A message that says a blue badge, copyright complaint or account appeal is pending may use a logo and a short deadline to pressure you into sending a one-time code. Meta says Instagram does not send account-security instructions by DM. The code is often the final piece needed to sign in or change a password. Even if the sender appears verified, the badge identifies an account category, not authority to collect your login details.
Before you start
Do not reply with a password, one-time code, backup code, selfie or identity document. Avoid opening an attachment or installing a 'support' app. If you already sent a code, act as if the account may be compromised, even if the other person says the process failed.Do it step by step
- Capture the sender's handle and message text if needed for a report, without tapping its link. Open Instagram's settings on your own device and inspect Emails from Instagram or the Support Inbox for a matching official notice.
- Report the suspicious DM from the conversation and block the sender. If they used a lookalike account, report the profile as impersonation or scam as appropriate. Do not post their link publicly to warn friends.
- If you revealed a password or code, change the Instagram password from the genuine app immediately. Use a unique password and change any reused copy on other sites. Secure the connected email account and its recovery methods.
- Review Where you're logged in, sign out unknown sessions and check whether the account email, phone or two-factor method changed. Enable or repair two-factor authentication and keep backup codes in a separate secure location.
- Check outgoing messages, posts and profile links for attacker changes. Let contacts know through another channel if the account sent them requests for money, codes or suspicious links. A private warning is more useful than repeating the scam URL.
- If access has already been lost, use Instagram's official hacked-account help. Keep evidence of the message and transaction if money or documents were sent, and contact the relevant financial institution directly using its known number.