
If someone else has access to your Instagram account, logging them out should be your first step—but it shouldn’t be your last. Instagram lets you view every device currently signed in and remotely log out any session you don’t recognize. If you suspect your password has been stolen or reused, change it immediately to invalidate existing sessions, review your recovery email and phone number, enable two-factor authentication, and remove any suspicious third-party apps. These steps help prevent attackers from regaining access even after they’ve been signed out.
If you’ve just searched “how to log someone out of your Instagram,” chances are you’re dealing with a messy reality: a person from your past logged in, you lost your phone, or found a suspicious login from somewhere you’ve never been. And when your Instagram is tied to personal memories or your entire creator business, it feels scary.
While Instagram does give you tools to see every active login, log out devices you don’t recognize, and even force a reset across all sessions, knowing where to tap makes the difference between closing a loophole and leaving the door cracked open.
In this guide, you’ll get the exact steps to log people out of your Instagram account on iOS, Android, or the web. More importantly, you’ll learn how to stop them from getting back in.
The quickest way to take back control is by logging a single device out of your account. Instagram makes this possible directly in the app or via the browser. Let's explore how to do it below.

That device will be signed out instantly. Whoever was using it won’t get a notification from Instagram, but they’ll know soon enough when they’re prompted to log back in.
Sometimes logging out a single device isn’t enough. If you suspect your password was phished, reused, or shared, the only reliable way to cut every active session is to reset your Instagram password.
In the Instagram app:
Once changed, Instagram automatically signs you out everywhere the old password was active: phones, tablets, browsers, and third-party apps.
Take credential leaks seriously. In June 2025, researchers uncovered over 16 billion fresh login records circulating online, many of which were scraped by infostealer malware from browsers and apps.
A stolen login on Instagram can hurt your creator business plenty. Attackers can gain access to brand DMs, monetization dashboards, and ad account integrations, or perform unauthorized purchases, scam collabs, and damage your business reputation.
Sometimes you open your login activity, see a device you don’t recognize, and by the time you try to log it out, it’s too late. If an attacker has already changed your password or recovery details, you’re looking at a full account takeover.
Here’s what to do:

● In the Instagram app, go to the login screen and tap Forgot password?
● Enter your email, username, or phone number.
● Follow the recovery link Instagram sends to your registered email or SMS.

● If you still have access, go to your Profile → Menu → Accounts Center → Personal Details.
● Review your email addresses and phone numbers. If you see unknown ones, remove them and update them with your own.

● If the attacker has already locked you out, use Instagram’s account recovery tool. Try this page to gain your login credentials back.
● If the attack is in an advanced state, you'll need to verify your identity with an alternative method, like a photo, video selfie, or code sent to your original email. Sometimes, Instagram may ask you to confirm your identity with one of the multiple ID document types they accept.

Once you’ve learned how to log devices out of Instagram and get yourself back in, change your password and turn on two-factor authentication (2FA) with an authenticator app.
Then head to Accounts Center → Your information and permissions → Apps and websites to review what’s connected to your Instagram. Remove any app or service you don’t recognize. Pay extra attention to older tools or “free follower” apps.
If you’re a creator, it’s also worth thinking about what happens after recovery. Most takeovers start with a phishing link or a shady collab request in DMs, all of which Bitdefender Security for Creators can help spot those risks in real time, so you’re not constantly playing catch-up after the fact.

Many takeovers start with a fake “partnership offer” or “verification” link. Report these to Instagram to cut off the attacker’s vector. Open the message thread that contains the suspicious DM, tap and hold the specific message (or tap the “i” in the top-right corner), then select Report and the reason behind. Make sure those malicious actors get blocked after.
Instagram allows you to stay logged into up to five accounts on a single device. That’s useful if you’re juggling a personal account, a professional page, and maybe a side project. But if you don’t stay organized, it also creates risks.
If you want to log out of only one account, go to Profile → Menu (☰) → Settings → Accounts Center → Log Out for the account you want to remove. You’ll still be signed in on remaining accounts.
Instagram sessions work across devices, so once you log in, that device stays trusted until you log out or reset your password. To give you control, Instagram shows a list of all devices currently signed in, including device type, approximate location, and last active time.
Know that IP-based locations are imprecise by default. Instagram determines your primary location using your IP address, in-app activity, and tags, even without Location Services, to secure your account and personalize your experience. What matters more is whether a device is completely unfamiliar.
So, if you see “New York, NY” when you’re in New Jersey, that doesn’t automatically mean compromise; it’s just IP clustering. What does matter is if you spot a device you’ve never owned, like a Windows PC, when you only use an iPhone.

Logging someone out is just damage control. But how about never having to panic over a hijacked session or a bad link gone wrong?
Our advice is to regularly check your sessions, rotate your passwords, and keep your accounts lean. And if your Instagram is more than a hobby, it’s worth having that extra security layer in place.
Bitdefender Security for Creators offers the sort of protection you don’t think about until it saves you from losing access when it matters most. Get protected for free today
Yes. Instagram lets you remotely sign out devices connected to your account through the Login Activity page. If you see a device, browser, or location you don’t recognize, you can log it out without needing physical access to it. If you think someone knows your password, change it immediately after logging them out and enable two-factor authentication to prevent them from signing back in.
If you’re signed into another person’s Instagram account on your own device, open their profile, go to Settings and activity, scroll down, and tap Log out. If the account isn’t yours, you should also remove any saved login information from your device so it can’t be accessed again. Never access or remain signed into someone else’s account without their permission.
Open Settings and activity > Accounts Center > Password and security > Where you’re logged in (or Login Activity, depending on your app version). Review the list of active sessions and select Log out for any device you don’t recognize. Then change your password, enable two-factor authentication, and verify that your recovery email address and phone number haven’t been changed.
Go to Settings and activity > Accounts Center > Password and security > Where you’re logged in. Instagram will display every device currently signed into your account. Select the session you want to end and tap Log out. For the best protection after a suspected account compromise, also change your password, review connected apps, and enable two-factor authentication so unauthorized users can’t sign back in.
tags
The meaning of Bitdefender’s mascot, the Dacian Draco, a symbol that depicts a mythical animal with a wolf’s head and a dragon’s body, is “to watch” and to “guard with a sharp eye.”
View all posts