It's now widely accepted that no online account is fully safe. Even so, when a message from what appeared to be the Instagram help team arrived in my inbox last spring, I clicked the link. I was told my account would be deleted within twenty-four hours unless I 'verified' my identity. I typed in my email and password. Within ninety seconds, I was locked out. My email had been changed. My phone number had been removed. Ten years of photographs, messages, and small businesses I had followed since school were, suddenly, no longer mine.
What I didn't understand at the time is that I had been phished. The link had taken me to a page that looked exactly like Instagram, but was in fact a copy hosted somewhere in Eastern Europe. As soon as my details were entered, they were captured and used to log in from another country. Two-factor authentication should have been set up years ago — but, like most people, I had put it off. It is thought that around sixty percent of adults still use the same three or four passwords across every account they own.
Recovery, I discovered, is slow. A short video selfie is required — that's how identity is now verified. It was uploaded to Meta the same afternoon, and I waited. Meanwhile, messages were being sent from my account to my followers, asking them to send crypto to a wallet. Several friends replied politely; two, embarrassingly, actually sent money. That money, of course, will never be seen again.
The account was recovered nine days later. I had it scanned by a professional first, in case anything else had been installed. What I learned, once the initial panic passed, is that this is happening to almost everybody. It's said that more than a million social-media accounts are compromised every single day. If you're reading this and you haven't turned on two-factor authentication yet, please close this tab and go and do it now. That single change is thought to block over ninety-nine percent of automated attacks. It's the cheapest insurance policy you'll ever buy.


