
Audience Building
Part of Building an owned audience outside social platforms
Recovering audience contact after a platform account problem
Secure a troubled creator account, give subscribers a verified update route and avoid treating follower data as an email list.
If a social account is compromised or unavailable, use contact routes your audience already chose while you follow the platform’s recovery process. A secure website or existing newsletter can carry a verified status update. Neither can reveal the email addresses of followers who never subscribed or restore the platform account.
Work out what happened
A routine login failure, a suspected compromise and a suspension need different responses. Check the platform’s own notices and official recovery guidance. If you suspect compromise, secure the affected account and connected email account, review recovery options and signed-in devices, change compromised credentials, and enable multi-factor authentication where available.
For Australian account-compromise guidance, consult the Australian Cyber Security Centre’s “Recovering a compromised online account” page at cyber.gov.au. Keep using the platform’s official recovery process as well.
Remove recovery or authentication methods you do not recognise. If an account can be used to spend money, contact the relevant financial provider promptly.
Recovery may not be possible. Keep a dated record of the incident and actions taken.
For a hacked YouTube channel, use YouTube’s official recovery process. Use the official process for the platform involved. Do not give passwords or verification codes to unofficial recovery services.
Key recovery and security stats from Australian sources
- Australian Cyber Security Centre (ACSC) guidanceOfficial recovery process recommended at cyber.gov.au/report-and-recover/recover-from/account-compromise/other
- Mailchimp contact exportAvailable for existing subscribers; keep exports secure and access-limited
- ACMA spam preventionSending unsolicited messages may breach Australian spam laws; avoid using public follower data
Give readers a verified update route
If your website and mailing account are secure, post a brief notice at a familiar address. Name the affected account, explain whether messages from it should be treated cautiously and say where the next update will appear. State only what you have confirmed. Do not promise a recovery date.
Template: I can’t currently access [account name]. Treat messages from it cautiously. I’ll post confirmed updates at [familiar website address] and email existing subscribers who agreed to receive updates.
Contact existing subscribers within the permission they gave. Do not turn public profile addresses, old direct-message contacts or follower names into a new marketing list. Invite people to subscribe through a clear form if they want later updates.
If unauthorised messages were sent, warn people who may have received them through a verified channel. Describe what to ignore without repeating a suspicious link. If the mailing account itself may be compromised, secure it before sending from it.
If your existing contacts are in Mailchimp, its contact tools let you view or export them. Keep any export secure and limit access to people who need it. Do not use follower data to create a marketing list.
Restore trust in the contact route
Once access returns, inspect profile details, posts, connected applications, permissions and messages sent during the incident. Correct false information and tell readers when the original account is safe to use again. If access remains unavailable, keep the verified notice current.
Before a future incident, confirm who can update the website, who can secure the mailing account and how subscriber and suppression records can be exported. Store any export securely and limit access to people who need it.



