
LinkedIn Hacked and Email Changed: How to Get Back In
LinkedIn hacked and the email changed? Use Forgot password, then "Can't access this email?" to add a new email and verify your ID. Steps for Malaysia.
The reset now goes to the attacker's email, so use LinkedIn's lost email route. Choose Forgot password, then Can't access this email, then Don't have access to any of these, and enter a new email only you control. LinkedIn then asks for a photo of a government ID. Secure your own email first and report the takeover.
Summary- If someone changed the email on your LinkedIn, the password reset now goes to them, so you need LinkedIn's route for members who cannot reach their email.
- On the sign in screen choose Forgot password, then Can't access this email, then Don't have access to any of these, and enter a new email you control.
- LinkedIn then asks for a photo of a valid government ID through its verification partner Persona, and sometimes a selfie, before it restores access.
- Secure your own email account first and use the Report Unauthorized Account Access or Changes form from LinkedIn's compromised account page.
- LinkedIn has no phone support and never asks for your password, so ignore anyone offering to recover the account for payment or asking for a code.
- LinkedIn makes the final decision and some cases take time; once you are back in, remove the attacker's details and turn on two-factor authentication, ideally with an authenticator app.
Table of contents14 sections
- 01What Do You Do When Your LinkedIn Is Hacked and the Email Is Changed?
- 02Which Situation Are You In?
- 03If You Can Still Sign In: Lock the Attacker Out
- 04If You Are Locked Out: The Lost Email Route
- 05How LinkedIn's ID Verification Works
- 06Evidence Checklist Before You Verify
- 07Why Your Verification Code Is Not Arriving
- 08Secure Your Email Before Anything Else
- 09After You Get Back In: Clean Up
- 10Fake LinkedIn Emails and Appeal Messages
- 11If Money Was Lost or Your Profile Scammed Others in Malaysia
- 12Mistakes That Slow a LinkedIn Recovery
- 13When Expert Recovery Help Makes Sense
- 14Frequently Asked Questions
You try to sign in to LinkedIn and your password no longer works. You tap Forgot password, and the code goes to an email address you have never seen. Or you still have access, but LinkedIn has emailed you about a sign in from a new device, and your headline now advertises something you did not post.
You can usually still get back in. LinkedIn has a route for members who cannot reach the email on their account: you give it a new email address and prove who you are with a government ID. At the same time, report the takeover to LinkedIn and lock down your own email so it cannot happen twice.
This guide covers both situations, the ID check, missing codes, and what to do in Malaysia if the attacker used your profile to scam others.
Last checked: 29 September 2026.
#What Do You Do When Your LinkedIn Is Hacked and the Email Is Changed?
Go to the LinkedIn sign in page, choose "Forgot password", enter your old email or phone, and when LinkedIn asks for the code, choose "Can't access this email?" and then "Don't have access to any of these?". Enter a new email address that only you control, then verify your identity with a photo of a valid government ID. LinkedIn's page on having no access to your email address lists these steps and says LinkedIn will process your information and contact you. Report the takeover through the form on LinkedIn's compromised account page as well, and include your profile URL if you have it.
#Which Situation Are You In?
Find the row that matches your screen, then follow the matching section below. Wording can vary by app version and region.
| What you see | What it usually means | Your route |
|---|---|---|
| A security email about a sign in from a new device or browser that was not you | Someone has your password and is trying the second step, or has already passed it | Reset the password now, sign out other sessions, report it |
| You can sign in, but posts, messages or profile details changed without you | Someone else is inside the account right now | Change the password, end sessions, check emails and phones, submit the report form |
| Your password stopped working, but the reset code still reaches your email or phone | The attacker changed the password but not your contact details | Reset the password with the code, then secure the account straight away |
| The reset code goes to an email or phone you do not recognise | The attacker replaced your contact details | Forgot password, "Can't access this email?", "Don't have access to any of these?", then ID verification |
| The two-factor code never arrives, or your authenticator no longer works | The attacker may have changed 2FA, or your own phone or app changed | See the section on missing codes below |
#If You Can Still Sign In: Lock the Attacker Out
Act while your session still works. LinkedIn's compromised account page asks you to submit the Report Unauthorized Account Access or Changes form, then take these steps immediately:
- Change your password to one you use nowhere else, not even on your email.
- Turn on two-factor authentication.
- Review your active sessions and sign out of anything you do not recognise.
- Check every email address and phone number on the account, and remove any that are not yours.
- Secure the personal email accounts tied to LinkedIn, including resetting their passwords.
Sessions live under the Me icon, then "Settings & Privacy", then "Sign in & security", then "Where you're signed in". LinkedIn's page on seeing where you're signed in says each session shows the device, browser, IP address and an approximate city. Choose "Sign out of all these sessions" on desktop or "End these sessions" in the app, then confirm with your password. Check connected third party apps under "Partners & services" too.
#If You Are Locked Out: The Lost Email Route
Use this when every reset lands in the attacker's inbox. LinkedIn's no access to email page gives these steps:
- On the sign in screen, select "Forgot password".
- Enter the email or phone on the account (try your old email first) and select "Next".
- When asked for the verification code, select "Can't access this email?".
- If LinkedIn offers a list of emails or phone numbers, and none are yours any more, select "Don't have access to any of these?".
- On a desktop, scan the QR code on screen with your phone. This step does not appear if you started on mobile.
- Enter the new email address you want on the account. You can also add your profile link, which is optional but helps.
- Verify your identity with an image of a valid government issued ID. LinkedIn then processes it and contacts you.
Why not just use the report form? At the time of writing, LinkedIn's help forms usually send a logged out visitor to the sign in page, which is exactly where you are stuck. The lost email route starts from the sign in screen, so start there and file the report once you are back in.
#How LinkedIn's ID Verification Works
LinkedIn uses Persona, an outside identity verification provider, to confirm you are the rightful owner. Its page on verifying your identity to recover access says Persona asks for a digital ID or a clear photo of a valid government issued ID card, driving licence or passport, and in some cases a photo of yourself to match your face to the ID portrait. Accepted documents vary by country, and library or school cards are not accepted. For most Malaysians that means a MyKad, a driving licence or a passport, but choose from the list Persona shows for Malaysia.
You need a smartphone to take the photo. LinkedIn says Persona shares data only after you tap "Yes, share", that LinkedIn gets a redacted copy of the ID showing just your name and face, not your ID number or biometric data, and that the data is generally deleted within 14 days.
#Evidence Checklist Before You Verify
A rejected photo or a mismatched name costs days. Prepare these before you start the flow:
- A valid, unexpired ID, photographed flat in good light with all four corners visible and no glare over the text.
- The name on your LinkedIn profile, written down exactly as it appeared before the hack, so you can explain any difference from your ID.
- Your profile URL, from an old email signature, CV or a colleague's browser.
- Every email address and phone number you ever used on LinkedIn.
- Dated screenshots of LinkedIn security emails you received.
- A short note of what happened: when you noticed, what changed, what the attacker sent.
#Why Your Verification Code Is Not Arriving
Missing codes are often the first sign of a takeover, and sometimes just a changed phone. LinkedIn's page on two-factor authentication says codes arrive by text message or authenticator app, and that a signed in phone may get a sign in prompt instead. Work through the likely causes:
- The code goes to an email or phone the attacker added. Use the lost email route above rather than requesting more codes.
- You replaced or reset your phone. LinkedIn's authenticator app page says the authenticator link is tied to each device and app install. From any device still signed in, turn 2FA off and on again with the new app. With no active session, contact LinkedIn support.
- You got a security email but did not sign in. LinkedIn's page on two-factor notification emails says it sends one for each sign in from a new device or browser, and if it was not you, reset your password right away.
A Malaysian check worth doing: if your phone suddenly shows no service around the time of the hack, call your carrier from another phone and ask whether a replacement SIM was issued on your number. Text message codes follow the SIM. That is one reason LinkedIn recommends an authenticator app as the preferred 2FA method.
#Secure Your Email Before Anything Else
Your inbox is the master key. LinkedIn's compromised account page lists the ways accounts are usually taken: a login left open on a shared or public computer, an old email or phone on the account that was recycled or compromised, or a password reused on another site that was phished. Change your email password, sign out its other sessions, delete forwarding rules or filters you did not create, and turn on two-factor authentication there too. Our guide to securing your social media accounts in Malaysia walks through that inbox check for Gmail and Outlook.
#After You Get Back In: Clean Up
LinkedIn can undo some of what the attacker did. Its page on compromised account cleanup says that once you regain access, a request form lets you ask it to move the attacker's messages to recipients' spam or label them with a warning, withdraw invitations not yet accepted, and remove posts or comments shared during the takeover. The email notification of an invitation cannot be withdrawn.
Then review recent connections, follows and posts, as LinkedIn suggests. Attackers often send fake job offers or investment links to your network, so warn contacts from another channel not to click anything "you" sent. Our guide to a hacked account messaging your contacts has wording you can adapt.
#Fake LinkedIn Emails and Appeal Messages
Attackers often get in with a fake LinkedIn email, then keep going with fake "policy violation" comments. LinkedIn's page on phishing content names three sender addresses that are genuine: [email protected], [email protected] and [email protected]. It also shows fake comments urging you to appeal to avoid permanent suspension. Real LinkedIn emails carry a security footer with your name and headline. When in doubt, open LinkedIn directly instead of clicking, and forward suspicious emails to [email protected].
LinkedIn's page on recognising scams also warns about job offers that ask for ID photos early or push you to WhatsApp or Telegram. In Malaysia these often arrive in English, Malay or Chinese as "work from home" offers.
#If Money Was Lost or Your Profile Scammed Others in Malaysia
If you or your contacts sent money, or shared banking details on a fake page, call the National Scam Response Centre on 997. The government's NSRC page asks victims to call within 24 hours of discovering the scam so accounts and transactions can be blocked, then contact the bank and lodge a police report. Keep your screenshots and LinkedIn emails for that report.
To report the phishing site or the incident itself, CyberSecurity Malaysia runs Cyber999, the national point of contact for computer security incidents, which accepts reports by online form, email, phone and mobile app.
#Mistakes That Slow a LinkedIn Recovery
- Requesting code after code to an address the attacker now controls, instead of choosing "Can't access this email?".
- Using your old, possibly compromised inbox as the new recovery email.
- Uploading a blurred, cropped or expired ID photo.
- Opening a new LinkedIn account while you wait, which splits your history and can confuse the case.
- Paying a stranger who promises to get the account back faster.
- Getting back in but leaving the attacker's email, phone or connected app on the account.
If LinkedIn restricted the account rather than handing it to someone else, the route is different; see our guide to a restricted LinkedIn account appeal. For the same problem on other platforms, our social media account recovery guide for Malaysia covers Facebook, Instagram and TikTok.
#When Expert Recovery Help Makes Sense
If you have used the lost email route, submitted your ID and filed the report, you have done what LinkedIn asks. A second opinion helps when the ID check keeps failing or the account is taken again after recovery. SocialSafe by AwareXone is AwareXone's recovery and account security service, and we are based in Malaysia. We review your situation first and use only LinkedIn's own processes. Our account security service explains what the review covers, and our Trust Center sets out what we will never ask you for.
#Frequently Asked Questions
Will LinkedIn delete the messages the hacker sent from my account?
How long does LinkedIn take to restore a hacked account?
Is it safe to send my IC to LinkedIn?
Can I call LinkedIn to recover my account?
Why did I get a LinkedIn security email when I did not sign in?
Can AwareXone get my LinkedIn back for me?
Official sources
- LinkedIn Help: Report a compromised account (read 29 September 2026)
- LinkedIn Help: No access to email address (read 29 September 2026)
- LinkedIn Help: Verify your identity to recover account access (read 29 September 2026)
- LinkedIn Help: Two-factor authentication overview (read 29 September 2026)
- LinkedIn Help: Notification emails for two-factor authentication (read 29 September 2026)
- LinkedIn Help: Authenticator app overview (read 29 September 2026)
- LinkedIn Help: See where you're signed in (read 29 September 2026)
- LinkedIn Help: Compromised account cleanup (read 29 September 2026)
- LinkedIn Help: Phishing content (read 29 September 2026)
- LinkedIn Help: Security footer message in LinkedIn emails (read 29 September 2026)
- LinkedIn Help: Recognize and report scams (read 29 September 2026)
- LinkedIn Help: Contact LinkedIn customer support (read 29 September 2026)
- Malaysian government: NSRC 997 hotline (read 29 September 2026)
- CyberSecurity Malaysia: Cyber999 overview (read 29 September 2026)
Need help with your account?
Tell us the platform and what you have already tried. We review the case first, work only through official platform processes, and never ask for your password, OTP or backup codes. The platform makes the final decision. Related service: Account security.




