Privacy & security

How to Secure Your Instagram Account: A Setting-by-Setting Lockdown

By TheTruthSpy Editor · Founder and editorPublished August 10, 202611 min read

A long password does not keep an Instagram account safe on its own. Most stolen accounts are taken with a password that leaked somewhere else, or one typed into a convincing fake page. To secure an Instagram account properly, you need your own recovery details, two-factor authentication with saved backup codes, login alerts, and a regular clear-out of old sessions and apps.

Myth: “My account is private, so it’s secure.” Privacy controls who sees your posts. Security controls who can log in. A private account with no two-factor is as easy to take over as a public one, and it can then be used to message every follower you approved.

Where the settings are, and the order to change them

Seven-step timeline to secure an Instagram account, from checking email and phone to two-factor, backup codes, login alerts, sessions, connected apps and privacy settings
About twenty minutes, done once. Steps 1 to 3 matter most.

Instagram’s security settings no longer live mainly on Instagram’s own settings page. Most of them sit in Accounts Center, the Meta panel shared with Facebook and Threads. On the current app the route is your profile › the menu (☰) › Settings and activity › Accounts Center › Password and security. Meta announced in April 2026 that Accounts Center will become Meta Account gradually over the following year, so you may see either name. The screens behind it are much the same.

The order below is deliberate. Fix the contact details before you turn on two-factor, or your codes may go to a number you no longer use. Save backup codes before anything else goes wrong. Review sessions and apps once alerts are on, so any new problem gets flagged.

Instagram Accounts Center Password and security screen listing Change password, Two-factor authentication, Saved login, Where you're logged in, Login alerts, Recent emails and Security Checkup
Most of this guide happens on this one screen. Security Checkup walks through the same items in a guided order.

Labels move between app versions and differ slightly between iPhone, Android and the web. If a setting is not where this guide says, type its name into the search bar at the top of Settings and activity. That search is quicker than working through the menus.

Step 1: make sure the recovery details are really yours

This comes first because every other protection depends on it. Password resets, login alerts and the security emails Instagram sends when something changes all go to the email address and phone number on the account. If one of those is an address you abandoned years ago, anyone who takes that address over can reset your Instagram from it.

Instagram contact info screen listing an old Hotmail address added in 2014 flagged for checking, a current Gmail address and a verified mobile number, beside a table of recovery checks
The address you signed up with years ago is the one to check hardest.

Open Accounts Center › Personal details › Contact info and go through each entry. For every email address, ask whether you could log in to it today and whether it has its own two-factor turned on. For the phone number, ask whether it is still yours. Mobile carriers reassign numbers that have been disconnected, and the new owner receives any codes sent to them.

Add the current details before you remove old ones, and confirm that a code actually arrives. If your mobile carrier offers an account PIN or a lock on moving your number to another carrier, turn it on. It makes a SIM swap harder, and a SIM swap is how SMS codes get stolen.

Step 2: turn on two-factor authentication, preferably with an app

Two-factor authentication means a password alone is not enough to log in from a new device. Instagram also asks for a code or confirmation from something you have. It is the single change that does most to secure an Instagram account, because it defeats the most common attack outright: a password reused from a site that was breached.

In Password and security, tap Two-factor authentication, choose the Instagram account, and pick a method. Instagram currently offers three: an authentication app, WhatsApp and text message (SMS).

Instagram Choose your security method screen with Authentication app selected, next to a table comparing authentication app, WhatsApp, text message and passkey by what an attacker would need
The difference between methods is what an attacker would have to steal to get your code.

An authentication app (Google Authenticator, Microsoft Authenticator, a password manager with a code generator, and others) is the strongest of the three. Codes are generated on your device and never travel over the phone network. Setting it up means scanning a QR code or copying a setup key into the app, then typing back the six-digit code it shows. SMS is the weakest, because a criminal who persuades your carrier to move your number receives your codes. It is still much better than having no second step.

Meta also announced in April 2026 that passkeys, which let you sign in with your phone’s face, fingerprint or PIN unlock, now work on Instagram as well as Facebook and Messenger. The rollout is gradual. If you see a Passkeys option under Password and security, it is worth adding. It does not replace backup codes.

Step 3: save your backup codes somewhere that isn’t your phone

This is the step most people skip, and it is the one they miss most later. Backup codes are a set of one-time codes Instagram generates when two-factor is on. Each gets you past the code prompt once, without the authenticator app or your number. If your phone is lost, stolen, reset or replaced, they are the difference between logging in and going through the identity checks a hacked account goes through.

Instagram backup codes screen showing eight example one-time codes, with a checklist of good and bad places to store them
Keep the codes where you would find them if the phone they protect was gone.

You’ll find them under Two-factor authentication › Additional methods › Backup codes; the exact label varies. Store them in a password manager or print them. A screenshot kept only on the same phone is nearly useless, because it disappears with the device you lost. Generating a new set cancels the old ones, so replace every copy when you do.

If you switch phones: move your authenticator app to the new phone before you wipe the old one. Many apps now back up to the cloud or offer a transfer option, but not all do it by default. Without the app or backup codes, a wiped phone can lock you out of your own account.

Step 4: switch on login alerts

Two-factor stops most intruders. Login alerts tell you about anyone who gets close. With them on, a login from a device or place Instagram does not recognise triggers a notification and, if you choose, an email. That gives you a chance to act while the session is still new.

Phone lock screen with an Instagram new login notification and a security email, next to the Login alerts settings with in-app notifications and email switched on
Alerts are only useful if they reach somewhere you look. Turn on both channels.

Open Password and security › Login alerts and enable both in-app notifications and email. Expect some false alarms. A new phone, a fresh browser, a VPN or a holiday abroad can all look unfamiliar. If an alert is not you, remove the session first under Where you’re logged in, then change your password. The order matters: changing the password alone does not reliably end a session that is already open.

A related screen, Recent emails, lists the security and login messages Instagram actually sent you. It is the quickest way to check whether a “new login” or “password reset” email in your inbox is genuine. Real ones come from addresses ending in @mail.instagram.com.

Step 5: clear out old sessions, saved logins and connected apps

Where you’re logged in lists every phone, tablet and browser currently signed in. Old sessions build up over the years: a phone traded in, a friend’s laptop, a work computer you have since left. Log out anything you do not physically have in front of you. It costs nothing, because you can sign in again on the devices you keep.

Saved login lets a device remember your account so you are not asked for the password. That’s convenient on your own phone and risky on a shared tablet or family computer. Turn it off anywhere other people pick the device up.

Browser mockup of Instagram Apps and websites showing two unused third-party tools marked for removal and one active booking app kept, with a keep-or-remove checklist
Unused tools and anything promising followers should go. Removal stops future access only.

Then check Apps and websites, found under Settings and activity › Website permissions in the app, or in your account settings on the web. It lists third-party services you have logged in to with Instagram, and each may still have access to your profile or posts. Remove anything you have not used recently and anything that promised followers, likes or a list of who viewed your profile. Those services break Instagram’s rules, and some have been used to take accounts over.

Step 6: privacy settings that make you a smaller target

Attackers need a way to reach you, usually a direct message, a comment or a tag with a link. The fewer strangers who can do that, the fewer phishing attempts you will ever have to judge. These settings are in Settings and activity, under the sections on who can see your content and how others can interact with you.

Instagram privacy settings list with Account privacy, Messages and story replies, Tags and mentions and Hidden Words, beside a table of safer choices and what each one stops
Privacy settings don’t stop logins. They reduce how often scams reach you.
If you are… Priorities Can reasonably leave open
A personal account Private account, message requests limited, tags from people you follow only Comments from followers
A creator or business Hidden Words with a custom list, manual tag approval, message request filtering Public profile, which your reach depends on
A teenager Instagram applies Teen Account defaults, including a private account and limits on who can message Little. Changes to several defaults need a parent if the teen is under 16

None of these settings stops a determined attacker who already has your password. They reduce the volume of fake “copyright violation”, “verification badge” and “you’ve won” messages that account theft usually starts with.

What these settings cannot protect you from

A secure Instagram account can still be lost. Knowing the gaps tells you what to watch for.

  • Handing over a code yourself. Two-factor fails if you type the code into a fake page, or send it to a “friend” who says it arrived by mistake. The friend’s account has usually been taken already.
  • A compromised email account. If someone controls your inbox, they can often reset Instagram from it. Secure the email with its own unique password and two-factor.
  • An unlocked phone in someone else’s hands. Anyone holding your unlocked phone has your open Instagram session. A screen lock is part of Instagram security.
  • Content already shared. Nothing here removes screenshots, reposts or data that a third-party app has already downloaded.
Fake Instagram copyright infringement email from a look-alike domain leading to a fake appeal page that asks for username, password and login code, with the warning signs listed
The only check that never fails is the address. Instagram does not ask for login codes on appeal forms.

Phishing is worth singling out because it is built to get around everything above. The page asks for your password and the six-digit code, then uses both within seconds. The warning signs are the sender’s address or URL, a deadline threatening deletion, and any form that wants a login code. If you have already entered one, change your password straight away, then remove unfamiliar sessions. If you are already locked out, our guide to getting a hacked Instagram account back covers each recovery route.

A two-minute check to repeat every few months

Quarterly check

What to look at, and what should worry you

Open Password and security and run Security Checkup. Then look at three things: Where you’re logged in (every device should be one you own), Personal details (both contacts still yours), and Apps and websites (nothing new you don’t recognise). Check that you can still find your backup codes. If any of these has changed without you doing it, treat it as a warning sign, not a glitch.

Outcome: problems caught while they are small. A stray session or a forgotten app is much easier to remove than an attacker is to evict.

If you reuse the same password on other sites, fix that too. A unique password on each site means one breach cannot spread to your other accounts. If remembering them is the problem, our guide to building passwords you can remember sets out a passphrase method.

How this page was put together

Menu paths and option names were checked in September 2026 against Instagram and Meta help pages on two-factor authentication, login alerts and recent security emails, and against Meta’s April 2026 announcement about Meta Account and passkeys. Instagram tests different layouts on different accounts, so the screens above are representative mockups, not screenshots. Your version may label or order things slightly differently.

We did not test any authenticator app or password manager for this guide and recommend none in particular. You can read the standards we follow for research and corrections.

Common questions

What is the most important setting to secure an Instagram account?

Two-factor authentication, set up with an authentication app, with the backup codes saved somewhere other than your phone. It stops a stolen or reused password from being enough on its own.

Can someone hack my Instagram if I have two-factor authentication?

It is much harder, but possible if you give them the code. That happens through a fake login page or a message asking you to forward it. With SMS codes it can also happen through a SIM swap at your carrier. An authentication app and a sceptical attitude to any request for a code close both gaps.

How do I see who is logged into my Instagram?

Go to Accounts Center › Password and security › Where you’re logged in. Each entry shows a device type, an approximate location and when it was last active. Log out anything you do not recognise, then change your password.

Does making my account private make it more secure?

It protects your posts and followers list from strangers, and it cuts the number of scam messages you receive. It does nothing to stop someone logging in with your password. Treat privacy and security as two separate jobs.

What happens if I lose my phone with the authenticator app on it?

Use one of your backup codes to log in, then set up two-factor again on the new phone. Without backup codes or another logged-in device, you will have to go through Instagram’s identity confirmation, which is slower.

Does Instagram ever ask for my password or login code by message?

No. Security notices come by email from addresses ending in @mail.instagram.com, and they appear under Recent emails in the app. Instagram does not send them as direct messages. Any message asking for a code, or threatening deletion within hours, should be ignored and reported.

Using a monitoring app for this? TheTruthSpy is a free parental control app for Android that stays visible on the child's phone. If it fits your family, see the Instagram monitoring feature.

Free parental control app for Android

GPS tracking, screen time limits, web filtering, SMS and call monitoring — visible on your child's phone. Pair a phone in about ten minutes.

Android · Free to set up · Visible on your child's phone