How to protect a handle you already own
If you hold a short or dictionary-word username, people are already trying to take it. Almost none of them attack the password — they attack the recovery email, the phone number, or the support agent. Ninety minutes of work removes nearly all of that risk.
How do you stop your username being stolen?
Secure the recovery email first, because that is how most account takeovers happen. Use a dedicated email address nobody knows, protected by a hardware security key. Enable app-based or hardware two-factor on the account itself rather than SMS, remove the phone number where the platform allows it, and audit connected third-party apps. SIM swapping defeats SMS two-factor, so it should not be your second factor.
What you need
- A password manager
- Two hardware security keys, if you can — one to carry, one in a safe place
- An authenticator app
- A fresh email address nobody has ever seen
- 1
Start with the recovery email, not the account
This is where almost every handle theft actually happens. Whoever controls the recovery email controls the account, so securing the account while leaving the recovery email on an old address you use publicly protects nothing.
- Create a new email address used for nothing else and shared with nobody
- Protect it with a hardware security key, not SMS
- Do not use it to sign up for anything, ever
- Set it as the recovery address on every valuable account
- 2
Replace SMS two-factor
SIM swapping is how high-value accounts are taken, and it is not exotic — it is a social engineering attack on a phone shop. Move to an authenticator app, or better, a hardware key.
- Hardware security key where the platform supports it
- Authenticator app where it does not
- Remove the phone number entirely where the platform allows it
- Store backup codes offline, on paper, not in the same password manager
- 3
Audit connected apps
Every scheduling tool, analytics dashboard and follower app you ever authorised still has access. Revoke everything you do not currently use, and check what the survivors can actually do.
- 4
Lock down the email provider too
Check forwarding rules, filters and recovery options on the email account itself. A common attack sets a quiet forwarding rule rather than changing the password, so nothing looks wrong for months.
- 5
Register the trademark if the handle is a brand
This is the one that matters if the worst happens. A registered trademark is what lets you get a stolen handle back, and without it recovery is substantially harder.
- 6
Document that you own it, now
Screenshots of the account, dated, with the profile and settings visible. Evidence of when you started using it. Keep it somewhere you will still have access to if the account is gone.
- 7
Never respond to verification or collaboration offers
The standard theft script is an offer: a brand partnership, a verification opportunity, a copyright warning with an appeal link. The attachment or the link is the attack. No platform ever asks for your password or a code.
How handles actually get stolen
- SIM swap, then SMS two-factor reset. The most common route for valuable accounts.
- An old recovery email that was itself compromised years ago.
- A phishing page reached from a "copyright strike" message, which is urgent by design.
- A third-party app authorised long ago and later sold or breached.
- Social engineering of platform support using leaked personal details.
- Reusing a password that appeared in a breach. Check yours.
When this stops being a DIY job
This checklist is free and you should work through it this week, whether or not you ever buy anything from us. If a handle has already been taken, that is account recovery rather than handle acquisition, and it is a different and more urgent job.
Handle servicesQuestions
Terms used here
Last reviewed . Platform processes change; we re-check every guide quarterly.