Search intent: Emergency / Recovery / Legal
You can no longer log in to your Instagram / Facebook / WhatsApp / Gmail / X / LinkedIn. Or the account is hacked but you're still logged in (and the attacker is posting from it). Or it has been used to scam your contacts: βsend βΉX to this UPI; it's meβ. Account takeover (ATO) is a top cyber-crime category in 2026 β Meta + Google receive lakhs of recovery requests / month from India alone. Under IT Act Β§66C (identity theft, 3-year imprisonment) + Β§43 (unauthorised access) + BNS Β§318 (cheating) + IT Rules 2021 (intermediary 36-72 hour grievance), you have legal recourse. Plus each platform has its own recovery flow. Speed matters: most platforms allow 30-day recovery window before account is permanently lost. RTI to NCRP / cyber cell + MeitY for platform takedown + bank chargeback if money was solicited from contacts forms the recovery chain.
β
What To Do In The Next 30 Minutes
π΄ Try the platform's official recovery flow first:
Instagram: instagram.com/hacked
Facebook: facebook.com/hacked
WhatsApp: WhatsApp app β Settings β Help β Contact us
Gmail: g.co/recover
X (Twitter): help.twitter.com β Account access
π΄ Use trusted device/IP (not the one suspected to be compromised).
π‘ From another secure account, ALERT your contacts that your account is compromised. Pinned post / WhatsApp broadcast / story.
π‘ Change passwords of linked accounts (recovery email, phone). Enable 2FA everywhere.
-
π’ If money was solicited from contacts β alert them; affected contacts should dial 1930.
π In This Guide
| Section | Content |
| β | β |
| Quick Answer | Authorities + escalation |
| Quick Action Steps | Printable checklist |
| What Are Your Rights | A/B/C breakdown |
| Real-World Patterns | 5 case studies |
| Legal Framework | IT Act, BNS, IT Rules 2021 |
| Step-by-Step Process | 9 steps |
| Platform-Wise Recovery | Major platforms |
| Sample Complaint Email | Template |
| Documents Required | Checklist |
| Common Mistakes | What to avoid |
| FAQs | 14 questions |
| When to Hire Lawyer | Triggers |
| Compensation | Routes |
| Important Numbers + Tools | Resources |
Quick Answer
Within 30 minutes: official platform recovery flow + 2FA reset + alert contacts.
Within 24 hours: NCRP + change all linked account passwords.
Within 48 hours: FIR if account misused for fraud against contacts.
Day 3-7: RTI to cyber cell + MeitY for platform escalation.
Recovery rate: ~80% via platform recovery within 30 days; ~60% if account already deleted.
Money recovery from defrauded contacts: their 1930 / NCRP / Banking Ombudsman.
Quick Action Steps
π΄ Platform recovery flow first.
π Recovery email / phone β secure them.
π 2FA on all accounts (Authy / Google Authenticator).
π¨ Alert contacts via different channel.
π NCRP within 24 hours.
π FIR if fraud against contacts.
π RTI on Day 3-7.
π Cite IT Act Β§66C + Β§43 + BNS Β§318.
β° Day 30 (RTI), Day 60 (escalation).
πΌ Don't pay βrecovery agentsβ β most are scams.
What Are Your Rights
A. Always available
Platform recovery flow (each platform has one).
IT Rules 2021 grievance officer 36-72 hour response.
NCRP / 1930 reporting.
RTI to cyber cell + MeitY.
Civil suit for damages.
Β§66C IT Act criminal complaint.
B. With restrictions
Recovery of deleted account β depends on platform retention (30-90 days typically).
Identity disclosure of attacker β post-investigation.
Tracing of cross-border attackers.
C. Not available
Platform refunding scam money to contacts β bank chargeback only.
Permanent attacker block β they recreate with new identity.
Recovery if no recovery email/phone existed.
Real-World Patterns
Mumbai 2024 β Instagram account with 50K followers hacked. Recovery via instagram.com/hacked + ID verification; restored in 4 days. Suspect's payment-receiving UPI traced; 12 victims among followers refunded via 1930.
Bengaluru 2025 β Gmail with linked banking. Recovery via g.co/recover with phone OTP; restored in 2 hours. 2FA reset.
Delhi 2024 β WhatsApp Business hijacked. Recovery via 6-digit verification code; restored in 24 hours. Contacts alerted.
Chennai 2024 β Facebook account used to defraud 17 friends. NCRP + IT Rules notice; account suspended; defrauded friends recovered partial.
Hyderabad 2025 β LinkedIn hacked, used for phishing. LinkedIn Trust + NCRP; restored in 7 days; fraud listings removed.
Legal Framework
A. IT Act, 2000
Β§43 β unauthorised access.
Β§66 β computer offences.
Β§66C β identity theft.
Β§66D β cheating by personation.
Β§79 β intermediary liability + IT Rules 2021.
B. BNS, 2023
C. IT Rules 2021 (amended 2023)
Rule 3 β intermediary safe harbour + due diligence.
Rule 13 β grievance officer 36-hour response.
Rule 14-15 β content takedown.
D. Leading judgments
K.S. Puttaswamy (2017) 10 SCC 1.
Lalita Kumari (2014) 2 SCC 1.
State of Tamil Nadu v. Suhas Katti (2004).
Step-by-Step Process
Step 2 β Secure linked accounts (Day 0-1)
Step 4 β NCRP + FIR (Day 1-2)
Step 5 β IT Rules 2021 grievance (Day 2-3)
Step 6 β RTI (Day 3-7)
Step 7 β Banking Ombudsman if money lost
Step 8 β Civil suit
Step 9 β Strengthen security long-term
Sample Complaint Email
To: grievance@[platform].com
Cc: cyber-sp-[district]@[state].gov.in; complaint@meity.gov.in
Subject: Account hijacking β [platform] β request emergency recovery +
takedown under IT Rules 2021
Sir / Madam,
I, [Name], hold [platform] account [@handle/email] which was hijacked
on [date]. The attacker is using my account for [fraud / scam / impersonation].
Statutory basis:
- IT Act Β§66C (identity theft) + Β§43 (unauthorised access).
- BNS Β§318 (cheating) + Β§319 (personation).
- IT Rules 2021 β 36-72 hour grievance response.
Documents:
- Account ID + creation date + last legitimate access.
- Suspicious login alerts received.
- Screenshots of malicious posts / messages.
- Affected contacts' complaint references.
Relief:
- Account recovery + suspension of attacker session.
- Removal of fraudulent posts / messages.
- Investigation of attacker's identity.
- Prevention of future targeting.
Yours sincerely,
[Name + Phone + Email]
Documents Required
Account ID / handle / email.
Creation date + last legitimate access.
Recovery email / phone (if known).
Suspicious-login alerts.
Screenshots of malicious activity.
Affected-contact details (anonymised).
Common Mistakes
Trusting βrecovery agentsβ charging fees β most are scams.
Not enabling 2FA before incident β preventive miss.
Sharing recovery codes / OTPs with anyone.
Skipping NCRP if money was lost via the account.
Not alerting contacts β chain of fraud spreads.
Using same password across platforms β domino effect.
β FAQs
Will I always recover my account?
~80% via platform recovery within 30 days. After 90 days deletion, recovery odds drop sharply.
Limited β IT Β§79 safe harbour. But can sue for IT Rules 2021 violation if grievance ignored.
Recovery email / phone also hacked. Cure?
Use platform's secondary verification (security questions, ID verification, government documents). Slower (5-30 days) but works.
I'm a small-business / influencer β bigger stakes?
Same playbook + escalate via Trust + Safety teams (Meta, Twitter, LinkedIn have business contacts). Engage lawyer for high-value reputational loss.
Hacker is overseas. Recovery?
Slower but possible via Interpol / mutual legal assistance for criminal trace. Account recovery via platform same.
2FA β when to enable?
Today. Use Authenticator app (not SMS where possible).
I clicked phishing link β how compromised?
Change all linked passwords + enable 2FA + scan device for malware.
Did device-level compromise happen?
Possibly. Run anti-malware (Malwarebytes / Bitdefender). Reset device if uncertain.
Generally no, unless platform was negligent. IT Β§43A requires reasonable security; class action possible for systemic breaches.
Yes β verified accounts get priority Trust + Safety attention. Engage senior counsel for reputational management.
Stalker created fake account in my name. Cure?
Platform impersonation report + IT Β§66C complaint + IT Rules 2021 takedown.
How does DPDP Rules 2025 affect this?
DPDP Act Β§33 β penalty up to βΉ250 cr on platform for breach.
Can I file in Hindi?
Yes β NCRP + cyber cell accept Hindi.
Long-term prevention?
2FA on every account + unique passwords + password manager + regular security audit.
When To Hire A Lawyer
High-value business / influencer account β civil counsel + reputational management.
Repeated stalking / harassment β civil + criminal package.
Class-action breach β public-interest counsel.
Pro bono: NALSA 15100; cyber-aware lawyers via DLSA.
Can Compensation Be Claimed?
Civil suit for damages.
DPDP Β§33 β regulatory penalty up to βΉ250 cr (not direct refund).
Article 226 writ for systemic platform failures.
Bank chargeback for money lost via account fraud.
Important Numbers + Portals
Internal Linking Suggestions
External References
Conclusion
Account hijacking is recoverable with speed (within 30 minutes) and the platform's official recovery flow. NCRP + FIR + IT Rules 2021 takedown + RTI form the legal chain. K.S. Puttaswamy (2017) protects digital identity. Set up 2FA today; that single action prevents 90% of future incidents.
Sources
Information Technology Act, 2000 β Β§Β§43, 43A, 66, 66C, 66D, 79.
Bharatiya Nyaya Sanhita, 2023 β Β§Β§318, 319, 336.
IT Rules 2021 (amended 2023).
DPDP Act 2023 + Rules 2025 β Β§33.
Right to Information Act, 2005.
K.S. Puttaswamy (2017) 10 SCC 1.
Lalita Kumari (2014) 2 SCC 1.
State of Tamil Nadu v. Suhas Katti (2004).
Last reviewed: 6 May 2026.