📱 Social Media
Hacked Business Social Media Account Recovery Runbook: Lock the Email First, Platform Recovery Paths, Admin and Partner Access Audit, Unauthorized Ad Spend Check, Follower Notice, and Post Incident Access Policy
A step by step incident runbook for a social media manager whose brand account was taken over: what to secure in the first hour, which official recovery path to use on each platform, how to audit admins, partners, and ad accounts, what to tell followers and when, and the access rules that keep it from happening again.
0Reviews
Prompt
Act as a social media operations lead who handles account takeovers for brands, works from the platforms' official recovery flows only, and keeps a timestamped evidence log from the first minute. Inputs: - Which accounts are affected (Instagram, Facebook Page, TikTok, X, LinkedIn Page, YouTube) and what you still control on each: [AffectedAccounts] - What happened and when: login alerts, changed email or phone, posts or DMs sent by the attacker, ad spend seen: [IncidentTimeline] - Who has access today: named admins, agency or freelancer access, business portfolio or business manager setup, shared passwords: [AccessMap] - Linked payment methods and ad accounts: [AdAccounts] - Other channels you can still reach customers on (email list, website banner, other social accounts): [BackupChannels] - Output format: [Format] Generate: 1. First hour checklist in order: secure the email inbox tied to each account first (password change, sign out other sessions, check forwarding rules and recovery options), then the platform accounts, then devices of anyone who clicked a suspicious link. 2. For each account in AffectedAccounts, the official recovery path: look for the platform's security email about the change and use its revert or secure link if offered, then the platform's hacked account help flow, then identity verification if asked. Mark any URL or menu path you are not sure of as "confirm in the platform's help center". 3. An access audit from AccessMap: remove unknown admins and partners, downgrade people who do not need full control, revoke third party app connections, and list every person who must reset passwords. 4. An ad and billing check from AdAccounts: unauthorized campaigns to pause, how to document charges, and when to call the card issuer. 5. An evidence log template: timestamp, what was seen, screenshot file name, who saw it, support case number. 6. Follower communications from BackupChannels: a short holding notice that says do not click links or reply to DMs from the account, and a recovered notice. No speculation about who did it. 7. A post incident access policy: named admins only, authenticator app or security key two factor on every admin, a password manager instead of shared passwords, quarterly access review, and an offboarding step for agencies. 8. A short internal summary for leadership: what happened, customer impact, money at risk, and next steps. Constraints: - Never suggest third party recovery services, buying back accounts, or paying anyone who contacts you offering to recover the account. - Calm, ordered, checkbox style. No em dashes.
Instructions
Replace every [bracket] with your details before running. Works on ChatGPT, Claude, and Gemini.
Generated Output
This image was generated using the prompt above.

Examples
Example Input
AffectedAccounts: Instagram business account for a bakery (lost access, email changed), Facebook Page (still admin), TikTok (fine) IncidentTimeline: 9:12 pm login alert from another country on Instagram; 9:20 pm email on the account changed; 9:40 pm attacker posted a fake crypto giveaway story and DMed 30 followers AccessMap: owner and one part time social media freelancer; Instagram password was shared over text; business portfolio has an old agency still listed as partner AdAccounts: one ad account with the owner's credit card, $50 daily cap BackupChannels: email list of 2,400, website, Facebook Page Format: first hour checklist, per platform steps, audit, comms, policy
Example Output
1) FIRST HOUR (tonight)
[ ] 9:45 pm: Owner changes the password on the Gmail account that Instagram used, signs out all other sessions, deletes any new forwarding rule, checks recovery phone
[ ] Search that inbox for the security email about the Instagram email change; if it has a revert or secure link, use it now
[ ] Freelancer changes passwords on her phone and laptop accounts, since the Instagram password traveled by text
[ ] Start the evidence log (section 5) and screenshot the fake story and DMs from a follower's view
2) PER PLATFORM
Instagram (lost):
- Use the revert link from the security email if available
- Otherwise run Instagram's hacked account help flow from the login screen ("forgot password" then the help options); confirm the current path in the Instagram Help Center
- Expect identity verification, such as a selfie video for accounts with photos of you
- Once back in: change password, turn on authenticator app two factor, review login activity, remove unknown email and phone, delete the fake story
Facebook Page (still admin):
- Check Page access for new people; remove anyone unknown
- Post the holding notice (section 6)
TikTok (fine):
- Change password and turn on two factor anyway
3) ACCESS AUDIT
- Business portfolio: remove the old agency partner
- Freelancer gets her own login with partial access instead of the shared password
- Revoke third party apps connected to Instagram that nobody recognizes
- Password resets: owner, freelancer
4) ADS AND BILLING
- Open the ad account: pause any campaign created after 9:12 pm
- Screenshot billing activity; if there are charges you did not make, call the card issuer and ask about a dispute
- Lower the daily cap to $10 until access is clean
5) EVIDENCE LOG
| Time | Seen | File | By | Case # |
| 9:12 pm | Login alert, foreign location | ig-01.png | Owner | |
| 9:20 pm | Email changed | ig-02.png | Owner | |
| 9:40 pm | Fake giveaway story, 30 DMs | ig-03.png | Freelancer | |
6) FOLLOWER MESSAGES
Holding (email, website banner, Facebook Page): "Our Instagram account was accessed by someone else tonight. Please do not click links or reply to DMs from it. We are working to recover it and will update you here."
Recovered: "Our Instagram is back under our control. If you clicked a link from us between Tuesday night and today, change that password. We never run crypto giveaways."
7) ACCESS POLICY
- Named admins only; no shared passwords
- Authenticator app two factor on every admin
- Password manager for the business
- Access review every quarter; remove agencies the day a contract ends
8) LEADERSHIP NOTE
Instagram was taken over Tuesday 9:12 pm. One fake story and 30 DMs went out. No confirmed ad spend yet. Recovery request submitted; follower warning sent by email and Facebook. Next: finish recovery, apply access policy by Friday.