Your friends are messaging you about strange DMs from your account, you spotted a login alert from a country you have never visited, and the password you have typed a hundred times suddenly does not work. That sinking feeling is real, but so is the path back. If your email or phone number is still attached to the account, you can often reset your way back in within minutes, and Roblox keeps a formal door open through Customer Support. Work through the steps below in order, and do it from a device, browser, and network you have signed in from before so the system recognizes you.
One thing to settle before you start. Roblox does not publish a guaranteed recovery timeline, and it is under no obligation to assist or to restore your account. What it does set is a deadline for you. If your account is compromised, you must contact Roblox within 30 days. So move quickly and follow the genuine official process rather than any paid shortcut.
Confirm the Compromise and Slam the Door
First, verify what is actually happening so you do not panic over a glitch. Tell-tale signs of a real takeover include login alerts from unfamiliar locations, friends receiving messages or trade requests you never sent, and a password that no longer works.
If you can still log in, do not wait. Head to Settings (the gear icon at the upper right on web, or the three-dots More icon on mobile), open the Security tab, and change your password immediately to something strong. Changing the password is the fastest way to push an intruder out, because it invalidates the access they were relying on.
While you are in there, treat your email as part of the account. If the attacker reached Roblox through your inbox, securing Roblox alone is not enough.
Reset Your Password Through the Forgot Password Flow
If your password no longer works and you are locked out, use the self-service reset. This is the quickest route back in as long as a verified email or phone number is still attached to the account.
- 1.On the Roblox Login page, select "Forgot Password or Username?" to reach the Account Recovery page.
- 2.Enter your email and press Submit to receive a reset email, then press the "Reset Password" button inside that email.
- 3.If you prefer to use your phone, select the phone option, choose your country code, enter your phone number, and continue to receive an SMS code.
- 4.Follow the prompt to set a new, secure password that is not easy to guess.
Watch out for one catch. If no email or phone number was ever added to the account, this feature cannot reset your password, and you will need to contact Customer Support instead, which is covered further down. And if the attacker has already swapped the email on the account, the reset link will go to their inbox rather than yours, which is another sign you should move to the support form.
Recover a Username You No Longer Remember
Sometimes the problem is not just the password. You cannot even recall which username was attached to the account. The same flow solves this.
On the Login page, select "Forgot Password or Username?" and enter the email address on your account, then press Submit. Going through the Account Recovery process lets you see your username and reset your password in one pass. Keep that username handy, because you will need to provide it if you end up contacting support.
Clear Out Malware Before You Trust the Account Again
Resetting the password is pointless if the thing that stole it is still on your device. Roblox is explicit on this point. Get rid of any malware first, before you settle back in.
Run a full virus scan on your computer to remove harmful files and programs. Then go through your browser extensions and remove anything you do not recognize, keeping only extensions from safe and verified sources. A single rogue extension or a hidden info-stealer can quietly grab your new password the moment you type it, so this step is what makes your recovery actually stick.
Set a Strong Password and Lock In Two-Step Verification
Once you are back in and your device is clean, harden the account so this cannot happen again. Start by confirming your password is strong and not easy to guess, then turn on the feature that would have stopped most of this.
- 1.Open Settings (gear icon at the upper right on web, or the three-dots More icon on mobile).
- 2.Select the Security tab.
- 3.Enable 2-Step Verification (2SV).
- 4.Choose your primary method, either Authenticator App (recommended), Email, or Security Keys.
Roblox 2-Step Verification supports a single active primary method at a time, but recovery depends on having a backup. To preserve your ability to regain access if you lose that primary method, Roblox requires that you keep two different verification methods on the account. Without sufficient backup methods you may be unable to get back in later.
So add at least two different methods, for example a verified email ("Email Me a Code") plus an authenticator app, and save your backup (recovery) codes somewhere safe. Those codes are each single-use. Note also that if you ever generate new codes (Settings > Security, "Generate"), doing so deactivates all previously created codes, so update wherever you stored them.
If you want the strongest option, Security Keys such as a YubiKey 5, Google Titan, or your device biometrics are supported. Enabling Security Keys requires that Authenticator App 2SV is also enabled, so you keep a fallback if the physical key is ever lost.
When Two-Step Verification Itself Is Blocking You
Sometimes 2SV becomes the obstacle, especially if the attacker changed something or your codes are not arriving. The login screen gives you a few levers before you escalate.
On the 2-Step Verification login screen, use the Resend Code or Start Over options. If you are using an authenticator app, make sure you enter the code while it is currently displayed, since these codes rotate and an expired one will not work. You can also switch to another 2SV method you set up earlier, which is exactly why keeping two methods matters so much.
If you still cannot log in with a new code after following the password-reset steps, that is your signal to contact Customer Support rather than retrying endlessly.
Escalate to Roblox Customer Support When You Are Still Locked Out
If resetting does not work and you genuinely cannot get back in, the official channel is the Roblox support request. Do not create a brand-new account to report the hacked one, and do not type your username into any site that is not the genuine Roblox help domain.
From the official Roblox support site, open the Submit a Request form and choose the account or login issue type. The Customer Support team handles billing and account issue questions. When you submit, provide the following.
- 1.Your Roblox username, and list all of them if you have multiple accounts.
- 2.The device you use to access Roblox.
- 3.Where any purchase was made, if your account has billing history.
Remember the clock. Roblox states you must contact them within 30 days of the compromise. There is no published timeline for how long the review then takes, and Roblox is under no obligation to assist. It does not guarantee restoration, and only in very limited circumstances may it offer recovery of lost inventory or its approximate value. That is why the self-service reset and a clean device are worth getting right first.
Stay Safe From the Scams That Target Hacked Players
People who have just lost an account are exactly who scammers hunt for, so protect yourself during recovery as carefully as you protect the account. Never share a verification code, your password, or a 2-Step Verification code with anyone. Real Roblox support will never ask you for any of them. Ignore any paid third-party "account recovery service" promising to get you back in, because the only legitimate paths are the reset flow and the official support form.
Before you enter your password or upload anything, confirm you are on the genuine official Roblox domain. Keep your recovery work on a device, browser, and network you have used to sign in before, since a familiar setup reduces extra security challenges and makes login alerts meaningful. You can also review Roblox's own safety guidance and the account-protection section on the official Roblox help site.
Frequently Asked Questions
How long does Roblox take to recover a hacked account?
Roblox does not publish an official timeline for how long account recovery takes once you submit a request. What is documented is the deadline on your side. You must contact Roblox within 30 days of the compromise, so file your request promptly rather than waiting.
What if there was never an email or phone number on my account?
The self-service "Forgot Password or Username?" flow can only reset your password if a verified email or phone number is attached to the account. If none was ever added, that feature cannot help, and you will need to contact Roblox Customer Support by submitting a request on the official Roblox help site with your username and device details.
Will Roblox guarantee that I get my account and items back?
No. Roblox explicitly states it is under no obligation to assist and does not guarantee restoration of the account. Only in very limited circumstances may it offer recovery of lost inventory or its approximate value, so securing the account yourself is the most reliable route.
Can a paid recovery service get my Roblox account back faster?
No, and you should avoid them. The only legitimate ways back in are the official "Forgot Password or Username?" reset flow and the Roblox Support request form. No real support representative will ever ask for your password, verification code, or 2-Step Verification code, so treat any such request as a scam.
I lost access to my 2-Step Verification method. Now what?
Try the Resend Code or Start Over options on the 2-Step Verification login screen, make sure authenticator codes are entered while currently displayed, and switch to another 2SV method if you set one up. This is why Roblox wants two different methods plus saved backup (recovery) codes on the account. If you still cannot log in with a new code after the password-reset steps, contact Customer Support.
Do I need a separate parent-company account to recover Roblox?
No. A Roblox account is a first-party Roblox credential, so the entire recovery process happens through Roblox's own login, reset flow, and support form. Start your recovery from a device, browser, and network you have signed in from before, and never create a new account to report the compromised one.











