Account Recovery Standard
Accounts can get hacked. These are the standards for recovering a hacked social media account.
Document who has access
Save a record of the name and login email/phone number of all individuals with access to each of your social media accounts. This information is required to be securely stored using multi-factor verification. Be sure to include those who have access to a third-party
publishing tool (e.g., Sprout Social) as well.
Recovering a lost account
Attempt a password recovery once. Be cognizant of potentially freezing access due to too many recovery attempts.
Submit appropriate support request
Reach out to the Office of Marketing’s social media team to determine if there is a platform representative or a third-party management tool representative who can be leveraged for quicker action.
Stakeholder Rapid Outreach
Notify the following staff (1) which account was compromised; (2) if Ohio State has access to the account; and (3) what content has been posted on the account.
Depending on the severity of the situation, the Office of Marketing will notify the Social Media Community of Practice to encourage review of account security.
Re-starting account
- Archive and hide/delete any posts published without your authorization.
- Review administrative settings and managers of the affected account. Remove all suspicious or unnecessary users until the situation has been resolved.
- Review direct messaging for unauthorized use. Offer an explanation to anyone who
was contacted without authorization. Contact the Office of Marketing for consultation on a “we’re back” / “apology” messaging. - Review about descriptions, contact information, links, and all other information on account pages. Reverse any changes.
- Post messaging once approved by the Office of Marketing.
Shutting down imposter accounts
If you come across an imposter profile of an institutional social media account, immediately report the account as an imposter/impersonation within the platform and notify the Office of Marketing at socialmedia@osu.edu with (1) the name, details and link to the imposter/impersonation account; (2) the name and link to the institutional social media
account that is being impersonated.
In severe cases, the Office of Marketing social media team can leverage a third-party cyber security tool to assist with shutting down the imposter account. In most cases, a clear parody account or an account with a disclaimer in the bio does not qualify as an imposter/impersonation account.