Most social account takeovers aren't the result of a sophisticated attack. They're the result of a reused password from some other breach, no second factor, and account-recovery information that's out of date or easy to guess. All three are fixed with a settings page, not a security product.
The core checklist
Reducing what an attacker can use against you
- Limit what's publicly visible — a public friends list, birthday, and hometown are frequently the exact building blocks used for security-question guessing and targeted phishing.
- Be cautious with quizzes and "which X are you" apps that request account access; many exist purely to harvest connected-app permissions and profile data.
- Watch for messages from friends' accounts that feel off — a takeover often gets used to message the victim's contacts next, since a request from a familiar name is far more convincing than one from a stranger.
If an account is already compromised
Use the platform's account-recovery flow immediately, revoke all active sessions once back in, change the password, and check connected apps and account email/phone for anything the attacker may have added. Warn your contacts separately, since a compromised account is a common vector for further scams against people who trust you.
The takeaway
Social account security is almost entirely a settings-page exercise: unique password, two-factor, clean connected-apps list, current recovery info, login alerts on. None of it requires technical skill, and together it closes the overwhelming majority of how these accounts actually get taken over.