# X Account Hacked and Email Changed? How to Recover It

> X account hacked in Malaysia and the email changed? Use the alert sent to your old inbox, X's hacked account form and your phone, and avoid recovery scams.

- URL: https://www.awarexone.com/research/x-account-hacked-email-changed
- Author: Md Shariar Shanaz Shuvon, Founder & CEO, AwareXone
- Published: 2026-09-29
- Topics: X, Account recovery, Malaysia
- Related service: X account recovery: https://www.awarexone.com/platforms/x

## Short answer

Open the inbox that used to be on your X account and find the email change alert X sends there. If any device is still logged in, change the password and email back, and log out other sessions. If you are locked out, try a password reset by phone, then file X's hacked account request. Never share your password.

## Summary

- X emails your previous address whenever the account email changes, so find that alert in your old inbox and keep it as proof of what happened and when.
- If you can still log in anywhere, change the password, put your own email back, log out all other sessions and revoke apps you do not recognise.
- If you are locked out, try a password reset by phone, then file X's hacked or compromised support request from the email that was on the account.
- X never asks for your password by email, Direct Message or reply, so anyone who wants your login details to recover the account is running a scam.
- X may suspend a hacked account until it is secured, and without the original email or a verified phone number X says it cannot continue.

You tried to log in to X and your password no longer works. The reset link goes to an email address you have never seen. Your handle may have changed too, and friends are asking about posts or crypto links you did not send.

You still have options, and the order matters. Your old inbox is the first place to look, because X sends a warning there when the email changes. After that, your phone number and X's hacked account support request are the official ways back.

This guide covers both cases (still logged in, or locked out), an attacker's two-factor authentication, and the scams aimed at people in this spot.

Last checked: 29 September 2026.

## What Should You Do If a Hacker Changed the Email on Your X Account?

Open the inbox that used to be on the account and find the email address change alert. X's [account security tips](https://help.x.com/en/safety-and-security/account-security-tips) say it sends one to the previous address every time the email changes. If any device is still logged in, change the password and email back straight away. If you are locked out, try "Forgot password?" with your phone number, then file X's [hacked or compromised support request](https://help.twitter.com/forms/account-access/regain-access/hacked-or-compromised) using the email that was on the account. In Malaysia, if money was lost, call 997 and your bank first.

## Is Your X Account Actually Hacked?

X's page on [compromised accounts](https://help.x.com/en/safety-and-security/x-account-compromised) lists the signs. Any one of these is enough to act:

- Posts or Direct Messages from your account that you did not send.
- Follows, unfollows or blocks you did not make.
- A notice from X that your account may be compromised, or that your account information changed when you did not change it.
- Your password stops working and X asks you to reset it.

## Which Situation Are You In?

What you can still reach decides your route. Find your row, then read the matching section.

*Common signs of an X takeover and the first step for each, at the time of writing. Screen labels vary by app version, device and region.*

| What you see | What it usually means | What to do first |
| --- | --- | --- |
| You are still logged in on the app or a browser, but settings show an email you do not know | The attacker changed the email and has not yet thrown you out | Change the password, put your email back and log out all other sessions now |
| Your old inbox has an alert that the X email was changed | The change is recent and you have a dated record of it | Keep the alert, secure that inbox, then reset or file the hacked account request |
| The login screen asks for a code from an app or key you never set up | The attacker turned on two-factor authentication | Use a logged in device if you have one; otherwise file the hacked account request |
| You cannot open the old inbox either | The takeover may have started with your email account | Recover the email account through its provider before anything else |
| The profile shows "Account suspended" | X may have suspended it because it looked compromised | Follow the prompts at login, then the suspension steps linked below |

## Still Logged In Somewhere? Lock the Attacker Out

A phone or laptop that is still logged in is the best thing you have. Do these in order on that device, before the attacker notices:

1. Change the password in Settings and privacy. X's compromised account page says to use a strong password you have not used before.
2. Put your own email back in the account settings. X's guide to [updating your email address](https://help.x.com/en/managing-your-account/how-to-update-your-email-address) says X then emails you a "Confirm now" button; tap it, or security features such as two-factor authentication stay unavailable.
3. Open "Apps and sessions". Under Sessions, choose "Log out all other sessions". X's [third-party apps page](https://help.x.com/en/managing-your-account/connect-or-revoke-access-to-third-party-apps) notes this stops further posting from those sessions, although messages already cached on the attacker's device may stay there.
4. In the same section, revoke access for every connected app you do not recognise. X says to do this and change your password if you suspect a bad app.
5. Check Security for two-factor authentication. If a method is on that you did not set up, turn it off, then enrol your own. X's [two-factor authentication guide](https://help.x.com/en/managing-your-account/two-factor-authentication) lists text message, authentication app and security key.
6. Check the phone number and handle on the profile, and change back anything the attacker altered.

Then delete posts the attacker made. X's compromised account page also suggests scanning your computer for malware, especially if strange posts continue after the password change.

## Locked Out? Your Official Route Back

Being logged out everywhere is harder, but not always final. X's help pages lead back to one of two things: the original email or a verified phone number.

1. Search the old inbox, including spam, for the email change alert. Screenshot it with the date showing. It proves the account was yours and when it was taken.
2. If that inbox has also been taken, recover it first through Gmail, Outlook or whichever provider you use. X's page on [email address access](https://help.x.com/en/managing-your-account/cant-access-my-accounts-email-address) says to contact your email provider, then request a new X password once you are back in.
3. If your phone number was verified on the account, enter it on the password reset page. The same X page says you will be offered a reset by SMS.
4. If the reset fails, file the [hacked or compromised support request](https://help.twitter.com/forms/account-access/regain-access/hacked-or-compromised). X's compromised account page asks you to use the email address associated with the account, and to include your username and the date you last had access. X then sends instructions to that email.
5. If the form asks you to verify a phone number, use the one that was on the account. X says that if the number was previously associated with the account, it will review the request and may re-add the number.

Use the email you had before the attacker's change, not their new one. X says it keeps previously used addresses for safety and security. If you are unsure which address you signed up with, our guide to [recovering accounts after losing your email, phone or 2FA](https://www.awarexone.com/research/lost-email-phone-2fa-account-recovery) helps you find old sign-up evidence.

> Warning: **No email and no verified phone.** X's email access page says that without the account's email address or verified mobile number, it is unable to continue troubleshooting, and it will not deactivate the account or free up the username. Get the old inbox or SIM back first.

## The Hacker Turned On 2FA. Can You Still Get Back In?

Attackers often switch on two-factor authentication with their own app or key, so a password reset alone no longer lets you in. What you can do depends on whether any of your devices is still logged in.

- Still logged in on a device: go to Security, then Two-factor authentication, and turn off the method you did not add. X's guide shows each method has its own switch.
- Logged out, with a backup code you saved earlier: X's [two-factor authentication help](https://help.x.com/en/managing-your-account/issues-with-login-authentication) says you can log in with the backup code, then update your settings. Codes must be used in the order they were generated.
- Logged out, with no backup code: X says to contact support. For a takeover, that means the hacked or compromised request described above.

## Why X May Suspend a Hacked Account

X's page on [suspended accounts](https://help.x.com/en/managing-your-account/suspended-x-accounts) says that if it suspects an account has been hacked, it may suspend it until it can be secured and restored to the owner. If prompts at login ask for a phone number or email confirmation, following them may unsuspend it. Otherwise, see our guide to [X suspension appeals](https://www.awarexone.com/research/x-account-suspended-appeal), or the one on [X lock screens](https://www.awarexone.com/research/x-account-locked-fix).

## How Did the Attacker Get In?

In plain terms, someone got your password, your email or a live login session. X's compromised account page names the usual causes: giving your login to a malicious app or website, a weak password, malware collecting passwords, or a compromised network.

Malaysian users often meet these as messages, in English, BM or Chinese. The wording below is illustrative, not quoted from a real message:

- A fake copyright or policy notice: "Your account will be suspended in 24 hours. Verify here." or "Akaun anda akan digantung. Sahkan di pautan ini."
- A "get verified" or "blue tick" offer that sends you to a login page that is not x.com.
- A Direct Message, even from a friend's hacked account, with an odd link: "Is this you in this video?" or "这是你吗？"

X's [fake email page](https://help.x.com/en/safety-and-security/fake-x-emails) says X only sends email from @x.com or @e.x.com, never sends attachments, and never asks for your password by email. The security tips page adds that X will never ask for your password by Direct Message or reply, and that a real X login page always sits on x.com.

## What Not to Do While You Recover

- Do not reply to accounts that comment "DM this expert, he got my account back" under your posts. That is a common pattern for recovery scams.
- Do not pay "hackers for hire" or unban sellers. Breaking into an account is not a recovery route, and they usually take the money and disappear.
- Do not share your password, any login code or a backup code with anyone, including people claiming to be X staff.
- Do not use tools that claim to switch off someone else's two-factor authentication. They are not an official route.

> Warning: **Nobody genuine needs your codes.** X, your email provider, your carrier and any honest helper can do their part without your password, login codes or backup codes. If someone asks for any of these, stop replying. If you already shared a code or paid, call 997 and your bank straight away.

## Warn Your Followers and Check Your Phone Line

Post a short warning from another account you control: your X account was taken, and nobody should click its links or send money. Our guide to [hacked accounts messaging your friends](https://www.awarexone.com/research/hacked-account-messaging-friends) has wording you can adapt.

If your phone suddenly shows "No service" or "SOS only", your number may have been moved to another SIM. Call your carrier from another phone, ask them to block the SIM and issue a replacement, and check your bank and email for SMS codes you did not request.

## If Money Was Lost or a Code Was Shared in Malaysia

Takeovers are often used for fraud, such as fake crypto giveaways or requests for money sent to your followers. The government's page on the [NSRC 997 hotline](https://www.malaysia.gov.my/en/categories/safety-and-community/cybersecurity/nsrc-997-hotline) says to call 997 within 24 hours of discovering a scam, contact the relevant bank and make a police report at the nearest police station. The hotline runs daily, 24 hours.

For the hacking itself, CyberSecurity Malaysia's [Cyber999 service](https://www.cybersecurity.my/portal-main/services/cyber999-overview) is the national point of contact for reporting computer security incidents. MyCERT's [reporting channel page](https://www.mycert.org.my/portal/full?id=9eb77829-7dd4-4180-814f-de3a539b7a01) lists an online form, email to cyber999@cybersecurity.my and 1-300-88-2999 during office hours.

## Evidence to Gather Before You File

A clear, consistent request is easier to review. Collect these before you submit, and keep copies in one folder:

- Your handle, plus the new one if the attacker changed it.
- The email address that was on the account before the change.
- The email change alert or new login alert from X, with its date and time.
- The date and time you last had access.
- The phone number verified on the account, if any.
- Screenshots of the attacker's posts or messages, and of any suspension notice.

## Lock It Down Once You Are Back In

Recovery is not finished until the same trick cannot work twice. X's security tips suggest a short setup:

- A long, unique X password stored in a password manager, and an equally strong one for the email on the account.
- Two-factor authentication with an authentication app or security key, plus a backup code saved somewhere offline.
- "Password reset protection" switched on under Security, so a reset needs your email or phone number.
- Two-step login on the email account itself, since whoever holds that inbox can reset X.

> Note: **X makes the final decision.** Only X can restore an X account. Reviews can take time, and an account where the attacker controls the email, the phone and the two-factor method may not come back. Nobody outside X can promise otherwise.

## When Expert Recovery Help Makes Sense

Most people can follow the steps above alone. A second look can help when the account carries a business or a large following, when the email and phone were both taken, or when a support request has already been closed without a fix. SocialSafe by AwareXone, our recovery service, reviews the case first and tells you honestly which official route is still open, if any. We work only through X's own forms and processes and never ask for your password or codes. See how [X account recovery](https://www.awarexone.com/platforms/x) works, and our [Trust Center](https://www.awarexone.com/trust) for what we will not do.

## Frequently Asked Questions

### Can I recover my X account if the hacker changed the email and phone number?

Possibly, if you still control the original email or the phone number that was verified on the account. File the hacked or compromised request from the original email. Without either, X says it cannot continue troubleshooting.

### How long does X take to respond to a hacked account request?

X does not publish a response time. Watch the inbox you used for the request, including spam, and reply only to messages that come from X.

### Does X have a phone number or live chat for hacked accounts in Malaysia?

The X help pages we checked send hacked accounts to online support forms and do not list a phone line. Treat anyone on social media or messaging apps who claims to be an X agent able to restore your account as a scammer.

### Will X tell me what the hacker did on my account?

X's email help says it keeps a history of email addresses used on the account, which you can see by downloading Your X Data once you are back in. Check posts, Direct Messages and connected apps as well.

### Can AwareXone get my X account back?

No one outside X can restore an X account. SocialSafe by AwareXone can review your case and help you prepare the official request, but X makes the decision.

## Official sources

- [X Help Center: Help with my compromised account (read 29 September 2026)](https://help.x.com/en/safety-and-security/x-account-compromised)
- [X Help Center: Hacked or compromised account support request (linked from the compromised account page, 29 September 2026)](https://help.twitter.com/forms/account-access/regain-access/hacked-or-compromised)
- [X Help Center: About account security (read 29 September 2026)](https://help.x.com/en/safety-and-security/account-security-tips)
- [X Help Center: Help with email address access (read 29 September 2026)](https://help.x.com/en/managing-your-account/cant-access-my-accounts-email-address)
- [X Help Center: How to update your email address (read 29 September 2026)](https://help.x.com/en/managing-your-account/how-to-update-your-email-address)
- [X Help Center: About third-party apps and log in sessions (read 29 September 2026)](https://help.x.com/en/managing-your-account/connect-or-revoke-access-to-third-party-apps)
- [X Help Center: How to use two-factor authentication (read 29 September 2026)](https://help.x.com/en/managing-your-account/two-factor-authentication)
- [X Help Center: Help with two-factor authentication (read 29 September 2026)](https://help.x.com/en/managing-your-account/issues-with-login-authentication)
- [X Help Center: About suspended accounts (read 29 September 2026)](https://help.x.com/en/managing-your-account/suspended-x-accounts)
- [X Help Center: About fake X emails (read 29 September 2026)](https://help.x.com/en/safety-and-security/fake-x-emails)
- [MyGOV Malaysia: NSRC 997 Hotline (read 29 September 2026)](https://www.malaysia.gov.my/en/categories/safety-and-community/cybersecurity/nsrc-997-hotline)
- [CyberSecurity Malaysia: Cyber999 Cyber Incident Response Center (read 29 September 2026)](https://www.cybersecurity.my/portal-main/services/cyber999-overview)
- [MyCERT: Reporting Channel (read 29 September 2026)](https://www.mycert.org.my/portal/full?id=9eb77829-7dd4-4180-814f-de3a539b7a01)

---

AwareXone is an independent Malaysia-based provider, not affiliated with any platform. The platform makes the final decision on every account. AwareXone never asks for passwords, OTP codes, backup codes or session cookies.
