Cyber crime & IT Act matters

Instagram or Social Media Account Hacked in Kerala? How to Recover It Under the IT Rules

By Adv. K J Muhammed Aslam · Advocate, Ernakulam (Bar Council of Kerala)

Published 5 September 2026

Your Instagram — or Facebook, X or Gmail — now shows a different email and phone, and the in-app “forgot password” loop fails because the recovery path has been replaced. This is not a help-desk ticket alone; under the Information Technology Act, 2000 it is commonly identity theft and personation (Sections 66C and 66D, plus 66), and under the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as amended 10 Feb 2026 (in force 20 Feb 2026) the platform has time-bound grievance and takedown duties — including a 2-hour path where the hijack is used for impersonation. Two tracks filed together — platform grievance + police complaint — recover more accounts than either alone.

Which provisions actually govern an account hijack?

Track Provision What it does Clock
Crime IT Act Sec 66C (identity theft) Fraudulent/dishonest use of your electronic signature, password or any other unique identification feature FIR → investigation by Inspector+ (Sec 78)
IT Act Sec 66D (cheating by personation using computer resource) Cheating by personation using a computer resource — the hacker posting as you Up to 3 years + ₹1 lakh, cognizable, bailable
IT Act Sec 66 (computer-related offence via 43) Dishonest access/damage to your computer resource (the account) Up to 3 years / ₹5 lakh
BNS Sec 308, 318, 351 Extortion, cheating and intimidation where ransom or fraud follows the hijack 308: up to 7 years
Platform IT Rules 2021 Rule 3(2) — grievance Resident Grievance Officer: general 7 days, unlawful-content 36 hours, impersonation/morphed/nudity 2 hours (post-Feb 2026) From your grievance
Rule 3(1)(d) — takedown on actual knowledge 3 hours for unlawful content from actual knowledge via court order or authorised government notification From order/notification, not from grievance
Rule 4 — SSMI duties (>50 lakh users) Significant social media intermediaries (Meta, X, Google) must publish monthly transparency reports, enable voluntary user verification, and act faster on impersonation — the route that makes the 2-hour path credible Continuous

Section 79 IT Act safe harbour for intermediaries depends on due diligence — Rule 3 compliance is that due diligence.

How should you file the platform grievance so it triggers the 2-hour track?

Where the hijack is used to impersonate you (posting from your account, DM-ing your contacts), frame the grievance explicitly as impersonation under Rule 3(2)(b) / Rule 4 — that engages the 2-hour user-grievance path. Include:

  1. Account identification: Exact handle/URL (https://instagram.com/your.handle), account creation email/phone, and your government ID proof.
  2. Hijack timeline: Date/time you lost access, the new recovery email/phone showing replacement, and the first impersonation post or DM with URL (not just screenshot).
  3. Label the category: Write “Complaint under Rule 3(2) and Rule 4 — impersonation / unauthorised access to user account (IT Rules 2021 as amended 10 Feb 2026) — request 2-hour handling as impersonation.” Citing the rule and the time track is not advocacy — it is the correct head for prioritisation.
  4. Preserve for Section 63 BSA: Export the impersonation post’s URL and metadata; keep the original-device export with hash — see Section 63 BSA guide.
  5. File in two places: The platform’s grievance form + email to the published Resident Grievance Officer (every SSMI must publish name and contact), and — where the hack is part of a fraud — a parallel government-notified track (police or MeitY-authorised agency) is what starts the Rule 3(1)(d) 3-hour clock. Your grievance alone does not trigger 3(1)(d).

A common failure: reporting via the in-app “Report a problem” with no URL, no impersonation label, and no grievance-officer email — the ticket is then triaged as low priority and the 2-hour path is never engaged.

How does the police complaint fit — and where do you file it in Kerala?

File a written, signed complaint at the district Cyber Police Station (every Kerala revenue district has one) or the station whose cyber cell covers the account, citing IT Act 66C/66D/66 and — where ransom or impersonation harm is made out — BNS 308/319/351 (and POCSO where a minor’s intimate image is involved). Attach: account URL, timeline, the impersonation post URLs, the hijack email/phone change screenshot, and the platform grievance acknowledgement. Request an FIR under Section 173 BNSS where cognizable ingredients are disclosed — Lalita Kumari remains the mandatory-FIR rule — and, if the account is used to freeze others’ money, note the Section 106 BNSS / 503 BNSS implications for lien.

For escalation where a filed NCRP/1930 reference draws no FIR, use the chain in the NCRP escalation guide — SP/CP written representation → CPGRAMS → Magistrate direction under Section 175(3) BNSS.

What about accounts used to impersonate you rather than hijack yours?

Where a different account clones your name and photo to scam your contacts, the same Rule 3(2)(b) 2-hour impersonation and Rule 3(1)(d) 3-hour tracks apply, and the crime sections shift emphasis to 66D (personation) and 319 BNS (cheating by personation), plus 66E / 67 / 351 where morphed images are used. File both the platform impersonation report (with both URLs — yours and the fake) and the police complaint. Courts in Kerala and the Delhi High Court have granted John Doe / Ashok Kumar injunctions and disclosure of subscriber data where impersonation is used for fraud — the written grievance with URLs is the pre-condition for that route.

What reduces recovery time — a short checklist

  • Enable two-factor authentication (TOTP app, not SMS alone) before hijack, and keep a backup code offline.
  • Do not click recovery links sent by the impersonator — they phish the replacement credentials.
  • Keep the original-device proof — the date your recovery email changed, as recorded on the device and by the platform’s security email, is the best timestamp for the investigation.
  • Do not transfer money to the hijacker for “return” of the account — use the police + government-notified takedown track instead.

Primary sources

FAQ

Common questions

My Instagram was hacked and the recovery email changed. What is the legal route beyond the in-app form?
Use the IT Rules 2021 legal track in parallel to the in-app recovery. File a grievance with the platform's Resident Grievance Officer under Rule 3(2) (now 7-day resolution; 36 hours for unlawful-content and 2 hours for impersonation/morphed-image cases), provide the account URL, your ID proof, and the hijack evidence. Intermediaries must also remove or disable access to unlawful content within 3 hours of actual knowledge via a court order or authorised government notification under Rule 3(1)(d) (down from 36 hours after the 10 Feb 2026 amendment); the 2-hour removal for non-consensual impersonation is the Rule 3(2)(b) user-grievance track.
Which sections apply when a social media account is hacked?
Commonly: IT Act Section 66 (computer-related offence via dishonest use), Section 66C (identity theft — fraudulent use of your password/electronic signature/unique identifier), Section 66D (cheating by personation using computer resource where the hacker impersonates you), and where ransom is demanded, BNS Sections 308 (extortion) and 351 (criminal intimidation). The IT Rules 3(1)(d) and 4 (for SSMIs) then supply the platform-due-diligence duties.
How long must Instagram or Facebook take to act on my hacking complaint?
Under Rule 3(2) as amended 10 Feb 2026 (in force 20 Feb 2026): general grievances in 7 days (down from 15), unlawful-content grievances in 36 hours (down from 72), and complaints about impersonation, morphed images, nudity or child safety in 2 hours (down from 24). The separate Rule 3(1)(d) clock — 3 hours for unlawful content — runs from actual knowledge via a court order or authorised government notification, not from your grievance alone; the 2-hour impersonation/morphed track is Rule 3(2)(b). File both tracks.
Can I file an FIR for a hacked Instagram account in Kerala?
Yes, where the ingredients of cheating, impersonation, identity theft or extortion are made out — which a hijacked account typically is. File a written complaint at your district Cyber Police Station citing IT Act 66C/66D/66 and BNS 308/318/319, with the account URL, timeline, and preserved screenshots with hash for Section 63 BSA. Cybercrime.gov.in allows confidential filing as well, but the district FIR is what grounds investigation under BNSS.
The hacker is extorting me to pay to get the account back. Should I pay?
No. Payment rarely restores control and funds the next impersonation. Preserve the extortion demand (chat, UPI ID, phone number), file the platform grievance and the police complaint, and let the Rule 3(1)(d) / investigation track operate. Paying also complicates proving extortion under Section 308 BNS.

Contact

3rd Floor, Lalan Towers (KGL Builders), Vanchi Square, High Court Junction, Ernakulam, Kerala 682031 · Monday – Saturday, 10:00 – 18:30 (by appointment)

A note before you read on. In keeping with the Bar Council of India Rules, this website provides information about Adv. K J Muhammed Aslam, and general legal information, only to those who seek it of their own accord. It is not an advertisement or solicitation, and nothing here is legal advice. By continuing, you acknowledge you are visiting voluntarily. Full disclaimer.