A padlock fastened through heavy chains, drawn in blue binary digits on a dark background, beside the headline Hacker Turned On Two-Factor? Get Back In.

Hacker Turned On Two-Factor Authentication? What to Do

A hacker turned on 2FA and the login code goes to their device? How to recover Instagram, Facebook, TikTok, X or Google, with Malaysia reporting steps.

11 min read
Short answer

The login code goes to the hacker's device, so your password alone will not get you back in. Secure your email first, then look for the platform's email about the change and use its secure link. Next, use the platform's hacked account route from a device you have used before. Only the platform can return the account.

Summary
  • When a hacker turns on two-factor authentication, the login code goes to their phone or app, so typing your password alone will not get you back in.
  • Secure your email account first, because whoever controls that inbox can keep resetting your social account and receiving the platform's security emails.
  • Use the platform's own hacked account route, such as instagram.com/hacked or facebook.com/hacked, from a phone or computer you have used on that account before.
  • Look for the platform's email about the change and use its secure or reverse link, because that link was sent to you and not to the attacker.
  • Nobody outside the platform can remove a hacker's two-factor setting, so ignore recovery offers and never share a password, login code or backup code.
  • Only the platform can confirm you are the owner and return the account, and some accounts are not recovered even when every step is followed.
Table of contents15 sections
  1. 01What Should You Do If a Hacker Turned On Two-Factor Authentication?
  2. 02How Did the Hacker Lock You Out With Your Own Security Feature?
  3. 03Where Is the Code Going? Match Your Screen to a Next Step
  4. 04First Ten Minutes: Secure the Email and Phone
  5. 05Instagram: The Secure My Account Link and instagram.com/hacked
  6. 06Facebook: facebook.com/hacked From a Familiar Device
  7. 07TikTok: Hacked Account Signs and Report a Problem
  8. 08X: The [email protected] Email and a Support Request
  9. 09Google: Account Recovery and Suspicious Sign-In Methods
  10. 10Evidence to Gather Before You Contact Support
  11. 11Mistakes That Slow Recovery Down
  12. 12If You Shared a Code or Lost Money in Malaysia
  13. 13After You Get Back In: Make the Account Yours Again
  14. 14When a Case Review Makes Sense
  15. 15Frequently Asked Questions

You type your password and the app asks for a six-digit code. The code goes to a phone number you do not recognise, or to an authenticator app you never installed. Someone got into your account and switched on two-factor authentication so that you are the one locked out.

The short answer: a hacker's 2FA does not end your options, but it does mean the normal login screen will not help. Secure your email first, then use the platform's hacked account route, from a device you have used on the account before. Those routes exist for exactly this situation.

This guide explains what happened, the recovery route for Instagram, Facebook, TikTok, X and Google, what to prepare, the mistakes that slow recovery down, and the paid "2FA removal" offers to ignore.

Last checked: 29 September 2026.

#What Should You Do If a Hacker Turned On Two-Factor Authentication?

Stop trying to guess or request codes on the normal login screen. Open the email account linked to your social account, change its password and check it for a security email from the platform about a change you did not make; many of these carry a link to secure the account or reverse the change. Then go to the platform's hacked account route, such as instagram.com/hacked or facebook.com/hacked, on the phone or computer you normally use. If money was lost or a code was shared in Malaysia, call your bank or the NSRC on 997 as well. No outside service, AwareXone included, can switch off a hacker's 2FA for you.

#How Did the Hacker Lock You Out With Your Own Security Feature?

Two-factor authentication asks for a second proof after the password. Instagram's help page on two-factor authentication says it requires a code when someone logs in from a device Instagram does not recognise. That protects you when you set it up. When an attacker sets it up, it protects them.

The usual sequence is simple. The attacker gets your password, often through a fake login page or a message pretending to be the platform. They log in, add their own phone number or authenticator app as the 2FA method, and sometimes change the email and password too. Now any new login, including yours, needs a code that only reaches their device.

Facebook lists this exact symptom. Its page on recovering a hacked account names "problems logging in" or a two-factor method, such as an authentication app, that "isn't working" among the signs of a hack, alongside emails about an added or removed phone number or email address that you did not make.

#Where Is the Code Going? Match Your Screen to a Next Step

What the login screen shows tells you what the attacker changed. The wording varies by app version, language and region, so match on the key words rather than the exact sentence.

Common screens after a hacker enables 2FA, based on platform help pages at the time of writing.
What you seeWhat it usually meansWhat to do first
A code sent to a phone number ending in digits you do not recogniseThe attacker added their own number as the text message 2FA methodSecure your email, then use the platform's hacked account route; do not keep requesting codes
A request for a code from an authentication app you never set upThe attacker linked their own authenticator appUse the hacked account route from a device you have logged in on before
A code sent to your own number, but it never arrives and your phone shows "No service"Possibly a SIM swap: someone moved your number to their SIMCall your carrier from another phone straight away, then secure your email
A code request and your password also failsThe attacker changed the password as well as 2FALook for the platform's security email in your inbox and use its secure or reverse link
You are still logged in on one phone or computerYour old session may still be active thereUse that device now to review security settings and remove unknown methods and devices

#First Ten Minutes: Secure the Email and Phone

The email account is usually the master key. Whoever controls it can reset your social passwords and receive the security emails that let you reverse a takeover. Check it before anything else.

  1. Change the email account's password from a device you trust, and sign out other sessions if the email service offers it.
  2. Look for forwarding rules and filters you did not create. Google's page on securing a hacked account tells Gmail users to remove labels, filters or forwarding rules they did not set up.
  3. Search the inbox, spam and trash for emails from the platform about a new phone number, a new 2FA method, a password change or an email change.
  4. Check your phone. If it shows "No service" and codes to your own number stopped arriving, call your carrier from another phone and ask whether your SIM was replaced.
  5. If you cannot get into the email either, recover that first. Google's account recovery tips say to use a device, browser and location where you usually sign in, and to answer every question rather than skipping.

If your number was moved to someone else's SIM, the problem is wider than one app. Our guide to SIM swap attacks in Malaysia covers what to ask your carrier and which accounts to check next.

Instagram's page on a hacked profile says that if you received an email from [email protected] telling you your email address was changed, you may be able to undo it by selecting "secure my account" in that message. Its hacked account hub sends anyone who cannot log in to www.instagram.com/hacked.

  1. Check your inbox for the [email protected] email and use "secure my account" if it is there.
  2. If that fails, tap "Forgot password?" on the login screen and request a login link to your email or phone.
  3. If the link does not work, request support from Instagram on a mobile device and give a secure email address only you can access.
  4. Instagram may ask for the email or phone you signed up with and the device you used, or, for an account with photos of you, a video selfie turning your head in different directions.

Instagram says it never contacts you about account security through Direct Messages, and its page on recent emails sent from Instagram lists the official sending domains, including @mail.instagram.com. If the attacker also swapped the email and phone, our guide to an Instagram account hacked with the email and phone changed goes further.

#Facebook: facebook.com/hacked From a Familiar Device

Facebook's hacked account page tells you to visit www.facebook.com/hacked on a device you have used to log in to Facebook before. When the email on the account changes, Facebook says it sends a message with a special link to the previous email address, and that link can reverse the change and secure the account.

If you are still logged in anywhere, Facebook says you can open "Where you're logged in" in Settings, select a device or location you do not recognise and log it out. Its page on how two-factor authentication works shows where the methods live: Accounts Center, then "Password and security", then "Two-factor authentication". Remove any method you did not add, then set up your own and save the recovery login codes.

#TikTok: Hacked Account Signs and Report a Problem

TikTok's page on a hacked account lists the signs: a changed password or phone number, a changed username or nickname, videos deleted or posted without permission, and messages you did not write. Its steps assume you can still open the app: reset the password, link your phone number, and remove unknown devices under "Security & permissions", then "Manage devices".

At the time of writing, that page does not describe what to do when you are fully locked out. TikTok's web Report a problem form is the official place to describe the takeover. Include your username, the date you lost access and what changed.

#X: The [email protected] Email and a Support Request

X's page on compromised accounts says that if you receive an email from [email protected] about an email address change, you can reverse it with the link in that email. If you still cannot log in after a password reset, X says to submit a support request using the email address associated with the compromised account.

#Google: Account Recovery and Suspicious Sign-In Methods

Google's page on a hacked Google Account says to use the account recovery page if someone changed your password or recovery phone number. It lists 2-Step Verification being turned on or off without your knowledge, or its methods changing, as settings to correct immediately.

Google also says that when it detects a suspicious sign-in method, it disables it and notifies you, and you have 30 days from that notice to confirm you added it; otherwise it is deleted. If the attacker added their own method, that notice works in your favour. Google says it never asks for your password or verification codes by email, phone call or message.

#Evidence to Gather Before You Contact Support

  • Screenshots of the login screen showing where the code is being sent, with the date and time.
  • Every security email from the platform about the takeover: new phone, new 2FA method, password change, email change.
  • Your username, profile link, and the email and phone number you originally signed up with.
  • The type of device you used when you created the account, which Instagram may ask for.
  • The rough date and time you last had normal access, and when you first noticed the lockout.
  • A few calm, factual sentences describing what happened, ready to paste into a form.

#Mistakes That Slow Recovery Down

  • Requesting code after code on the normal login screen. Each one goes to the attacker, not you.
  • Trying recovery from a new phone, a friend's laptop or behind a VPN, instead of your usual device.
  • Leaving the email account unsecured, so the attacker can reset your social account again after you get it back.
  • Ignoring the platform's security emails, or deleting them, when they carry the link that reverses the change.
  • Getting back in and not removing the attacker's phone number, authenticator app and logged-in devices.

#If You Shared a Code or Lost Money in Malaysia

Deal with the money first. The NSRC's FAQ on the NFCC website tells fraud victims to contact their bank's 24-hour hotline or the NSRC on 997 as soon as they discover the fraud, then make a police report at the nearest station. It also says NSRC, PDRM, MCMC, BNM and banks will not ask for your password, PIN, TAC or OTP.

A phishing page or fake login link that led to the takeover can be reported to CyberSecurity Malaysia's Cyber999 incident response centre, which accepts reports by online form, email, phone and its mobile app. Warn friends and family from a channel you still control, because hacked accounts are often used to ask contacts for money or codes.

#After You Get Back In: Make the Account Yours Again

  1. Remove every 2FA method you did not add: phone numbers, authenticator apps, security keys.
  2. Log out all devices and sessions you do not recognise.
  3. Change the password to one you have never used anywhere else.
  4. Add your own 2FA, preferably an authentication app, which Instagram recommends because several devices can receive codes.
  5. Save your backup or recovery codes offline, somewhere an attacker with your phone cannot reach.

If the attacker's 2FA is gone but you have also lost your own old email or phone, our guide to recovering an account without your email, phone or 2FA covers that different problem.

#When a Case Review Makes Sense

Most people can work through the routes above alone. Only the platform can confirm ownership and return the account, and some accounts are not recovered even when every step is followed. A second opinion helps when the email, phone and 2FA were all taken at once, when the account carries a business, or when the official forms keep looping. SocialSafe by AwareXone, our recovery service, looks at the case before anything is agreed and uses the same official routes you can use, prepared properly. You can read how we approach account security and recovery, and our Trust Center explains what we never ask for, starting with your password and codes.

#Frequently Asked Questions

Can a hacker turn on two-factor authentication on my account?
Yes. Once someone knows your password and logs in, they can add their own phone number or authenticator app as the second step. After that, every new login needs a code that reaches their device.
Why is my login code being sent to a number I don't recognise?
The attacker most likely added their own number as the text message 2FA method. Stop requesting codes and use the platform's hacked account route instead.
Will resetting my password remove the hacker's 2FA?
Usually not on its own, because the new login still asks for the second step. Use the platform's secure or reverse link from its security email, or its hacked account route, then remove the attacker's method once you are in.
Can I recover my account if the hacker changed the email and turned on 2FA?
Often, yes. Instagram, Facebook and X send a message to the previous email address when the email changes, and that message can reverse it. If it does not, the platform's identity check is the next step.

Official sources

Need help with your account?

Tell us the platform and what you have already tried. We review the case first, work only through official platform processes, and never ask for your password, OTP or backup codes. The platform makes the final decision. Related service: Account security.