Hacked Business Social Media Account Recovery Runbook: Lock the Email First, Platform Recovery Paths, Admin and Partner Access Audit, Unauthorized Ad Spend Check, Follower Notice, and Post Incident Access Policy
Ppromptstudio·Oct 8, 2026
No rating
A step by step incident runbook for a social media manager whose brand account was taken over: what to secure in the first hour, which official recovery path to use on each platform, how to audit admins, partners, and ad accounts, what to tell followers and when, and the access rules that keep it from happening again.
Act as a social media operations lead who handles account takeovers for brands, works from the platforms' official recovery flows only, and keeps a timestamped evidence log from the first minute.
Inputs:
- Which accounts are affected (Instagram, Facebook Page, TikTok, X, LinkedIn Page, YouTube) and what you still control on each: [AffectedAccounts]
- What happened and when: login alerts, changed email or phone, posts or DMs sent by the attacker, ad spend seen: [IncidentTimeline]
- Who has access today: named admins, agency or freelancer access, business portfolio or business manager setup, shared passwords: [AccessMap]
- Linked payment methods and ad accounts: [AdAccounts]
- Other channels you can still reach customers on (email list, website banner, other social accounts): [BackupChannels]
- Output format: [Format]
Generate:
1. First hour checklist in order: secure the email inbox tied to each account first (password change, sign out other sessions, check forwarding rules and recovery options), then the platform accounts, then devices of anyone who clicked a suspicious link.
2. For each account in AffectedAccounts, the official recovery path: look for the platform's security email about the change and use its revert or secure link if offered, then the platform's hacked account help flow, then identity verification if asked. Mark any URL or menu path you are not sure of as "confirm in the platform's help center".
3. An access audit from AccessMap: remove unknown admins and partners, downgrade people who do not need full control, revoke third party app connections, and list every person who must reset passwords.
4. An ad and billing check from AdAccounts: unauthorized campaigns to pause, how to document charges, and when to call the card issuer.
5. An evidence log template: timestamp, what was seen, screenshot file name, who saw it, support case number.
6. Follower communications from BackupChannels: a short holding notice that says do not click links or reply to DMs from the account, and a recovered notice. No speculation about who did it.
7. A post incident access policy: named admins only, authenticator app or security key two factor on every admin, a password manager instead of shared passwords, quarterly access review, and an offboarding step for agencies.
8. A short internal summary for leadership: what happened, customer impact, money at risk, and next steps.
Constraints:
- Never suggest third party recovery services, buying back accounts, or paying anyone who contacts you offering to recover the account.
- Calm, ordered, checkbox style. No em dashes.