Instagram accounts get stolen at industrial scale - Not for the photos, but for the audience. A hijacked account with even a modest following gets flipped for crypto-scam posts, phishing DMs sent to every follower, or outright resale, and Meta's recovery process can take days once an attacker changes the email on file. The cheapest insurance is a password nobody can guess and nobody else holds: if your current one is short, reused from another site, or was in a breach dump, replace it now. Meta has consolidated Instagram's password controls into Accounts Center alongside Facebook's, so the menu path has changed from what older tutorials show. Here's the 2026 layout.
Change Your Instagram Password on the Web
From a desktop or mobile browser:
- Sign in at instagram.com and click More (bottom-left) or your profile menu, then Settings.
- Open Accounts Center - Meta surfaces it at the top of the settings screen.
- Click Password and security → Change password.
- If you've linked Facebook and Instagram in Accounts Center, select your Instagram account.
- Enter your current password, then the new password twice, and save.
For the replacement, skip anything you'd invent yourself - Pet names, band names, and years are the first guesses in any cracking wordlist, as our breakdown of dictionary attacks shows. A 16-character string from a password generator is the strong default; if you genuinely need to type it on a phone keyboard sometimes, a four-word passphrase is far easier to enter and still resistant to guessing.
Change It in the Mobile App
Most people live in the app, and the path is short:
- Go to your profile and tap the menu button (three lines, top-right).
- Tap Settings and privacy (or Settings and activity, depending on app version).
- Tap Accounts Center → Password and security → Change password.
- Choose your Instagram account if multiple Meta accounts are linked.
- Enter the current password, the new one twice, and confirm.
If you signed up through Facebook and have never set an Instagram-specific password, the same screen lets you create one - Worth doing so your Instagram access doesn't depend entirely on another account's security.
If You've Forgotten Your Password
On the login screen, tap Forgot password? (labelled "Get help logging in" on some versions):
- Enter your username, email address, or phone number.
- Pick a delivery channel for the reset link or code - Email, SMS, or logging in via your linked Facebook account.
- Follow the link or enter the code, then set the new password.
If none of those channels work - Say an attacker already swapped the email - Look for the "Need more help?" path, which routes into Instagram's identity verification. For accounts with photos of you, that can include a video selfie check; it works best when you start recovery from a phone the account has used before. And a scam warning that bears repeating: accounts and ads promising to "recover any Instagram account for $50" are almost always fraudsters targeting desperate people. Real recovery never happens through a stranger's DMs.
The first thing account thieves change is your email address, because it turns the lock-out around: now you're the stranger trying to get in. A strong password plus 2FA keeps that switch from ever flipping.
After You Change It
| Task | Where | Payoff |
|---|---|---|
| Sign out unknown devices | Accounts Center → Password and security → Where you're logged in | Removes any session the old password created |
| Enable two-factor authentication | Password and security → Two-factor authentication | A leaked password alone no longer works |
| Save your backup codes | Inside the 2FA settings | You can still log in if you lose your phone |
| Check linked email and phone | Accounts Center → Personal details | Confirms an intruder hasn't planted recovery info |
| Update your password manager | Your vault | Keeps autofill working with the new credential |
The session sweep matters most: password changes don't always kill existing logins, and an attacker with a live session can simply set a new password again. After sweeping, turn on two-factor authentication - Instagram supports authenticator apps, which generate rotating six-digit codes on your device; the comparison in authenticator apps compared will help you pick one, and our TOTP generator demonstrates exactly how those codes are derived.
Where do you keep the new password? Not in your Notes app, and ideally not only in your browser - The tradeoffs are covered honestly in is it safe to save passwords in your browser?. A dedicated manager is the durable answer, and if this incident started with a breach notification, work through the full after-a-breach checklist - The same leaked password reused elsewhere is still a live threat on every other site.
FAQ
Is my Instagram password the same as my Facebook password?
No. Even when the accounts are linked through Meta's Accounts Center, each keeps its own password. Linking mainly enables cross-posting and shared logins. If you reused the same string on both - A habit attackers count on - Change both and make them different this time.
Why does Instagram say my password was found in a data leak?
Meta checks credentials against known breach dumps and warns when yours appears. It means that exact password is circulating publicly and will be tried against your accounts by automated tools. Change it on Instagram and on every other site where you used it, and don't dismiss the warning as spam.
How do I log out of Instagram on all other devices?
Open Accounts Center → Password and security → Where you're logged in, select your account, and review the device list. Tap each unfamiliar session and choose to log it out. Do this immediately after any password change that was prompted by suspicious activity.
What should I do if my Instagram was already hacked?
Try the Forgot password flow first; if the attacker changed your email, Instagram sends a "your email was changed" notice to the old address with a revert link - Act on it fast. Failing that, use the in-app "Need more help?" identity verification. Once you're back in, change the password, sweep sessions, verify your contact details, and enable 2FA before anything else.