facebook hacked, how to secure facebook account

What To Do If You Were Hacked on Facebook / How To Secure Your Account

Share This Post

What To Do If You Were Hacked on Facebook — How To Secure Your Account

If your Facebook profile, Business Manager, ad account, or Page was hacked, do not assume changing your password is enough. Attackers often leave behind extra login methods, connected apps, business permissions, partner access, or backup recovery options so they can get back in later.

This guide is the clean, full audit I recommend if you want to remove hidden access and lock the account down properly.

Start here first: Run Facebook’s official recovery flow at facebook.com/hacked. That flow helps Facebook identify suspicious access and walks you through the initial recovery process.

STEP 1 Go through Accounts Center completely

Open accountscenter.facebook.com and review every section carefully.

A) Connected Experiences

Disconnect anything you do not recognize. If a connected experience is not essential, remove it.

B) Personal Details

Check your contact information and make sure only your real email addresses and phone numbers are listed.

C) Accounts

Make sure only your real Facebook, Instagram, and other Meta accounts are connected. If you see an account you do not recognize, remove it.

D) Profiles

If Facebook or Instagram profile settings open here, review them carefully for extra phone numbers or linked accounts.

E) Meta Pay

If anything payment-related is saved and you do not recognize it, remove it.

F) Password and Security

This is one of the most important sections — covered in detail in the next step.

STEP 2 Change your password and reset login access

Inside Password and Security:

  • Change your password to something long, unique, and not used anywhere else.
  • Review saved logins and remove devices or sessions you do not recognize.
  • Check passkeys and remove any you did not set up yourself.
  • Review where you are logged in and log out of everything except the device you are actively using to secure the account.

STEP 3 Rebuild two-factor authentication the right way

Do not just check whether 2FA is on. Audit every method tied to it — authenticator apps, SMS numbers, WhatsApp login factors, backup methods, trusted devices, security keys, and login alerts.

Best practice

  • Add your own authenticator app first.
  • Remove any authenticator entries you do not recognize.
  • Remove any SMS or WhatsApp number you do not fully control.
  • Clear trusted devices you no longer want trusted.
  • If you have a hardware key such as a YubiKey, this is a good time to add it.

STEP 4 Remove third-party apps and business integrations

This is one of the most common backdoors people miss. Attackers know many users run Facebook’s recovery wizard, change the password, and stop there. If a malicious app or business integration still has access, the attacker may still have a path back in.

Check everything. If you do not recognize it, remove it. If you no longer need it, remove it.

STEP 5 Check phone-number and SMS backdoors

Old mobile and SMS settings can sometimes stay around longer than you expect. Review every place where Facebook might still have an old number, text-routing option, or recovery hook. If you see a phone number you do not recognize, remove it. If SMS login or text notifications are not needed, disable them.

STEP 6 Audit business-level access very carefully

This is where serious backdoors often survive. Even if your personal profile looks clean, an attacker may still retain access through Business Manager, Page roles, shared assets, partner relationships, or system-level business users. Review these sections one by one:

What to look for

  • Unknown admins
  • Unknown employees or people with partial access
  • Partner businesses you do not recognize
  • System users you did not create
  • Ad accounts shared with unknown users or businesses
  • Pages attached to the wrong business
  • Pixels or data sources owned by the wrong entity
Important: During cleanup, require strong security for legitimate users — do not weaken security. If your business can require two-factor authentication for people with access, enable that for trusted users once cleanup is complete.

STEP 7 Audit Page access and profile access

If your Facebook Page uses the newer Page experience, review Page access closely and remove any unknown people immediately. Also review Page and business roles anywhere Meta surfaces them, because attackers sometimes add a second admin so they can restore access later.

STEP 8 Review recent security events and recovery trails

You want to know whether the attacker changed email addresses, approved devices, or triggered recovery events. For Download Your Information, request and review security and login information — that can help expose contact changes, login locations, and other account events.

STEP 9 If a backdoor will not disappear, force a recovery review

If Facebook will not let you remove a bad phone number, login method, or suspicious access point, use the recovery and review flows again. In stubborn cases, identity verification may be the only way to flush old recovery data or force a manual review.

STEP 10 What to remove immediately if you see it

  • Unknown email addresses
  • Unknown phone numbers
  • Unknown authenticator apps
  • Unknown WhatsApp login methods
  • Unknown trusted devices
  • Unknown apps or websites
  • Unknown business integrations
  • Unknown business people, admins, employees, or partners
  • Unknown system users
  • Unknown Page access
  • Unknown ad account access
  • Unknown recovery options or backup methods

Final Lockdown Checklist

After cleanup is done, make sure all of this is true:

  • Your password is new and unique.
  • Your email account is also secured with its own 2FA.
  • Only your phone numbers and email addresses remain on the account.
  • Only your own authenticator app or security key is attached.
  • All suspicious sessions are logged out.
  • All suspicious apps and business integrations are removed.
  • All suspicious business people, partners, and system users are removed.
  • Your Pages, ad accounts, and data sources are assigned only to people and businesses you trust.
  • Login alerts are enabled.
  • You have checked both standard Facebook settings and Accounts Center.

Master Link List

If your account was hacked, do not stop after changing the password. Audit every login factor, every contact method, every connected app, and every business permission. That is how you remove the hidden backdoors and keep the attacker from getting back in.


Share This Post

Leave a Comment

Search

#1 Affiliate Marketing Book

From Zero to Super Affiliate

From Zero to Super Affiliate - The newbie affiliate marketer bible

Buy Now At Amazon.com