The single most effective step is switching two-factor authentication from text messages to an authenticator app, since Instagram’s own security page lists it as the recommended method and SIM-swapping is a documented way to intercept SMS codes. Beyond that, use a unique password stored in a password manager, add a passkey now that Instagram supports them, and review which third-party apps still have access to your account. One piece of advice is worth correcting up front. Do not change your password on a fixed schedule; current guidance from NIST and Microsoft both advise against it, even though Instagram’s own help page still recommends doing it regularly.
Turn on an authenticator app, not text messages
Instagram offers three ways to receive a login code, an authenticator app, a text message, or WhatsApp, and Instagram’s own two-factor authentication help page marks the authenticator app as the recommended option, because it lets you register multiple devices to receive codes rather than being tied to one phone number. The reason to prefer it over SMS is documented rather than a bare platform preference. CISA, the US government’s cybersecurity agency, warns that SMS-based codes are vulnerable to SIM-swap attacks, where someone convinces your carrier to move your number to a device they control and receives your codes in your place. An authenticator app avoids that specific attack, since the code generates on the device itself instead of travelling over the phone network. Set it up under Settings, then Accounts Center, then Password and Security, then Two-Factor Authentication, and save the backup codes it gives you somewhere safe: they are the only way back into your account if you lose the device.

Add a passkey
Instagram added passkey support in April 2026 as part of Meta’s unified account system, meaning the same passkey already works across Instagram, Facebook, and Messenger. A passkey replaces your password with your device’s own screen lock, fingerprint, or face unlock, and it cannot be phished or guessed the way a typed password can, because there is no shared secret for an attacker to steal in the first place. Set one up under Settings, then Meta Account Settings, then Login and Security, then Passkey; you can register up to five.
Use a password manager, and stop changing your password on a schedule
A unique, randomly generated password matters more than a memorable one, because the realistic threat is your password leaking from an unrelated breach and being tried against your other accounts, not someone guessing it directly. A password manager generates and stores these so you never have to remember them.
Here is the correction worth making explicitly. Instagram’s own current help page tells users to “change your password regularly,” and recommends a password manager specifically to make regular changes easier. That advice is now behind current security guidance rather than ahead of it. NIST’s digital identity guidelines state plainly that services “shall not require subscribers to change passwords periodically,” reserving a forced change for actual evidence of compromise, and Microsoft’s own guidance agrees, warning that mandatory rotation rules push people toward weaker, more predictable passwords rather than stronger ones. Use a strong, unique password and change it only when you have a real reason, such as a breach notification.

Review which apps still have access to your account
Any third-party app or website you have ever authorized, whether for scheduling posts, buying followers, or an old game that asked for Instagram login, retains some level of access until you remove it. Instagram’s system now expires apps you have not used in 90 days automatically, cutting off their access to non-public information, though your public profile details remain visible to them regardless. To see the full current list, go to Settings, then Website permissions, then Apps and Websites, then Active, and remove anything you no longer recognize or use.
What to do if something looks wrong
If you are logged out unexpectedly, see a login you do not recognize, or notice your linked email or phone number has changed, run Instagram’s own Security Checkup from Settings, then Accounts Center, then Password and Security. It walks through your login activity, password strength, two-factor setup, and recovery contact information in one place, and it is the fastest way to confirm nothing else has been changed without your knowledge.
Frequently asked questions
Should I really stop changing my password every few months? Yes, according to current NIST and Microsoft guidance, provided the password is strong and unique to begin with. Change it on evidence of a problem, not on a schedule.
Is SMS two-factor authentication useless? No, it is still far better than no two-factor authentication at all. It is simply weaker than an authenticator app specifically because of the SIM-swap risk, so use the app-based option where Instagram offers a choice.
Do I need both a passkey and two-factor authentication? A passkey on its own already replaces the password-plus-code login flow for that device. Keeping two-factor authentication active as well covers you on devices where you have not set up the passkey.

I am the chief editor of TheLeaker. I also maintain the backend stuff of the site. I’m a tech enthusiast and loves to do Python coding in my free time. I have worked at many giant publications like XDA Developers and NXTtech before starting TheLeaker.
You can get in touch with me at Garv[at]theleaker.com.
