SecurCheckCyber Centre

FACEBOOK · BRANDS · CREATORS · META

How to check a hacked Facebook account: the Meta security assessment guide

Secur Cloud ·

A Facebook profile takeover can expose conversations, spread scams and damage an organisation’s reputation. For community managers, leaders and advertisers, linked Pages and ad accounts deserve particular attention: consequences depend on the compromised profile’s Meta Business Suite permissions, potentially including control over assets or unauthorised spending.

Here is how to perform an Facebook account assessment and organise your response. At work, immediately alert Meta asset owners and IT without waiting to finish your checks.

1. Warning signs of a Facebook intrusion

  1. An unusual sign-in alert

    A successful sign-in from an unfamiliar device warrants checking in Facebook opened directly. Approximate location or a VPN may explain an unexpected country. An email displaying security@facebookmail.com is not, by itself, proof of authenticity.

  2. Unrecognised campaigns or spending

    New ads, budget changes or billing alerts appear without team approval. Check their origin with authorised staff and have unauthorised campaigns paused as soon as possible.

  3. Added managers or partners

    An administrator, partner business or permission assignment appears without your knowledge in business settings. Impact depends on access level: limited permission is not the same as full control of a Page or business portfolio.

  4. Suspicious Messenger messages or posts

    Contacts receive phishing links, fake investments or requests for money from your profile. Unauthorised changes to your password or recovery details are also important warning signs.

2. Assess the account without exposing access

Never share your password, a 2FA code or a backup code with a third-party assessment tool. Perform checks in official interfaces opened directly.

  1. Review sign-ins

    From a trusted device, open Accounts Centre, then Password and security and the section showing where you are logged in. Select the correct Facebook profile. Compare devices, dates and activity; log out of sessions you do not recognise. Labels may vary by app version.

  2. Check recent emails

    In security settings, review recent emails sent by Facebook: check the period shown in this section. A missing notification needs checking; an older message may simply be outside the displayed period. The displayed sender name alone does not authenticate a message.

  3. Review recovery and linked access

    Review email, phone, 2FA methods and linked accounts. Also examine authorised apps and remove unfamiliar access. Secure the recovery email account. For a business profile, have an administrator review people, partners and permissions on Meta Business assets. Review business integrations as well as apps and websites.

3. Secure an account you can still access

  1. Change the password and log out of unfamiliar sessions

    From the official app or website on a trusted device, choose a long, unique password stored in a password manager. Change it elsewhere if reused. Log out of unrecognised devices and review sign-ins again. Do not assume all linked access or app permissions have disappeared.

  2. Restore contact details and strengthen 2FA

    Correct altered details and methods added without approval. Enable an authenticator app or compatible security key rather than relying only on SMS. Check that no unfamiliar method was added. Keep backup codes away from a compromised device and replace them if potentially exposed. An authenticator reduces dependence on the mobile number but does not make phishing impossible.

  3. Contain the impact on your brand

    Alert your communications team and IT support. Preserve useful screenshots and times, report fraudulent content and warn followers through a trusted channel if needed. Depending on linked accounts and affected permissions, have campaigns, spending and advertising administrators reviewed; report unauthorised activity to the relevant service.

4. Locked out of an account or Page: recovery options

Open facebook.com/hacked directly and follow the official steps. Meta recommends a device you previously used to sign in; make sure it is trusted. If you suspect credential-stealing malware, have the device examined and use a clean one.

If contact details changed, review notifications sent to your previous address and verify authenticity before using any account security link. If uncertain, return to official recovery. Do not pay a supposed account recovery specialist contacted through Messenger or share codes with them.

Hijacked business Page: consult official Page recovery help. Recovering a personal profile does not automatically restore rights to a Page or business portfolio. Have ownership, partners and advertising access checked separately.

Break the attack chain through prevention

Fake Page suspension, copyright or partnership messages can be used as bait. Credential-stealing malware also puts team devices at risk. Checking a suspicious Facebook account, limiting team access and reviewing authorised apps complement device and recovery email security. Monitor the account after an incident: no checklist alone guarantees that all unauthorised access is removed.

Read also: has my account been hacked?

Read also: Instagram account assessment

Deploy SecurCheck Business to support your teams every day

Official Facebook and Meta references