On this page
Work in this order: change the password, end every other session, then turn on two-factor authentication. After that, check that the email and phone on the account are still yours, and revoke third-party app access. The step almost everyone skips is the one that matters most later — changing that same password anywhere else you used it.
Why a viewer never needs a password, and how to recognise the sites that ask, are covered in never enter your Instagram password into a viewer. This is the other half: it already happened, and the useful question is what to do in what order.
The first 10 minutes
Speed matters more than thoroughness here. Three actions, in sequence:
- Change the password from the app or from instagram.com typed by hand, never from a link in an email.
- End all other sessions in the login activity screen. A password change alone does not always evict someone already signed in.
- Turn on two-factor authentication, preferring an authenticator app over SMS, so a stolen password is no longer enough on its own.
Done in that order, an attacker holding your password is left with a credential that no longer works and a session that no longer exists.
Check the recovery paths
The professional move for someone taking an account is not to post — it is to change the recovery details so you cannot take it back. Open your account settings and confirm the email address and phone number are yours, then check your email provider for any change-of-address notice you missed.
Instagram sends a message when the email on an account changes, and that message usually contains a revert link. If you find one, use it immediately; those links expire.
Revoke what you connected
While you are in there, review the apps and websites with access to your account and remove anything you do not actively use. Some fake viewers ask for a password; others ask you to authorise an app, which quietly survives a password change because it holds its own token.
The permissions angle is worth understanding in general, and our piece on whether anonymous viewers need permissions explains why a legitimate one never needs any of this.
No login, nothing to steal
The story viewer reads public content through its own servers. There is no field for your password because there is no account involved.
The step people skip for weeks
The credential you handed over is now on a list, and lists get tried elsewhere automatically. If that password protects your email, your bank, your cloud storage or an old forum account, those are all exposed, and the email account is the worst of them because it can reset everything else.
Change the email password first, then work outward. If the same password appears in more than two places, this is the moment to move to a password manager and stop repeating one string across your life.
If you are already locked out
Go to the login screen and start the account recovery flow rather than hunting for a support address, which does not exist in the way people expect. Instagram's recovery includes identity checks — a code to a recovery contact, and in some cases a video selfie that is matched against photos on the account.
Two things help enormously and both have to be done before the fact: having two-factor enabled, and having an email address you still control on the account. Nothing else reliably substitutes for them.
The clean-up nobody mentions
Once you are back in, look at what was done while someone else had access. Check sent direct messages, since accounts are commonly used to send the same scam onward to your contacts — warn anyone who received one. Check for new posts or stories, for follows you did not make, and for changed profile links. And tell the people who got a message from you what happened; the chain stops when someone breaks it.
Common questions
What do I do first after entering my password on a fake site?
Change the password, then end all other sessions from login activity, then enable two-factor authentication. That sequence removes both the credential and any live session.
Does changing my password log the attacker out?
Not always on its own. Use the log-out-of-all-sessions control in login activity so an existing signed-in session cannot continue after the change.
Do I need to worry about other accounts?
Yes, if you reused that password. Stolen credentials get tried elsewhere automatically. Change your email password first, because it can reset everything else.
What if they already changed my email address?
Look for the change notice Instagram sends to your old address; it usually contains a revert link that expires. Otherwise start the account recovery flow on the login screen.
Can I get the account back without two-factor or my old email?
Sometimes, through the recovery flow's identity checks, including a video selfie matched to photos on the account. It is slower and far less certain.
The people behind StalkView — a privacy-first team writing honest guides to watching and saving public Instagram without leaving a footprint.