Reviewed September 2026.
After a phishing click, romance pitch, or fake “support” chat, social profiles are often the next harvest: photos of your kids, employer, vacation dates, and pet names that double as password-reset answers. This checklist hardens Facebook, Instagram, X (Twitter), TikTok, LinkedIn, and similar apps. Credential theft basics: Phishing and account takeover. Broader consumer fraud patterns: Credit and debt scams. If SMS codes are in play, fix the phone number too: SIM-swap defense.
First 30 minutes
- From a trusted device, change the password on the hit account; make it unique in your password manager.
- Change the email password that receives reset links for that account.
- Turn on app-based or hardware MFA; remove unknown phones and sessions.
- Review logged-in devices and log out anything you do not recognize.
- Check email forwarding filters and “authorized apps” / OAuth connections; revoke strangers.
If the scammer already posted as you or DMed friends for money, warn those contacts in a separate channel (Signal, phone call) and report the account takeover to the platform.
Privacy settings that cut scam intel
| Setting | Safer choice | Why |
|---|---|---|
| Friend / follower approval | Manual approve | Stops mass scrape accounts |
| Who can see birthdate, city, employer | Only you or close friends | Reduces KBA-style guessing |
| Who can tag you | Friends + review | Stops fake tagged photo lures |
| Past posts visibility | Limit old public posts | Hides vacation and family patterns |
| Location / Exact location features | Off | Reduces “I’m nearby, send cash” scripts |
| Public contact info | Remove phone/email from About | Cuts SIM-swap and spear-phish data |
Romance-scam money rails still need bank reporting: Romance scam money movement and Report to FTC and bank.
Worked example: fake Meta “ads manager” DM
Luis gets an Instagram DM: “Your ad account is suspended. Verify here.” He taps, enters password + SMS code, then loses the account. Recovery:
- Uses Facebook/Meta’s official hacked-account flow from a browser he types himself (not the DM link).
- Changes Gmail password; switches MFA from SMS to an authenticator app.
- Sets Instagram DMs from non-followers to filtering; turns off public email in About.
- Tells three friends who got “Luis needs gift cards” follow-up messages to ignore them.
- Secures the bank login (app MFA, password, recent sessions) and reviews account activity because SMS codes were used there; contacts the bank if a code or credentials may have been exposed. Separately, places bureau freezes if identity data may enable new-credit fraud (freezes do not stop takeover of an existing bank login) (ATO after a breach).
Content and tagging hygiene
- Pause public check-ins for a few weeks after a scare.
- Strip SSN, license, and passport images from old posts and Drive links (Protect your SSN).
- Avoid “verify your account by posting a code” challenges.
- Make family photo albums friends-only if they show school names and jersey numbers.
- On LinkedIn, limit profile visibility to fields you need for job hunting; recruiters do not need your personal cell in the summary.
Checklist
- Reset passwords on social + email; enable non-SMS MFA.
- Kill unknown sessions, apps, and forwarding rules.
- Tighten who can friend, message, tag, and see About fields.
- Limit old public posts; remove phone/email from profiles.
- Warn contacts if the attacker messaged them as you.
- Report the attempt at ReportFraud.ftc.gov if money or impersonation was involved.
Educational only. Not legal advice. Platform menus change; use in-app Security / Privacy centers you open from the official app or a typed URL.