And then my Instagram account was hacked...
(Klik hier voor het Nederlandse artikel)
🇦🇺It was an ordinary Friday. Well, ordinary for corona times of course. It was my day off from my work in medical project management. I had just posted a picture of my kitchen on Instagram, describing my failed attempt to recreate my mum's curry, which was leading to hilarious conversations. Allowed to go to the gym again, I jumped in the car and sped off. Upon arrival (I was a little early) I thought I'd quickly read my mail before going in.
In my inbox was a collaboration request, of which I receive many. It outlined a barter deal with suggested content, and a link to the Instagram account in question. The email didn't spark my interest but I was curious to see what account it was for, so clicked the link, logged into Instagram and viewed the account.
Looked pretty cool actually, albeit totally not my niche (fashion and lifestyle, rather than interior). I would answer them later to decline. I do remember thinking: a) why would they want ME to promote their products as it's not my section (but that happens more often if target audiences overlap) and b) why (as a large American account / company) don't they employ someone with fluent English? However, you must know, I work daily with people from all over the world. Not everyone speaks perfect English. I don't judge second language fluency, it is usually a sign that someone is particularly literate, often knows even more languages than I do and makes an effort to communicate with me. And as I mentioned before, I get these types of emails all the time. Little did I know it was a phishing mail. And of course this particular company had nothing to do with it.
My account was hacked while at the gym
I completed my work out, walked back to my car and checked my phone. There were a number of new emails, but a few stood out. A number of them from Instagram in rapid succession: a new login attempt, I apparently changed my username, changed my email, and allegedly removed my phone number. And to please let them know if that hadn't been me making all those changes.
Then a 5th email:
Good day! We apologize for the inconvenience. Your account has been temporarily blocked!
It's perfectly safe and we haven't touched it. We are waiting for your reply 2 hours!
If you do not respond, we will start to clear your account (delete photos) and sell your account! We are waiting for your reply !
I felt my stomach drop. Surely this wasn't real? I tried to open Instagram but couldn't. Log in denied. No user found. I was whatsapping with an insta girlfriend that same moment and asked her to quickly check. She confirmed my worst fears; account gone. Please tell me this wasn't happening? Years of hard work, relationships, partnerships, my interior design business and creative projects gone, just like that? I raced home, told my husband to drop everything to help me, and jumped online to contact Instagram. Obviously I couldn't revert the changes. Was it me that made the changes to my profile? Of course not! But when I pressed the link to let Instagram know it just showed an error message. I researched how to report a hack, how to contact customer service, how to get this undone, but simply got nowhere. All methods listed on the site required some sort of identification, and the hackers had changed every single thing. There was nothing in their system anymore relating to me. I was on the phone with another insta buddy to work out the steps required, and in the meantime cursing myself for not having the 2-step verification security measures on. Why oh why did I not have that turned on? I have no idea! Didn't even realise it wasn't. I originally created my personal account many many moons ago, never used it, and converted it to a business account a few years back. Instagram never prompted me to review my security settings (or make it mandatory which I think they should) and it hadn't even crossed my mind to check. So dumb, I know.
At this stage I am visibly trembling, shaking and crying all at the same time. Close to vomiting really. Hubby found an Instagram customer service phone number online that offered assistance in these types of situations. I called, and yes! They could help me! They could help me log back in and get my account back. I was surprised, as Instagram is known to be impossible to contact, let alone speak to an actual human. Could it be as simple as a phone call? As they were requesting access to my screen, I got suspicious and did a quick google. I wasn't going to be scammed twice. Of course they were criminals too so I slammed down the phone (figuratively of course, as I wasn't actually going to smash my iPhone).
Defeated. Angry. So so upset. And that feeling of being personally violated. The cheek of those hackers to wish me a good day, and 'apologies for the inconvenience'. Inconvenience? This is my business you've just shut down in a matter of minutes! It may as well have been a shop that burnt to the ground.
Contact with the hackers
I was stuck between a rock and a hard place. And decided to contact the hackers. They were very polite actually, and of course very responsive, Assuring me that they had no real interest in my account, all they wanted was money. If I paid up I would get my account back. Clearly the initial thought was to tell them to F*&k off. But I was desperate. They wanted 285 USD. 285 dollars for my entire business; I wasn't sure to be relieved or offended. Of course I knew full well I was probably never going to see that money again, but I figured if there was even a 1% chance they would do as they said, it was worth it. We had a little kitty of bitcoin of which I had forgotten its existence (set up during the rise of bitcoin, and left to its own devices after the rate did a nose dive). I figured this was my rainy day. So I paid. And waited. They emailed me back, telling me they were restoring my account and to give it 15 mins. That became thirty. An hour. And they kept responding to my emails. Politely. Telling me what there were doing. So I remained hopeful. Until I realised it really was never going to happen, and gave up.
I was sitting on the couch completely numb. That same couch that's featured on Instagram so often. Blaming myself for being stupid and clicking on a link from my mobile, stupid for logging in again, stupid for not having my 2-step verification on and stupid for paying up. Thinking of the lovely conversations with my contacts on Instagram that now would think I just vanished. Thinking of the collaborations I had coming up and how I would explain my commercial partners that my platform was gone. Thinking of what to do next, but my head was so foggy. Insta buddies would start phoning and messaging me, offering me their support, suggestions and contacts of people who'd experienced the same. Wonderful people, and I am eternally grateful for their instant offline support. Real people, who I've met in a virtual world.
Then hubby messaged me and said 'Quick, I need all your insta details - there might just be a way!' He remembered an old primary school friend who's made it big within Facebook (who owns Instagram). He contacted her in California, she responded very quickly to say she could submit my case to an internal system reserved for friends and family of staff, which apparently then jumps the queue (or actually puts the request in a queue in the first place). She was heading off on her holidays however, and soon to be out of WiFi, so we had to get it in quickly. She had no idea what could be done, how long it would take, or what would be left of my account, if anything. Just that everyone was snowed under due to corona.
It happens all the time.
And then the wait started. People get hacked all the time I learnt. By then, I had read pretty much any article on the web about Instagram hacks and what to do, every possible scenario of what could happen (ranging from full recovery to everything lost) and the fact that Instagram is not really much assistance (if at all). I ended up finding a link on the log in page, where you get to after a few clicks, that says 'need more help?'. There I could tick a box that I had been hacked and submit a form with my original email address I signed up with, as well as a contact email address. It didn't matter which email address I entered (even complete dummy ones), the automated reply always came back with the same answer:
How devastating. Could everything really be gone? Surely Instagram has some sort of back up system in place? And the email itself was weird too. No subject. No logo. Twice hi. Even our friend who works for the company thought it was spam. But it wasn't.
I didn't hear anything for days and was a blubbering mess. I would even wake up hubby in the middle of the night to go and check his phone to see if there were any messages (which wasn't received with thanks mind you). Considered chopping his finger off to use the fingerprint ID to check his phone while he was sleeping. Because I wasn't. I was a walking zombie. We couldn't exactly keep bugging our contact either. She was on holidays, did the best she could, hubby hasn't seen or spoken to her in many years and I don't even know the girl (but boy do I love her).
I started receiving lots of messages through other channels. People found me via my website, or facebook, or had been given contact details through mutual friends. It made me even more determined to get back, I was actually being missed! Yes it's a virtual world, but it's the real people behind the accounts that are so lovely, and make it such a great community. I didn't care if I lost all photos, or nonsense bot followers, all my chances for commercial projects, as long as I could get back to my followers who genuinely like what I have to say and show every day.
What doesn't kill you makes you stronger
A few days later I decided this wasn't going to bring me down. What doesn't kill you makes you stronger. I'd be back. I wasn't sure yet how or when, but I was going to make a come back. Some said the forced break would do you good, but it didn't. I missed the Instagram world terribly. I had decided for myself I was not going to start anything new, until hubby's friend would tell me all is lost.
It was two weeks later when hubby's friend let us know she received notification that they had 'picked up the case'. Oh Em Gee. Butterflies. But what does that mean? Overnight I received a standard email from Instagram saying: you've changed your email address. It was changed back to my own email address. Username still garble, but the email address was mine. They asked me to confirm my email, but obviously that didn't work. I had no password! Plus, it still said that funny username didn't exist! No instructions or anything. Useless. I was at a loss. It looked like progress, but now what?
Then I remembered that backdoor way of reporting a hack. I hoped that, because there was now an email address in the system that was mine, perhaps I would receive another automated email rather than the 'sorry nothing we can do' one. I submitted my details and yes! I received an automated email asking me for some more details, such as previous usernames, timing of hack, how it had happened etc. I submitted it thinking nothing would come of it, as I had read in so many other blogs. Or, I thought, perhaps I would be asked to submit one of those personal photo's holding a picture with a code. I couldn't ask our FB contact as it was the middle of the night on the other side of the world.
But then, very soon after, I received an email from Facebook, a proper one, in Dutch this time, that said: 'Thanks for verifying your identity. You're almost done with recovering your account.' And with instructions on how to log back in and adapt my account information. Were they for real? I was in the car and didn't dare trying on the mobile. I waited until I was back home and jumped on the laptop. Logged in and there it was. My account, fully in tact, with all my pictures and 27 thousand followers. As if nothing ever happened. Other than stats and concepts gone, everything was there. I was able to change the username back into my old one, changed a few details, changed my password and of course turned on the 2-step verification security measures.
I was elated! Never did I think all my work would be fully recovered! I took a screenshot of my profile page to text to my friends, contemplating my first move back, thinking I would take my time to properly consider. But the news had already gone viral. My lovely online community picked up the news, ran with it, shared with all of their followers and celebrated together with me. It was as if I had come home again. The comments on my first post back (and only post so far at time of writing) were heartwarming and I cherish them so much. I also had the best sleep I had in weeks (after downing a bottle of wine).
SO I AM BACK BABY! Take that hackers! And not going anywhere for a while.
Things I learnt from this ordeal are...
Get your safety checks in order. Set up the 2-step verification. Change passwords. Don't have unnecessary log ins, or links to third party apps you don't even use. Don't click on dodgy links!
Don't pay hackers. They are cunts.
Instagram customer service is absolutely useless. I guess they can afford to lose a biggish account here and there. Truth is, they don't really care. I wonder what they had done though if Kylie Jenner lost her account.
It's not what you know but who you know. Having an internal contact is absolutely gold. And in a case of a complete hack and takeover seemingly the only way to recovery when everything else seems a lost cause.
My instafriends are real friends. And bloody good real friends. Humans made from flesh and blood. The support I received from fellow Instagrammers, some who I've met in person, and some I haven't, has been overwhelming. My commercial partners willing to set up campaigns to help me get back on my feet. People providing me with log-in details of their cat's account to get back into Instagram (which I didn't by the way, but it's the thought that counts). It's a super nice community of which I am proud to be a part of.
It's not what you know but who you know.
Don't get hacked. It sucks.
Moral of the story, don't get hacked. It sucks. Big time. And it's so hard to recover. In the end I was only gone for 2 weeks, but it felt like 2 years. Hopefully my story helps prevent an hack or two. That would have made it worth it.
Thank you all for sticking by me. You have no idea how much I appreciate it. I will continue to post pretty pictures and silly stories until I drive you nuts!