Skip to main content
My Consumer Finance

How to lock down social media after a scam attempt

Privacy, password, MFA, and tagging checklist for Facebook, Instagram, X, TikTok, and LinkedIn after a phishing or romance-scam attempt.

Reviewed September 2026.

After a phishing click, romance pitch, or fake “support” chat, social profiles are often the next harvest: photos of your kids, employer, vacation dates, and pet names that double as password-reset answers. This checklist hardens Facebook, Instagram, X (Twitter), TikTok, LinkedIn, and similar apps. Credential theft basics: Phishing and account takeover. Broader consumer fraud patterns: Credit and debt scams. If SMS codes are in play, fix the phone number too: SIM-swap defense.

First 30 minutes

  1. From a trusted device, change the password on the hit account; make it unique in your password manager.
  2. Change the email password that receives reset links for that account.
  3. Turn on app-based or hardware MFA; remove unknown phones and sessions.
  4. Review logged-in devices and log out anything you do not recognize.
  5. Check email forwarding filters and “authorized apps” / OAuth connections; revoke strangers.

If the scammer already posted as you or DMed friends for money, warn those contacts in a separate channel (Signal, phone call) and report the account takeover to the platform.

Privacy settings that cut scam intel

SettingSafer choiceWhy
Friend / follower approvalManual approveStops mass scrape accounts
Who can see birthdate, city, employerOnly you or close friendsReduces KBA-style guessing
Who can tag youFriends + reviewStops fake tagged photo lures
Past posts visibilityLimit old public postsHides vacation and family patterns
Location / Exact location featuresOffReduces “I’m nearby, send cash” scripts
Public contact infoRemove phone/email from AboutCuts SIM-swap and spear-phish data

Romance-scam money rails still need bank reporting: Romance scam money movement and Report to FTC and bank.

Worked example: fake Meta “ads manager” DM

Luis gets an Instagram DM: “Your ad account is suspended. Verify here.” He taps, enters password + SMS code, then loses the account. Recovery:

  1. Uses Facebook/Meta’s official hacked-account flow from a browser he types himself (not the DM link).
  2. Changes Gmail password; switches MFA from SMS to an authenticator app.
  3. Sets Instagram DMs from non-followers to filtering; turns off public email in About.
  4. Tells three friends who got “Luis needs gift cards” follow-up messages to ignore them.
  5. Secures the bank login (app MFA, password, recent sessions) and reviews account activity because SMS codes were used there; contacts the bank if a code or credentials may have been exposed. Separately, places bureau freezes if identity data may enable new-credit fraud (freezes do not stop takeover of an existing bank login) (ATO after a breach).

Content and tagging hygiene

  • Pause public check-ins for a few weeks after a scare.
  • Strip SSN, license, and passport images from old posts and Drive links (Protect your SSN).
  • Avoid “verify your account by posting a code” challenges.
  • Make family photo albums friends-only if they show school names and jersey numbers.
  • On LinkedIn, limit profile visibility to fields you need for job hunting; recruiters do not need your personal cell in the summary.

Checklist

  1. Reset passwords on social + email; enable non-SMS MFA.
  2. Kill unknown sessions, apps, and forwarding rules.
  3. Tighten who can friend, message, tag, and see About fields.
  4. Limit old public posts; remove phone/email from profiles.
  5. Warn contacts if the attacker messaged them as you.
  6. Report the attempt at ReportFraud.ftc.gov if money or impersonation was involved.

Educational only. Not legal advice. Platform menus change; use in-app Security / Privacy centers you open from the official app or a typed URL.