Forgot password, and reset using your email, phone or @username. Do it on a browser, device and network you have signed in from before.
Attacker changed the emailTry the reset by phone number first. Attackers often swap the email and forget the phone, and the SMS code still lands with you.
Email and phone both changedSelf-service is done. File X's form for a hacked or compromised account under Regain access, and expect a wait.

When you file, give X the things only the owner knows: your @username, the email and phone that used to be on the account, roughly when you lost access, the last thing you remember posting, and whether the account has Premium. Watch the spam folder for the reply.

Two honest notes. There is no phone number for X support, so anything claiming to be one is a scam. And recovery write-ups from this year report a wide spread on timing: often the same day when you still hold the email, several business days once the form is involved, and one to two weeks when identity has to be verified (Guard.io, Jan 2026). X publishes no guaranteed turnaround.

Step 3: kick out every session and revoke every app

This is the step the ranking pages skip, and it is the one that decides whether the hack is over.

Changing a password does not end other live sessions, and it does not revoke a third-party app that already holds an OAuth token for your account. X's own guidance treats revoking app access as a separate action from changing your password (X Help). If somebody got in through a sketchy "free followers" app or a fake analytics tool, that token is still live after your reset, and it can keep posting, DMing and following.

So do both, in one sitting:

  1. Settings and privacy, Your account, Security and account access, Security, Apps and sessions, Sessions. Read the list: device, browser, last active, rough location. Tap Log out of all other sessions.
  2. Back one screen, open Connected apps. Revoke every app you do not use or do not recognise. Revoke generously. A legitimate tool just asks you to reconnect.
  3. Change the password again afterwards if the attacker was signed in while you did step 1.

That screen is worth a visit every few months even when nothing is wrong. We walk through it in the X login guide, along with the switcher and the 2FA settings you will need next.

Step 4: undo what they did

Attackers usually want your audience, not your posts. Check, in this order:

  • Posts and replies, including deleted-then-reposted spam and crypto replies under big accounts.
  • DMs sent, which is where the attack spreads to your contacts. Tell anyone who got a link from you that it was not you.
  • Following list for accounts you did not follow, and blocked list for people the attacker blocked to hide the mess.
  • Profile: name, @handle, bio, header, birth date and the link in bio. A changed handle is a common step so the account is harder to find.
  • Email, phone and connected Google or Apple sign-in under Account information, to make sure they still point at you.
  • Payouts and subscriptions if you monetise, since that is the actual prize on a larger account.

If you want a clean record of what the account looked like before, download your X archive once you are back in, and keep it. It is also the fastest way to see what changed.

One thing worth separating out: a hacked account and a suspended account are different problems with different forms. If X locked the account rather than an attacker, X account suspended covers the appeal path instead.

Step 5: close the door

  • Unique password. Password reuse is the single most common way X accounts fall, because the breach happened on some other site. A manager makes this free to do.
  • Two-factor authentication, under Security and account access, Security. An authenticator app beats SMS, since SMS is the one a SIM swap defeats. Save the backup codes offline.
  • Password reset protect, on the same screen, so a reset needs more than your @username.
  • Audit connected apps on a calendar reminder, not on vibes.
  • Slow down on links. The 2026 phishing kits are good: a fake copyright-strike DM, a fake verification form, a fake brand deal with a login page that looks exactly like x.com. Type x.com yourself instead of clicking through.

What nobody can promise you

Anyone selling a guaranteed X account recovery is selling you a second incident. There is no back channel, no priority queue you can buy, and no hacker-for-hire who can undo it. The DMs and ads that appear the moment you post "my account was hacked" are hunting people in exactly that state.

The honest picture: if you still control the email, you will very likely be back in within the hour. If the attacker changed the email, the phone and the password, you are dependent on X's review, and some accounts do not come back. Everything in this guide is about improving the odds and cutting the damage, not a certainty.

That same instinct applies to how you use the account afterwards. Your logged-in session cookie is effectively your account, so anything that stores or proxies it, including cloud tools, shared "multi-account" browsers and broad-permission extensions, becomes another way in. We explain that trade-off in local vs cloud X automation, and it is why X-Autopilot runs from your own browser session on your own Mac rather than holding your login in the cloud.

Bottom line

An X account hacked today is usually recoverable, and the order is what makes it stick: email first, then the password reset from a device X already trusts, then sessions and connected apps, then the cleanup, then 2FA and a unique password so it does not happen twice. Do the sessions-and-apps step even if everything looks calm. It is the quiet one, and it is the reason a lot of people get their account back and then lose it again.

Frequently asked

Answers indexed by Google + AI assistants.

How do I recover a hacked X account?+

Secure the email account first, then go to x.com, click Forgot password, and reset using the email, phone number or username still attached to the account. Once you are in, change the password, log out of all other sessions, revoke unknown connected apps, and turn on authenticator-app 2FA. If the reset fails, file X's account recovery form for a hacked or compromised account.

What if the hacker changed my email and phone number?+

Self-service reset stops working, so the recovery form is the route. Attackers often change the email but forget the phone number, so try the reset by phone first. When you file, include your @username, the old email and phone, roughly when you lost access, and anything that shows the account is yours.

Does changing my X password log the hacker out?+

Not on its own. A password change does not end other live sessions or revoke the third-party apps holding a token for your account. Both are separate steps under Settings and privacy, Security and account access, Apps and sessions.

How long does X take to respond to a hacked account report?+

There is no published guarantee and no phone support. Recovery write-ups from 2026 report anything from a few hours when you still control the email to one to two weeks when X has to verify identity, with the form itself typically taking several business days (Guard.io, Jan 2026).

Can someone still post from my account after I reset my password?+

Yes, if they left a connected app or an open session behind. That is the most common reason people get hacked, recover, and then get posted from again the same week. Revoke apps and sessions before you consider the job done.

How do I stop it happening again?+

Use a unique password no other site knows, turn on two-factor authentication with an authenticator app rather than SMS where you can, enable password reset protection so the reset flow demands more than your @username, and audit connected apps every few months.

Related searches
x account hackedhow to recover a hacked x accounttwitter account hacked what to dohacker changed my x email and passwordx account compromised recovery formsomeone is posting from my x accounthow to log out a hacker from xx account recovery timex account compromisedtwitter account hackedx password resetx two factor authenticationrevoke third party app access xx account recoveryx login problem
DY
Deepak YadavBuilding X-Autopilot

Product designer and indie hacker. Runs the agent on his own X account every day and writes up what the data shows, including when it's inconvenient.

Follow on X →
Try X-Autopilot.
$199 once. No subscription, no monthly bill. Real Chrome on your Mac.
See pricing
Free PDF · the X Growth Playbook

The exact playbook we use to grow on X

The bio that converts, the daily reply loop, the posting cadence, and the tool stack, in one no-fluff PDF. Drop your email and it's yours.

No spam. Unsubscribe anytime.

Free tools

Try it yourself.

All free X tools →
Keep reading

Related posts.