I need your help guys ( My 2010 X account was hacked)

My main account, which I opened in 2010, was hacked since July 19, and the person changed the email as well… Is there any way to find out who did that?

THIS is the EMAIL that did this to me [email protected]

After much back and forth with X, this is what I was told, as can be seen in the image below

ADMIN! I need your help to approve this post, as I need to understand what can be done to retrieve the account or at least know the user behind this attack.

X’s “we can’t verify you as owner — make a new account” is a tier-1 form letter, not a verdict. Almost everyone gets it; it’s beatable — and even if X drags its feet, you can make that stolen 2010 handle worthless and traceable. Here’s the 3-front plan. Most of it needs no login.

:stopwatch: Do this in the next 10 minutes (before the thief scrubs your name + photos)archive.today → paste x.com/YOURHANDLESave. A dated snapshot of the account still wearing your face is your #1 evidence for everything below. Repeat on Wayback → Save Page Now.


:key: FRONT 1 — beat the auto-deny (re-attack, don’t just retry)

The generic “forgot password” is the dead end you already hit. File the specific hijack routes, each with a fat proof bundle:
├─ :gem_stone: Hacked / compromised account form — the real appeal, works while locked out
├─ Can’t-access-my-email flow · 2FA-problem form — for the email/2FA the thief changed
└─ Proof X’s appeal secretly weights → the 2010 creation date + @handle, any email/phone EVER linked, X Premium / payment receipts, connected apps, old login IPs, and the big one — a phone/SIM still in your hands (X’s own reply hinted it: “contact your service provider”). Pull your 2010 Wayback profile snapshot to prove you held the handle 15 years ago.

:balance_scale: FRONT 2 — levers with legal teeth (skip tier-1 entirely)

├─ :gem_stone: Request your account info — DSAR / GDPR — X must answer (~30 days) with your creation date, every email/phone ever linked + login IPs = your ownership proof and a lead on the thief
├─ :gem_stone: Impersonation reportno login needed; a 2010 handle still running your name/photos is impersonation → confirmed reports get it suspended (the prize becomes a dead account)
├─ :gem_stone: DMCA takedown of your stolen profile pic + header — and if the thief counter-files to keep them, X forwards you their real name + mailing address
└─ FTC IdentityTheft.gov → spits out an official identity-theft report you staple to every form above.

:crossed_swords: FRONT 3 — unmask + corner them (lawful — for the report, not revenge)

:bullseye: The realistic win isn’t X reversing — it’s a police case number that subpoenas the truth.

  • :detective: Feed the hacker’s [email protected] to Epieos + Holehe + HIBP + Gravatar → linked accounts, a name, maybe a face; run the @handle through WhatsMyName. (Silent look-ups — to identify for the report, never to contact.)
  • :shopping_cart: A stolen OG 2010 handle almost always gets flipped — watch SWAPD + OGUsers; the listing exposes the seller and is evidence.
  • :postbox: File FBI IC3 (US) or your country’s cyber-crime portal → hand the case number to X’s legal / preservation portal + Microsoft’s LE portal. Police preservation → subpoena is the ONLY lawful route to the email-change records + IPs that name them. :hourglass_not_done: preservation expires — file fast.
🔵 Heavy artillery if X still stonewalls — EU / legal escalation

:warning: Straight talk: X almost never hand-reverses a “can’t verify” denial — so don’t bet on one magic form. Bet on the stack: the DSAR + the impersonation freeze + a police subpoena is what actually moves the needle, and a phone you still hold is your single best recovery card. Run all three fronts in parallel, today, under one case number.

You can’t out-argue a form letter — but a stolen handle that’s frozen, DMCA-stripped, and sitting in a police file stops being worth stealing.

Thank you so much, White hat! Just came online and am reading through this…