The standard advice for a hacked Facebook account is “change your password.” That’s the first step, not the whole job. Treating it as the whole job is why so many people get compromised a second time a week later.

Facebook, like Microsoft 365 or Google Workspace, has a lot of ways attackers can take over an account and keep access: live sessions, third-party app permissions, recovery email addresses and phone numbers, Page and business portfolio access, and payment methods on ad accounts. An attacker who knows what they’re doing may plant access in several of those places before they do anything obvious. Reset the password and they may still have a way back in.

Here’s the sequence we’d actually run, in order.

Immediate actions

If you’ve been locked out entirely, start with Meta’s own recovery flow at facebook.com/hacked, from a device you’ve logged in from before if possible.

If you still have access to the account, work through the list below.

The short version

  1. Change your passwordPassword and security
  2. Terminate all other sessionsLogin activity
  3. Remove unfamiliar email addresses and phone numbers → Accounts Center → Personal details → Contact info
  4. Remove unfamiliar apps, websites, and Business IntegrationsApps and Websites
  5. Turn on 2FA, security key or authenticator app, then add a passkey → Two-factor
  6. Verify security messages from Meta → Password and security → Recent emails

That’s the personal-account job, and it often takes about ten minutes if you still have access. If a business Page or ad account is attacked, it’s an incident rather than a checklist, and there’s more below.

Two things before you start. Use a device you have reason to trust: if the compromise followed a suspicious download, browser extension, or unexpected login prompt, switch devices and scan the affected one. Then secure the email account tied to Facebook, with a unique password, terminated sessions, verified recovery options, and strong authentication. Review that mailbox’s forwarding rules, filters, blocked senders, and recent login activity too. An attacker who controls the inbox can reset Facebook again and hide the warnings that would tell you what they changed.

Most of what you need lives in Accounts Center, not in Facebook’s old settings menu. Go straight to accountscenter.facebook.com/password_and_security rather than clicking through. The menu path is profile picture (top right) → Settings and privacy → Accounts Center → Password and security, which is a lot of clicking when you’re in a hurry.

The same six steps, with the detail that matters

  1. Change your password, then log out of every other session. Both controls live on the Password and security page. The order matters: changing the password alone may not terminate every existing session, and a stolen session cookie may remain valid until that session is revoked.
  2. Review where you’re logged in at login activity. Click into the device list, select everything you don’t recognize, realistically everything that isn’t the device in front of you, and log those sessions out.
  3. Check the email addresses and phone numbers on the account, in Accounts Center under Personal details → Contact info. An attacker may add their own recovery email and use it to take the account back after you’ve reset everything. Remove anything unfamiliar.
  4. Review connected apps, websites, and Business Integrations. Click your profile picture in the top right, then Settings and privacy → Settings → Apps and Websites, or go directly to facebook.com/settings/?tab=applications. Remove anything you don’t recognize or no longer use. Permissions vary, but some integrations can retain access to Pages, ads, messages, or other business assets after a password change. Removing an integration stops future non-public access; it does not delete data the provider already received.
  5. Turn on two-factor authentication at two-factor. Prefer a hardware security key or authenticator app over SMS, then add a passkey if Facebook offers it on your device.
  6. Review Recent emails—in Facebook and in your mailbox. In Accounts Center, open Password and security → Recent emails. This shows security emails Meta says it sent and helps you distinguish a real account notice from a phishing message. Then search the email account tied to Facebook, including Spam or Junk, Trash or Deleted Items, and Archive or All Mail, for notices about unfamiliar logins, password resets, or changes to contact information. Missing messages or rules that automatically hide, forward, or delete Meta emails are signs that the email account may be compromised too. Some older Facebook guidance refers to a separate Login alerts switch, but the current Accounts Center may not expose that control.

If Facebook sends you a notification about an unrecognized login, it may identify the device or browser and give an approximate location. Treat the location as a clue, not proof: mobile networks and VPNs can make a legitimate login appear to come from another city. Don’t use links in the alert email. Open Facebook or Accounts Center directly, confirm the message under Recent emails, terminate any unfamiliar session under Where you’re logged in, and change your password again. If the same warning returns after that, recheck the associated email account and scan the devices and browser extensions you use to access Facebook. Meta summarizes these controls in its account security guidance.

If you can’t get back in and the recovery flow isn’t working, continue through Meta’s identity-verification process. If you lost a Page you manage, use Meta’s separate hacked Page recovery process. Be extremely cautious with anyone advertising “Facebook account recovery services.” Recovery scams commonly target people who are already victims, and no third party can guarantee that Meta will restore an account.

Use phishing-resistant authentication

When you set up 2FA, the method matters. SMS codes can be defeated by SIM swaps and by phishing kits that relay the code to an attacker in real time. An authenticator app is a real improvement. A hardware security key is stronger because it is phishing-resistant.

A passkey is also phishing-resistant, but on Facebook it is a sign-in method rather than a replacement for configuring 2FA. A passkey is bound to the domain it was created for, so a look-alike phishing site cannot use it. There’s no code to read out, retype, or hand over. It lives on your device or in its credential manager and is unlocked with your fingerprint, face, or device PIN. If the feature is available to your account, Meta manages it at accountscenter.facebook.com/passkey/management.

If you’re re-securing an account that was just taken over, enable strong 2FA and add a passkey while you’re already in there. Store your recovery codes somewhere secure and regenerate them if you think the attacker may have seen them.

The investigation generic advice misses

The checklist secures the personal account. This is the part that establishes what else the attacker reached and whether they still have access through a business asset.

Login history. Top right → Settings and privacy → Activity Log, then work through Logins and logouts and Where you’re logged in. This helps establish how long the attacker may have had access, which determines the scope of everything else.

Page and business portfolio access. Rather than relying on your login, attackers may grant their own account Facebook access or task access to Pages and other business assets linked to your account. That access survives your password change, session revocation, and 2FA enrollment because it belongs to a separate identity.

To check: switch into the business Page from the profile menu, then Settings and privacy → Settings → Page setup → Page access. Review everyone with Facebook access and task access, remove accounts you don’t recognize, and check pending invitations too, since an unaccepted invite is a foothold waiting to be claimed. Repeat this for every Page and asset in the business portfolio, not just the main one. Meta’s Business Help Center has recovery guidance for business assets specifically. Pay particular attention to anyone holding full Facebook access, since that role can add and remove other admins, including removing you.

Ad accounts. This is where the money is, and it may be the point of the compromise. Attackers can pivot from a hijacked personal account into Meta Ads Manager, attach their own payment method or use yours, and run fraudulent ad spend, often scam ads served under your brand’s name until the account gets flagged. Check for unfamiliar campaigns, users, payment methods, and changes to billing thresholds. Preserve campaign and transaction details, pause unauthorized activity, report the compromise to Meta, and promptly contact the payment-card issuer about fraudulent charges.

The pattern here is the same one we work through in email compromise investigations: a password is one credential among many, and eviction means revoking sessions, auditing every delegated grant, and hunting the persistence mechanisms the attacker left behind. The platform changes; the framework doesn’t.

If a business Page is attached, treat it as an incident

A hijacked personal profile is a bad day. A hijacked Page with an active ad account is a security incident with financial and reputational exposure:

  • Fraudulent ad spend hits a real payment method. Report it through Meta’s business support process and contact the payment-card issuer promptly.
  • Scam ads running under your brand reach your audience wearing your name. That’s the same trust exploitation as BEC, on a different channel.
  • Customer messages in the Page inbox may have been accessed or misused. Review the activity and treat sensitive conversations as potentially exposed until you determine otherwise.
  • Connected assets such as Instagram accounts, catalogs, pixels, and audience lists may all be reachable from the compromised business portfolio.

Notify your team by a channel the attacker doesn’t control, and tell your customers what happened if scam content went out under your name. Preserve screenshots, campaign IDs, transaction details, and access changes when it is safe to do so, but don’t delay containment to collect evidence. As with any incident, that evidence helps establish the scope later.

Enroll high-risk accounts in Advanced Protection ahead of time

Meta runs a program for accounts at elevated risk of targeted attack: journalists, election officials, executives, and other public figures. It’s now called Advanced Protection, though you’ll still see it referred to as Facebook Protect in older guidance and in a lot of search results. Same program, new name. It enforces stronger authentication requirements and adds monitoring for the enrolled account.

If you’re responsible for security at an organization with executives or public-facing staff on Facebook, enroll them proactively if Advanced Protection is available to their accounts. Also take the more basic step most organizations skip: know which employees hold access to the company’s social accounts, and remove the ones who left two years ago.

The broader lesson

Facebook is one SaaS account among dozens your organization depends on, and most of them work the same way, with sessions, OAuth grants, delegated admin roles, and recovery paths that all outlive a password reset. Most companies have never inventoried who holds access to what across those platforms, which means a compromise anywhere turns into an open-ended question about scope.

That inventory is what our SaaS security and access assessment produces: who has access to which platforms, which third-party apps hold standing grants, and where the orphaned admin accounts are. If you’re dealing with a live account takeover right now, whether on Facebook, Microsoft 365, or anywhere else, contact us or call (608) 448-6075.