- Instagram 2FA prevents unauthorized access even if your password is compromised
- Use an authenticator app (TOTP) โ it's more secure than SMS and works without cell service
- Instagram also supports WhatsApp 2FA as a verification method
- Save backup codes and store them somewhere safe like a password manager
- Enable 2FA in Settings > Security > Two-Factor Authentication
Instagram accounts are among the most targeted on the internet. Enabling two-factor authentication (2FA) is the single most effective step you can take to stop unauthorised access.
In This Guide
Why You Need 2FA on Instagram
Instagram uses email and phone number for account recovery โ both commonly exposed in data breaches. With 2FA enabled, even if someone has your password, they cannot log in without the time-based code from your phone.
Method 1: Authenticator App (Recommended)
Using an authenticator app is more secure than SMS because codes are generated locally and cannot be intercepted via SIM swapping. For recommendations, see our guide to the best authenticator apps for 2026.
- Open Instagram and tap your profile picture in the bottom right
- Tap the menu icon (โฐ) โ Settings and privacy
- Go to Accounts Centre โ Password and security โ Two-factor authentication
- Select your Instagram account, then tap Authentication app
- Instagram will display a QR code and a 32-character secret key
- Open your authenticator app (or use 2faco.com) and scan the QR code or paste the secret key
- Enter the 6-digit code displayed to confirm setup
Method 2: SMS
Follow the same steps but choose Text message instead of Authentication app. SMS is better than nothing but significantly weaker than an authenticator app โ SIM swapping attacks can bypass SMS 2FA entirely.
Save Your Backup Codes
Instagram provides 5 backup codes. After enabling 2FA, return to the Two-factor authentication screen and tap Backup codes. Save these in a password manager โ they're your only way in if you lose your phone.
What if I get a new phone?
Transfer your authenticator accounts before switching phones. Always do this before factory-resetting your old device.
Why Instagram Accounts Get Hacked
Instagram accounts are frequent targets because the platform stores personal data, direct messages, and payment information. Attackers use phishing pages that look like the Instagram login screen, credential stuffing with passwords leaked from other sites, and social engineering targeting your linked email or phone number. High-profile accounts are stolen for scams, verified badge resale, or ransom. Even small accounts are harvested for spam networks. Two-factor authentication blocks all of these attack types โ even if your password is stolen, the attacker still cannot sign in without the second factor.
Authenticator App vs SMS on Instagram
Instagram offers three second-factor options. The table below compares them:
| Method | Security Level | Requires Internet | SIM Swap Risk |
|---|---|---|---|
| Authenticator App (TOTP) | Highest | No | None |
| SMS | Medium | Yes | Vulnerable |
| Medium | Yes | Vulnerable |
For accounts with a business following or monetisation, always use an authenticator app rather than SMS or WhatsApp.
Using an Authenticator App with Instagram
When you select "Authentication app" in Instagram's 2FA settings, Instagram either automatically links to the authentication app on your phone or shows a QR code you can scan. Open your authenticator app (Google Authenticator, Authy, 1Password, etc.), add a new account, scan the code or enter the text key, then enter the 6-digit confirmation code Instagram asks for. Your setup is complete.
Instagram Recovery Codes
Instagram generates five 8-digit recovery codes when you enable 2FA. These can each be used once to sign in without your 2FA device. Copy them and store them separately from your phone. If you lose your codes, generate new ones from Settings โ Security โ Two-Factor Authentication โ Additional methods โ Recovery codes. Generating new codes invalidates the old ones.
Trusted Devices on Instagram
After completing 2FA on a device, Instagram asks if you want to save it as a trusted device, skipping 2FA checks on future sign-ins from that device. This is convenient for your personal phone but never enable it on a shared, borrowed, or public device. Manage your trusted devices from Settings โ Security โ Two-Factor Authentication โ Additional methods โ Trusted devices.
What to Do If You Lose Access
If you lose your phone or your authenticator app, you still have several ways to regain access to your Instagram account. Use one of your backup codes from Settings. If you no longer have your backup codes, Instagram can send a recovery code to your linked email or phone number. You can also use the "Need more help?" link on the 2FA screen to submit a review request โ Instagram may ask for a photo of yourself or other identity verification. To avoid being locked out, store backup codes in a password manager and keep your recovery email and phone number up to date.
Frequently Asked Questions
Can I use the same authenticator app for multiple Instagram accounts?
Yes. Most authenticator apps support multiple accounts. Simply scan or enter the QR code for each Instagram account during setup. Each account will appear as a separate entry with different 6-digit codes.
Does Instagram 2FA work internationally?
Yes. Authenticator app codes work offline and anywhere in the world. SMS 2FA requires cellular service and may not work while roaming internationally. WhatsApp 2FA requires an internet connection. For frequent travellers, an authenticator app is the most reliable option.
Can I disable Instagram 2FA?
Yes. Go to Settings โ Security โ Two-Factor Authentication, tap your account, then tap Turn Off. Instagram will ask you to confirm. Be aware that disabling 2FA makes your account significantly more vulnerable to takeover.
What happens if Instagram detects a suspicious login?
Instagram may block the login and prompt the attacker for a 2FA code they don't have. You may also receive an email or push notification about the attempted login. If you receive such an alert, change your password immediately and review your login activity in Settings โ Security โ Login activity.
Common Instagram 2FA Mistakes That Lead to Takeovers
Most Instagram account takeovers happen after 2FA was enabled and then quietly undone. The most common mistake is switching 2FA off "temporarily" because a code was slow to arrive โ people forget to turn it back on, and the account sits unprotected for months. Treat 2FA as always-on; if you must disable it to fix a login problem, set a reminder to re-enable it the same day.
Another frequent error is choosing SMS only because it's faster to set up. SMS codes can be intercepted through SIM swapping, and Instagram's recovery flows lean on your phone number, which makes an SMS-only account weaker than it looks. The next most common mistake is letting a third-party app log in โ apps like "follower trackers" or "insight boosters" that ask for your Instagram password and then your 2FA code. A genuine authorized app never needs your 2FA code; anyone who asks for it is harvesting it. Review the apps connected to your account under Settings โ Security โ Apps and websites and revoke anything you don't recognize.
Finally, treat fake security alerts as a scam signal. A message claiming "someone tried to log in to your account" with a link to "confirm your identity" is a phishing lure โ Instagram sends such warnings inside the app and to the email you registered, never by SMS with a short link. If you are unsure, open Instagram directly and check Login activity rather than clicking anything in the message.
2FA for Business and Creator Accounts
Business and creator accounts sit inside the Meta Accounts Centre, which groups Instagram with Facebook and Messenger. You can manage two-factor authentication for the linked accounts in one place, but enabling it for one account does not enable it for the others โ each account must be toggled separately. If your page is managed by a team, set up 2FA per person's own account rather than sharing one login, because every person with the password also becomes a potential recipient of 2FA codes.
When the person who set up 2FA leaves the team, their authenticator entries and backup codes usually leave with them. Keep a copy of the account's backup codes in the company password manager, and use Instagram's "Add partner" feature for collaborators instead of handing out the main login. This gives you a clean way to revoke access without touching the main account's security settings.
What to Do If Your Instagram Account Is Already Hacked
If an attacker has changed your password and email, start at instagram.com/hacked. Instagram will ask you to identify the account by your original email address, phone number, or username, then send a login link to the contact details still on file. If the attacker removed those, you can request a review and may be asked for a selfie video to confirm your identity โ this review can take a few days, so be patient and keep checking the email address you provided.
Once you are back in, do these in order: sign out of all sessions from Settings โ Security โ Login activity, change your password, re-enable 2FA with an authenticator app, generate fresh backup codes, and remove any authorized apps the attacker may have connected. If the account was used to message your followers, post a short notice on your profile that the account was briefly compromised so your contacts don't fall for any scam messages sent while the attacker had control.