Posted on

Account-recovery impersonation that targets users already locked out

A person who cannot get into an account is unusually easy to sell a shortcut to.

The problem is immediate. The account may contain years of photos, messages, customers, contacts, saved work, or access to other services. Normal help pages suddenly feel slow, repetitive, and useless.

That is exactly when an unsolicited “recovery expert” sounds most believable.

The Federal Trade Commission’s guidance for hacked email and social-media accounts says that if you cannot log in, use the provider’s own account-recovery instructions. Its recovery guidance links directly to the official processes for major services rather than to third-party helpers.

See the FTC’s guidance for hacked email and social-media accounts.

Meta similarly directs hacked Facebook users to its own recovery flow at facebook.com/hacked, preferably from a device previously used with the account.

See Facebook’s official hacked-account recovery page.

The impostor sells certainty during uncertainty

A fake recovery helper may claim to have an internal contact, special tool, administrator access, or guaranteed method the public does not know about.

The requests that follow are the important part.

A scammer may ask for an upfront fee, a password, a login code, a backup code, personal identity information, or access to the victim’s email. Those are not proof that recovery is underway. They may simply create a second compromise on top of the first one.

The FTC warns broadly about recovery scams in which people claiming they can fix an earlier loss demand advance fees or personal and financial information.

See the FTC’s guidance on refund and recovery scams.

Start recovery from a place you already trust

The safest recovery path begins with the service itself: its app, a bookmarked help center, or a domain you independently type or verify.

Do not use a phone number, link, username, or “specialist” supplied by a stranger who found your public complaint. Do not hand over one-time codes. A recovery code is often equivalent to a key.

Account-recovery scams are unusually cruel because they arrive after the victim already has a real problem.

The scammer does not need to invent the emergency.

The lockout is real.

The scam is the stranger claiming to be the only person who can make it disappear.

Posted on

Doxxing risk and the choice to lock an account

A public account becomes less attractive when the cost of being identified can move offline.

Doxxing is the deliberate public release of identifying or sensitive information about another person, often to intimidate, shame, or punish them. Researchers distinguish it from ordinary embarrassment because the released information can expose a person’s physical location, employer, family, or other details that make further targeting possible. See Doxing: a conceptual analysis.

Recent scholarship based on interviews with victim-survivors has emphasized that the harm is not limited to one embarrassing post. Doxxing can undermine a person’s ability to control who knows what about them and can produce reputational, emotional, and physical-safety consequences. See Briony Anderson’s 2026 book Doxxed: How Privacy Abuse Harms.

Locking an account changes the exposure model

X provides a straightforward example of what this retreat looks like technically.

Its current documentation says public posts are visible to anyone, even people without an account. Protected posts are visible only to approved followers, no longer appear in third-party search engines, and are searchable on X only by the account owner and followers. See X’s public and protected post documentation.

That is a dramatic reduction in public discoverability without any requirement that the person stop posting.

A user can continue talking every day to hundreds of people while effectively disappearing from Google and from casual observers who are not already inside the follower boundary.

Privacy controls reduce exposure, not risk to zero

A locked account is not a vault.

Approved followers can still take screenshots. Material may be copied elsewhere. Previously public information may remain in archives, caches, screenshots, or other people’s posts. Public records and data brokers can expose identifying information independently of social media.

X explicitly warns that followers may capture and share protected posts.

So locking an account should not be treated as proof that doxxing has become impossible.

It is a way to reduce the number of people who can casually collect new material directly from the account.

Retreat can be a safety decision

For Dead Internet Theory, this is another reason public activity may decline while human activity continues.

A person who once posted openly may still participate constantly after protecting the account. The difference is that outsiders can no longer observe the conversation, index it, or stumble across it through search.

The visible web becomes quieter because the participant decided visibility was a liability.

That is not the same thing as leaving.

Sometimes disappearing from the public web is how somebody stays online.