Edgemont ADVISORY Incident response Hacked account Contact

Guidance

Recovering a hacked account, and how to spot a recovery scam.

No firm can reach inside a platform and restore an account. Recovery happens through the platform's own review process, and that process is free. Anyone who tells you otherwise is selling something they cannot deliver. This page covers the free routes first, then how to tell a legitimate incident response firm from the industry that has grown up around this confusion — including how to test us against the same criteria.

Start here, and it costs nothing

Every major platform has its own account recovery flow, and it is the only route that actually restores access. Begin there before you consider paying anyone, and be aware that a paid service will usually be shepherding you through this exact process.

Use the platform's recovery flow first

Instagram, TikTok, X, YouTube, and Snap all publish a hacked-account path. If the recovery email and phone number are still yours, this frequently resolves it without anyone else involved.

Paid tiers get you a human

Meta Verified, X Premium, and TikTok's creator and business support replace the form queue with live chat. For a monetised YouTube channel, Creator Support is reachable inside Studio, and larger channels have an assigned partner manager.

Your representation is the most underused door

Talent agencies, management companies, MCNs, and media agencies often hold named partner contacts at Meta, Google, and TikTok. A representative flagging the case internally moves faster than almost anything you could buy. The same applies to a players' association, or a collective or NIL agency for a college athlete.

Brand partners have leverage too

If a campaign is live, the brand's social agency likely has a platform contact and a commercial reason to use it on your behalf.

Business accounts have a better queue

If the account sits inside a Business Manager rather than a personal profile, business support is a separate and generally more responsive channel.

If money moved, file with ic3.gov and identitytheft.gov. Insurers and some platforms will ask for a report reference, and for a wire already sent the reporting window matters in hours.

Signals that you are being scammed

They contacted you — an unsolicited direct message, reply, or comment offering to help.
They guarantee recovery, or guarantee a timeline.
They claim contacts, insiders, or a back channel at the platform.
They ask for your password, or for a two-factor code.
They want payment in cryptocurrency, gift cards, or a peer-to-peer cash transfer.
They describe themselves as an ethical hacker, or offer to hack the account back.
They ask for a small payment first, then ask for more access.
There is no company, no named person, no address, and no written scope.

The common pattern is a modest up-front fee followed by either silence or escalating requests for the credentials that are still working — which deepens the compromise rather than ending it. Nobody legitimate will ever ask you for a two-factor code.

What a legitimate firm looks like

It never asks for credentials

No passwords, no two-factor codes, not by email and not by form. Where account access is genuinely needed, it happens live with you driving your own screen.

It promises process, not outcomes

A real responder will tell you what they will do and how fast they will start, and will decline to guarantee that a platform restores anything. Certainty is the tell.

It exists on paper

A named person, a written scope, an invoice, conventional payment. Not crypto, not a handle.

Two more worth insisting on. A legitimate engagement addresses how access was gained, not just the account itself — restoring an account without closing the entry point simply hands it back. And you should receive something in writing at the end that says what happened and what remains unresolved.

Questions to ask anyone you are considering

Will you ever need my password or a two-factor code? The answer should be no.
Can you guarantee you will get the account back? The honest answer is no.
What exactly are you doing that I cannot do myself through the platform?
Who specifically will do the work, and what is their background?
What do I receive at the end, in writing?
How do you determine how they got in, not just that they are out?
What does it cost, and is it a fixed fee or an open clock?
Who do you invoice, and how do you take payment?

Ask us the same eight. Our answers are on the incident response page, and the first call is free specifically so you can establish whether paying anyone is warranted.

When hiring someone is and is not worth it

Usually not worth paying for

A single account, recovery email and phone still under your control, no extortion, no money moved, nothing else affected. The platform flow will very likely resolve this, and a paid service is mostly filling in the same forms.

Worth engaging someone

The recovery email or phone was changed. More than one account or service is affected. There is an extortion or leak threat. A device was stolen or compromised. A payment or wire is involved. The account is the business and every day dark is revenue lost. Or nobody can work out how they got in — which means it can happen again tomorrow.

One tactical point either way: do not launch a replacement account under the same name while a recovery case is open. If it starts interacting with the same audience, the platform can read the original as the impostor.

Common questions

Can a company hack my account back for me?

No, and anyone offering to is either lying or proposing something illegal. Access is restored by the platform through its review process. What a legitimate firm does is establish what happened, present a properly evidenced case to the platform, escalate through the correct channel, and close the way in that was used.

Is it a scam to pay anyone to recover an account?

Not always, but the burden is on the firm to show what it adds beyond a process you can run yourself for free. Consumer protection bodies warn against paid account recovery precisely because most of that market charges for form-filling. The distinction is whether you are buying access, which nobody can sell, or investigation and escalation, which is real work.

Someone messaged me offering to help. Should I reply?

No. Unsolicited outreach after a compromise is the single strongest scam signal, and people who monitor for public complaints about hacked accounts are the same people who target them. Legitimate firms are approached; they do not appear in your direct messages.

Do I have to give anyone my password?

Never. Not to a recovery service, not to a support agent, not to anyone claiming to be from the platform. A two-factor code request is the same answer, and is the most common way a compromise gets worse after the fact.

What does Edgemont Advisory actually do differently?

We do not sell recovery, because nobody can. We establish how access was gained and what was reached, preserve the evidence before platforms age it out, escalate a documented case through the correct channel, close the entry point, and hand over a written brief where every finding is traceable to a named source. Where the free platform route is likely to work on its own, we will tell you that on the first call rather than take the engagement.

Not sure which situation you are in.

The first call is free and exists to answer exactly that. If the platform's own process is the right answer, we will point you at it. Contact details only — no credentials, and no specifics of any demand.