Mon-Sat · 9:00 AM - 7:00 PM
Cyber Law

Hacked WhatsApp or Facebook Account: Recovery and FIA Complaint Process

How to get a hijacked WhatsApp, Facebook or Instagram account back, contain the damage to your contacts, and when it becomes an FIA matter.

Muhammad August 29, 2026 ~6 min read
Quick answer: Move on two tracks at once. Recovery: use the platform's own account recovery, and for WhatsApp re-register the number with an SMS code, which logs the intruder out. Containment: warn your contacts immediately, because the attacker's first move is to message them asking for money or codes. If money was taken, identity was misused, or the account is being used to harass others, report to the FIA on 1991.

Account takeovers in Pakistan almost always follow one of two patterns: the victim is tricked into sharing a six-digit verification code, or a weak and reused password is compromised. Neither is exotic, and both are recoverable if you act quickly. The urgent part is rarely the account itself; it is the messages the attacker is sending to your contacts in your name.

Recovering a hijacked WhatsApp account

  1. Reinstall and re-register. Install WhatsApp and register your number again. You will receive an SMS verification code. Entering it signs the intruder out, because a number can be active on only one phone.
  2. Never share the code. If someone messages claiming they sent it by mistake and asking you to forward it, that is the attack.
  3. Enter your two-step PIN if you had one. If the attacker set their own PIN, there is a waiting period before you can reset it - frustrating, but the account does come back.
  4. Turn on two-step verification immediately once you are back in, and add your email so a reset is possible.
  5. Check linked devices and log out anything you do not recognise.
  6. Warn your contacts and groups that messages sent during the period were not from you.

The single most common WhatsApp takeover in Pakistan is the verification code scam: a message from a hacked contact you trust, saying they accidentally sent you a code, asking you to send it back. That code is your own login. Never forward it to anyone for any reason.

Recovering Facebook and Instagram

  1. Use the official recovery flow from the login screen, not a link sent to you.
  2. Try every registered contact point - old email addresses and phone numbers you may have forgotten are attached.
  3. Use identity verification where the recovery flow offers it, which may involve submitting an identity document.
  4. If email and password were both changed, use the platform's compromised-account report route, which handles exactly this scenario.
  5. Once back in, change the password, enable two-factor authentication, review active sessions, and remove any unfamiliar connected apps, admin roles or recovery contacts the attacker added.

Where the attacker has taken over a business page or removed you as admin, the commercial stakes are higher and the recovery path is different. Document your ownership - business registration, ad account and billing records - before you start, as you will be asked to prove it.

Containing the damage

Do this in the first fifteen minutes, ahead of the recovery if necessary. The attacker's business model is not your account; it is your contact list.

  • Post a warning from any channel you still control - another platform, a group, a message from your spouse's phone.
  • Tell people the specific scam: "My WhatsApp was hacked. If you got a message from me asking for money or a code, it was not me."
  • Change passwords everywhere the same password was reused, starting with your email, which is the master key to everything else.
  • Check your bank and wallet accounts for unfamiliar activity, and act on the banking channel immediately if there is any.
  • Check password reset emails in your inbox for other services the attacker may have targeted.
How it happenedTell-tale signThe fix that prevents it
Verification code sharedA "contact" asked you to forward a six-digit codeNever forward a code; enable two-step verification
Password reusedSeveral accounts compromised at onceUnique password per account, starting with email
Phishing linkYou logged in from a link in a messageType the address or use the app, never the link
SIM swapYour phone lost service before the takeoverApp-based two-factor rather than SMS where offered
Malicious appYou installed an APK from outside the storeOfficial app stores only; review app permissions
Recover re-register / reset Contain warn contacts now Secure 2FA everywhere Report FIA if money lost
Run both tracks at once. Containment protects your contacts, which is where the actual loss usually happens.

When to involve the FIA

Recovery alone is enough for many cases. Report to the FIA where:

  • Money was obtained from you or from your contacts using the account.
  • Your identity or images are being misused to defraud or harass others.
  • You are being blackmailed with material taken from the account - see blackmail and sextortion.
  • A business account with commercial value has been taken over.
  • The account cannot be recovered and is still being used against you.

Unauthorised access to an information system is itself an offence under PECA, independent of any money lost. File through the portal or on 1991, following our online complaint walkthrough, and attach screenshots of the fraudulent messages, the recovery correspondence and any transaction records.

Making it not happen again

  • Two-factor authentication on everything, and a two-step PIN on WhatsApp. This alone defeats most takeovers.
  • Never share a verification code. There is no legitimate reason for anyone to ask.
  • Unique passwords, particularly for your primary email, which controls every reset.
  • Do not log in from links sent by message. Type the address or use the app.
  • Review linked devices and connected apps periodically.
  • Treat urgency as a warning sign. "Send it quickly" is the oldest lever in the toolkit.

Start with your email, not the social account

People instinctively rush to recover the account they noticed was compromised. That is usually the wrong order. Your primary email address is the master key: it can reset almost every other account you own, including banking apps.

Work outwards in this sequence:

  1. Email first. Change the password, enable two-factor authentication, and review forwarding rules and recovery addresses. Attackers frequently add a silent forwarding rule so they keep receiving your reset codes even after you change the password.
  2. Then banking and payment apps. Change credentials and check for new registered devices or beneficiaries.
  3. Then the compromised social account.
  4. Then everything sharing that password. If a password was reused anywhere, treat all of those accounts as compromised.

Check for a hidden email forwarding rule specifically. It is the single most commonly missed step, and it silently defeats every password change you subsequently make.

If a business account or page is taken over

Commercial takeovers are handled differently and the stakes are higher, because the attacker may be running ads on your payment method or messaging your customers.

  • Stop the spend. Contact your bank or card issuer to block the card attached to the ad account. This is the immediate financial exposure.
  • Gather ownership proof before you start - business registration, NTN, the original email used to create the page, ad billing history and invoices. You will be asked to establish ownership.
  • Use the business recovery route, not the personal one.
  • Notify customers publicly through another channel, since the attacker may be soliciting payments in your name.
  • Report to the FIA, as commercial loss and customer fraud materially strengthen the case for investigation.

Where your brand is being impersonated rather than your account taken over, a registered trademark makes platform enforcement significantly easier - see trademark registration in Pakistan.

Frequently asked questions

How do I recover a hacked WhatsApp account in Pakistan?

Reinstall WhatsApp and re-register your number. Entering the SMS verification code signs the intruder out, because a number can only be active on one device. Then enable two-step verification and warn your contacts.

Someone asked me to forward a six-digit code. Is that a scam?

Yes, always. That code is your own login verification. Nobody has a legitimate reason to ask you to forward it, including a contact whose account has itself been hacked.

What if the hacker set a two-step PIN on my WhatsApp?

There is a waiting period before the PIN can be reset, which is frustrating but does not mean the account is lost. Warn your contacts in the meantime, since the attacker retains access during that window.

Is hacking someone's account a crime in Pakistan?

Yes. Unauthorised access to an information system is an offence under the Prevention of Electronic Crimes Act 2016, independent of whether any money was taken.

Should I report a hacked account to the FIA?

Report if money was obtained from you or your contacts, your identity or images are being misused, you are being blackmailed, a business account was taken over, or the account cannot be recovered and is still being used against you.

How do I get my Facebook business page back?

Use the platform's compromised-account and page recovery routes, and gather proof of ownership first, such as business registration and ad billing records, since you will be asked to establish that the page is yours.

Sources & official references

Muhammad

Lawyers at LegalPK advising on cybercrime complaints, online harassment, digital fraud and PECA proceedings across Pakistan. PECA has been amended since 2016, so section numbers and penalties should be verified against the current text before being relied on in a filing.

Speak to a cybercrime lawyer

Account taken over?

We file FIA complaints for account takeovers, identity misuse and fraud committed through your accounts.

Talk to a lawyer

Ready to Resolve Your Legal Matters?

Get expert legal advice from Pakistan's most trusted law firm. First consultation is free.