Open Instagram’s Accounts Center, choose Password and security, then Where you’re logged in to review devices and sessions. Menu names can change as Meta updates the app. If you do not recognize a session, log it out, change the password, review the account’s email and phone number, and turn on two-factor authentication.

Review Instagram login sessions

In the Instagram app, open your profile and menu, then enter Accounts Center. Under Password and security, select Where you’re logged in and choose the Instagram account. Review the device type, approximate location, and recent activity for each session.

On the web, open Instagram through its known address and use Accounts Center or the security settings available for the account. Do not reach the page through an unexpected “new login” email or direct message.

Why a location may look unfamiliar

Instagram estimates location from network information. Mobile carriers, VPNs, travel, and internet-provider routing can display a nearby or previous city. A device label may also be generic.

Compare the location with the device, date, browser, and actions on the account. When the details remain uncertain, log out that session. You can sign in again on a device you own.

What to do with an unknown session

  1. Log out the unfamiliar device or session.
  2. Change the Instagram password to a unique one.
  3. Review the email address and phone number in Accounts Center.
  4. Turn on two-factor authentication, preferably through an authenticator app or another strong method offered by Instagram.
  5. Save new backup codes and remove old authentication devices.
  6. Review linked Facebook accounts and other Accounts Center connections.

Check recent posts, stories, messages, follows, profile changes, ads, and purchases. Delete content created by the intruder only after preserving evidence you may need for a report.

Review professional-account and advertising settings when the profile is connected to a business. An intruder may add an ad account, payment method, page role, or business integration without posting on the public profile. Check Meta Accounts Center and the business tools you use, then remove people and assets you do not recognize.

Download or screenshot security details before ending a session if a business, payment, or impersonation report may follow. Keep copies outside Instagram because recovery problems can remove access to the evidence.

If the email address was changed

Instagram may send a message to the original address when account email changes. Verify that message carefully and follow Meta’s documented reversal or recovery route. If you cannot access the old mailbox, work with the email provider to recover it and update Instagram to an address you control.

Use instagram.com/hacked or the recovery flow reached from the official Instagram app when you cannot sign in. Do not pay an account-recovery service or send a verification code to someone claiming to be Meta support.

Secure the recovery email and phone number

An attacker can regain Instagram through a compromised mailbox or phone number. Change a reused email password, review mailbox forwarding, enable two-factor authentication, and secure the mobile-carrier account with a PIN.

Remove recovery methods you no longer control. Keep backup codes offline rather than in an Instagram direct-message conversation or an unprotected photo.

Watch for impersonation after recovery

Tell contacts if the account sent investment offers, emergency money requests, or malicious links. A scammer may also create a separate profile using your name and photos. Report the impersonating account through Instagram’s official tools.

Review apps and websites connected to Instagram or Meta. Remove services you do not recognize or no longer use.

Search for accounts using the same name, profile photo, and recent posts. Tell contacts which profile is legitimate without reposting the scammer’s clickable links. If direct messages requested money or codes, ask recipients to preserve the conversation and report it inside Instagram.

Continue watching for new login alerts and recovery changes after access is restored. A return of unknown sessions suggests that a password, recovery method, linked Meta account, or device remains compromised.

Does another login mean the phone was hacked?

No. Someone may have obtained the Instagram password through phishing, reuse, a data breach, or access to the recovery email. Scan the phone when you installed a suspicious app, granted remote access, or see device-level symptoms. Account recovery and device review are separate tasks.

How dfndr security can help

Breach Report may identify known credential exposure related to a registered email address. Link protection may warn about selected fake login pages. dfndr security cannot list or remove Instagram sessions; use Instagram’s own account controls for that action.

PSafe’s analysis of Instagram sessions

Review active sessions and the recovery methods that could let someone sign in again. Logging out one phone is not enough if the attacker controls the email address, phone number, or a linked Meta account.

Frequently asked questions

Can Instagram show the exact location of a login?

No. The displayed location is an estimate and may reflect network routing rather than the device’s physical position.

Will changing the password log out every device?

Do not assume it will. Use Where you’re logged in to review and end sessions explicitly.

Can Meta support ask for my password or code in a DM?

Do not provide passwords or one-time codes through direct messages. Use the official app, help center, and recovery pages.

Should I unlink Facebook?

Review the linked account and its security. Unlink only when you no longer want the connection or cannot secure it; otherwise, protect both accounts and Accounts Center.