
Last updated: July 6, 2026
Facebook security is no longer only about protecting a profile. The same login can expose Messenger conversations, personal photographs, Marketplace deals, Pages, groups, advertising accounts, saved payment methods, business assets, and people who trust messages coming from your name.
A strong password helps, but it is not enough by itself. In real account takeovers, the first crack is often not the password screen. It may be a fake Page-violation warning, a Marketplace buyer asking for a code, a hacked friend sending a voting link, a browser extension stealing an active session, an email account forwarding security messages to an attacker, or an old agency account that still has Page access.
This guide explains how to protect a Facebook account in 2026 with passkeys, two-factor authentication, recovery codes, session reviews, Recent Emails, Meta Account or Accounts Center checks, Messenger and Marketplace scam defenses, Page-access audits, device cleanup, and a practical recovery plan if something already went wrong.
For a defensive explanation of the techniques criminals commonly use, read our guide to Facebook hacking methods and how those attacks work.
2026 interface note: Meta announced that Accounts Center is gradually evolving into Meta Account. Depending on your device, country, account type, app version, and rollout status, your menus may still say Accounts Center, or they may already show Meta Account. The exact labels can change, but the security logic remains the same: protect the login, recovery channels, sessions, connected profiles, devices, and business permissions.
Quick Facebook Security Plan
If you only have ten minutes, start with the controls that close the most common takeover routes:
- Secure your recovery email first. A hacked inbox can undo every Facebook security setting.
- Create a Facebook passkey on a private, trusted mobile device if the option is available.
- Replace any reused Facebook password with a unique password stored in a reputable password manager.
- Enable two-factor authentication with an authenticator app or hardware security key where practical.
- Generate recovery codes and store them somewhere safer than a normal phone screenshot.
- Review contact information and remove old email addresses or phone numbers you no longer control.
- Open Where you’re logged in and remove sessions you cannot explain.
- Turn on login alerts and investigate alerts that do not match your activity.
- Review Meta Account or Accounts Center for unfamiliar profiles, shared contact details, and cross-account login options.
- Audit Pages, ads, apps, games, websites, agencies, and browser extensions that still have access.
| Security layer | What it helps stop | Practical note |
|---|---|---|
| Passkey | Phishing, password guessing, and password spraying | Strong on supported private devices, but fallback methods still matter |
| Unique password | Credential stuffing from other leaked websites | Use a password manager instead of memorable variations |
| Authenticator app or security key | Logins attempted with a stolen password | Save recovery codes before replacing your phone |
| Recovery email security | Password resets, hidden alerts, and recovery hijacking | Check forwarding rules and deleted security emails |
| Session review | Stolen cookies, old shared computers, and forgotten logins | Do not judge by city alone; compare device, time, and activity |
| Recent Emails | Fake Meta warnings and phishing appeals | Verify the warning inside Facebook instead of trusting the message |
| Marketplace caution | Fake courier links, payment screenshots, and code scams | Facebook codes are never for confirming a sale |
| Page access audit | Rogue admins, agencies, ad spending, and Page theft | Review full control, task access, partners, and payment methods |
| Device cleanup | Keyloggers, malicious extensions, and session stealers | If sessions return after password changes, inspect the device |
What Actually Gets Facebook Accounts Stolen
Most Facebook takeovers are not dramatic Hollywood-style hacks. They are usually a chain of small mistakes, weak recovery routes, or convincing social engineering.
Common takeover patterns include:
- Fake Page violation notices: A Page owner receives a warning that a Page will be deleted unless they appeal through an external form.
- Marketplace code scams: A buyer asks for a phone number, then says a code was sent to “verify” the seller. The code is actually for account access.
- Compromised friends: A real friend’s account sends a voting link, video link, emergency money request, or account-recovery story.
- Password reuse: A password leaked from another site is automatically tested against Facebook.
- Recovery email compromise: The attacker uses the inbox to request password resets, delete alerts, or hide account-change emails.
- Session theft: Malware or a browser extension copies an already logged-in session, so the attacker may not need the password again.
- SIM swapping: A criminal transfers the phone number and receives SMS-based recovery or authentication messages.
- Old connected apps: Forgotten games, websites, tools, dashboards, or integrations retain permissions nobody reviews.
- Business-access abuse: A former agency, employee, partner, or compromised colleague still has Page or ad-account access.
- Recovery scammers: Someone promises to restore a hacked account for money, codes, remote device access, or identity documents.
The lesson is simple: do not protect only the password. Protect the email, phone number, active sessions, trusted devices, connected Meta profiles, browser extensions, and every Page or business asset controlled by the account.
1. Create a Facebook Passkey
A passkey replaces password entry on supported devices with the same trusted method used to unlock the device, such as a fingerprint, face scan, device PIN, or device password. Because the passkey is tied to the legitimate service, it is much harder for a fake Facebook page to steal than a typed password.
How to create a Facebook passkey
- Open the Facebook mobile app on a private device you control.
- Open Menu.
- Select Settings & privacy, then Settings.
- Open Accounts Center or Meta Account.
- Select Password and security.
- Select Passkey.
- Choose the Facebook account.
- Follow the device prompts to create and save the passkey.
Read Facebook’s official passkey setup instructions
Do not create a passkey on the wrong device
Create the passkey only on a device you actually control. Avoid:
- A shared family tablet without separate profiles.
- A work device where the employer controls the profile.
- A borrowed phone.
- A repaired or second-hand device you have not reset.
- A public computer or public kiosk.
The practical mistake is treating passkeys as magic. A passkey protects the front door, but it does not fix a compromised recovery email, a stolen active session, a malicious browser extension, or a Page administrator who still has full control.
If the passkey option is missing
Do not chase unofficial apps, browser extensions, or “Facebook passkey activators.” Availability can depend on rollout status, device support, app version, and account setup. Keep the Facebook app and operating system updated, then rely on a unique password, 2FA, recovery codes, session reviews, and recovery-email protection until the option appears.
2. Use a Unique Password and Password Manager
Even with a passkey, keep a strong Facebook password because passwords may still exist as a fallback on unsupported devices or during recovery.
The most important part is not whether the password looks complicated. It is whether the password is unique. A complicated reused password can still be dangerous if it was leaked from a forum, online store, game account, old email provider, or hacked application.
Good Facebook password rules
- Use a password that belongs only to Facebook or the relevant Meta login.
- Generate it through a reputable password manager.
- Do not base it on your birthday, partner, pet, hometown, football club, phone number, or Page name.
- Do not reuse the same password for email, Instagram, hosting, banking, or business tools.
- Do not store it in Messenger, screenshots, spreadsheets, plain notes, or agency chat history.
- Do not share it with employees, relatives, freelancers, agencies, or friends.
How to change your Facebook password
- Open Settings & privacy > Settings.
- Select Accounts Center or Meta Account.
- Open Password and security.
- Select Change password.
- Choose the Facebook account.
- Enter the current password and a new unique password.
- Save the change.
Read Facebook’s official password instructions
Do not rotate a strong password into predictable versions like Summer2026!, Summer2026!!, and Winter2026!. Change the password when it is weak, reused, exposed, shared, entered into a suspicious page, or connected with signs of compromise.
3. Enable Two-Factor Authentication
Two-factor authentication adds another verification step when Facebook detects a login from a browser or device it does not recognize. A stolen password should not be enough by itself.
Facebook may offer:
- Hardware security key: A physical USB, NFC, or compatible security device. This is a strong option for Page owners, advertisers, public figures, and high-risk accounts.
- Authentication app: A code-generating app. This is the most practical strong option for many users.
- SMS: A code sent to a mobile number. It is better than password-only access, but weaker than an authenticator app or security key because the phone number can be lost, ported, or SIM-swapped.
How to enable Facebook two-factor authentication
- Open Settings & privacy > Settings.
- Select Accounts Center or Meta Account.
- Open Password and security.
- Select Two-factor authentication.
- Choose the Facebook account.
- Select a security key, authentication app, or SMS.
- Complete the setup.
- Test the method before signing out of every trusted device.
Read how Facebook two-factor authentication works
The phone-replacement trap
A common lockout happens when someone enables 2FA, later replaces or resets the phone, then discovers the authentication app did not transfer. Before replacing, selling, repairing, or factory-resetting your phone:
- Check whether your authenticator app is backed up or synchronized.
- Save Facebook recovery codes.
- Confirm that the recovery email is current and secure.
- Keep at least one trusted device signed in until the new setup is tested.
- Remove the old phone only after the new authentication method works.
Never read a two-factor code to anyone who contacts you. A real support process should not require a private code through Messenger, WhatsApp, Telegram, email, phone call, comment, or Marketplace chat.
4. Save Facebook Recovery Codes Before You Need Them
Facebook can provide ten single-use recovery codes for accounts protected by two-factor authentication. These codes matter most when your phone is lost, damaged, stolen, reset, or unavailable.
How to generate recovery codes
- Open Accounts Center or Meta Account.
- Select Password and security.
- Open Two-factor authentication.
- Choose the Facebook account.
- Open Additional methods.
- Select Recovery codes.
- Generate the codes and store them securely.
Read Facebook’s recovery-code instructions
Do not store recovery codes only as a normal screenshot
A screenshot may sync to cloud photos, appear in search previews, remain in Recently Deleted, or be visible to anyone who unlocks the phone. Better options include:
- An encrypted password manager.
- A printed copy stored privately.
- An encrypted offline document.
- A secure emergency kit stored away from the phone.
If you think anyone else saw the codes, generate a new set. New recovery codes invalidate the old ones.
5. Secure the Recovery Email and Phone Number
If the recovery email is weak, the Facebook account is weak. An attacker who controls the email inbox may request password resets, read security alerts, delete warnings, or add forwarding rules that keep copying future security messages.
Secure the email account as seriously as Facebook
- Use an email password that is different from the Facebook password.
- Enable a passkey, authenticator app, or hardware security key where available.
- Review active email sessions and trusted devices.
- Remove unknown forwarding rules and filters.
- Check deleted and archived folders for missing security messages.
- Remove old recovery phone numbers and email addresses.
- Review connected apps and app-specific passwords.
- Save the email provider’s recovery codes.
The forwarding-rule check is easy to overlook. Someone may no longer know your email password but still receive copies of future Facebook alerts if a hidden rule remains active.
Review Facebook contact information
- Open Accounts Center or Meta Account.
- Select Personal details.
- Open Contact info.
- Review every email address and mobile number.
- Remove anything you no longer control.
- Add and verify a current email address when needed.
Manage email addresses connected to Facebook
Manage mobile numbers connected to Facebook
Do not rely only on an employer-controlled inbox, a school email you may lose, a temporary email, a shared family inbox, or a number you may soon cancel.
6. Review Meta Account or Accounts Center Connections
Facebook may be connected with Instagram, Messenger, WhatsApp, Meta Horizon, Threads, Meta AI, or Meta devices through Accounts Center or Meta Account. This can simplify login, but it also creates more places to review.
Read Meta’s announcement about Meta Account
Check these connection details
- Which Facebook, Instagram, Messenger, WhatsApp, and other Meta profiles are present.
- Whether one account can log in to another.
- Which email addresses and phone numbers are shared.
- Whether a single Meta Account password is being used.
- Whether WhatsApp is connected or remains separate.
- Whether an unfamiliar profile, device, passkey, or recovery method appeared.
A practical warning sign is not always “unknown Facebook login.” It may be an unfamiliar Instagram profile, Meta Account connection, shared email address, or login method that gives the attacker a path back after the Facebook password is changed.
Remove connections you do not recognize. Then secure every account that remains connected. A weak connected profile or inbox can undermine a strong Facebook setup.
7. Run Facebook Security Checkup
Facebook Security Checkup is useful because it gathers several important protections into one guided review. Depending on your account and rollout, it may cover password strength, two-factor authentication, login alerts, and personalized security recommendations.
Use Security Checkup after:
- Receiving an unfamiliar login alert.
- Getting a password-reset email you did not request.
- Changing the Facebook password.
- Adding a new phone, computer, passkey, or authentication method.
- Removing malware or a suspicious browser extension.
- Recovering a compromised account.
- Changing the primary email address or phone number.
- Removing a Page administrator, agency, or business partner.
Open Facebook Security Checkup
Security Checkup is not the whole audit. It may not catch every Page permission, ad campaign, payment method, Marketplace conversation, browser extension, or email forwarding rule. Treat it as the starting point, not the finish line.
8. Review Every Active Login Session
Where you’re logged in lists active or recent Facebook sessions. A session may show device type, browser or app, approximate location, and time of activity.
How to review Facebook sessions
- Open Settings & privacy > Settings.
- Select Accounts Center or Meta Account.
- Open Password and security.
- Select Where you’re logged in.
- Choose the Facebook account.
- Inspect each device and session.
- Log out individual sessions or select multiple devices to remove.
Read Facebook’s instructions for logging out other devices
Do not panic over one weird city
Facebook location can be approximate. Mobile carriers, VPNs, internet-provider routing, travel, and nearby network gateways can make a real login look like it came from another city.
Compare more than the location:
- Is the device type familiar?
- Is the browser or app familiar?
- Does the time match your activity?
- Were you travelling, using mobile data, or using a VPN?
- Did posts, messages, settings, ads, or Page access change at the same time?
An unfamiliar city on your own phone is less suspicious than an unfamiliar Windows browser at 3 AM followed by a new Page admin, changed recovery email, or messages sent to friends.
If sessions come back after you remove them
This is one of the most important practical warning signs. If an unknown session returns after password changes, consider:
- The recovery email may still be compromised.
- A browser extension may be stealing sessions.
- Malware may be active on a device you still use.
- A connected Meta profile may provide another route back.
- A business integration or Page partner may still have access.
- You may be changing the password on the infected device.
Move to a clean device, secure the email first, then change the Facebook password and remove sessions again.
9. Enable and Investigate Login Alerts
Login alerts can warn you when Facebook detects access from a device or browser it does not recognize.
When an unfamiliar alert appears
- Do not click the alert link if it came by email or message.
- Open Facebook directly through the app or by typing the address yourself.
- Review Where you’re logged in.
- Select This wasn’t me when Facebook provides the option.
- Change the password if the access is not yours.
- Review recovery details, authentication methods, Pages, ads, apps, and connected accounts.
Do not dismiss an alert just because the password still works. Some attackers prefer quiet access and avoid changing the password until they finish reading messages, adding Page access, sending scams, or preparing ad-account abuse.
10. Verify Facebook and Meta Emails Inside Facebook
A sender name, Meta logo, and official-looking address are not enough. The safer method is to check whether Facebook records sending the message.
How to verify a Facebook email
- Do not click the message link.
- Open Facebook directly.
- Open Accounts Center or Meta Account > Password and security > Recent emails, or visit Facebook’s Recent Emails security page.
- Check whether Facebook records sending the message.
- Review the claimed problem inside Facebook, Account Status, Page settings, or Meta Business Support Home.
Read Facebook’s official email-verification instructions
Meta currently identifies official correspondence as coming from domains or subdomains associated with:
fb.comfacebook.comfacebookmail.cominstagram.commeta.com
Even then, do not rely only on the sender. Email display names can mislead, inboxes can be compromised, and links can be disguised. Facebook states that it will not request your password by email or send your password as an attachment.
Suspicious messages can be forwarded to [email protected]. Do not forward private login codes or sensitive recovery links to unrelated people.
11. Recognize Fake Meta Support, Appeal, and Page Scams
Fake Meta support messages often work because they feel urgent and specific. They may mention your Page name, recent post, ad account, trademark, copyright, or business category. That personalization does not make the message official.
Common Facebook-specific scam stories
- Your Page will be unpublished within 24 hours.
- Your account violated copyright or trademark rules.
- Your ad account requires immediate verification.
- You have been selected for Meta Verified or a special program.
- A “Meta employee” needs a code to confirm ownership.
- A friend asks you to vote in a contest.
- A video or photo allegedly shows you.
- A recovery specialist claims to know someone inside Meta.
- A form asks for your password, 2FA code, recovery code, or Page admin access.
Use the three-part verification test
- Where did it arrive? A comment, Messenger chat, tagged post, or WhatsApp message is not a safe support channel.
- Where does it send you? Do not trust a page only because it copies Meta’s design. Inspect the actual domain or open Facebook yourself.
- Can you confirm it inside Meta? Check Recent Emails, Account Status, Page settings, notifications, or Meta Business Support Home.
Read Facebook’s guidance for avoiding scams
Never provide a password, passkey approval, two-factor code, recovery code, password-reset link, email password, Page access, or remote-control access to someone claiming to be support.
12. Treat Unexpected Messenger Links and Files as Untrusted
A Messenger scam is especially convincing when it comes from a real friend’s account. The attacker may have access to old chats and can copy the friend’s writing style.
Common examples include:
- “Is this you in this video?” followed by an external link.
- A request to vote for a friend through a Facebook-looking page.
- A story that the sender needs your phone number and a code to recover their account.
- An urgent request for money, gift cards, or help with a payment.
- A file that requires a “document viewer” or browser extension.
- A Page-policy warning from an account using Meta branding.
Reading ordinary text is not normally enough to compromise your account. The danger begins when you open an external page, download a file, install software, approve a login, or disclose a code.
How to verify a strange message from a real friend
- Call them using a number you already had before the suspicious message.
- Ask a question that is not visible on their profile.
- Do not verify through a new number supplied in the suspicious chat.
- Do not send screenshots of security settings, login codes, or recovery codes.
- Warn them through another channel if you suspect their account is compromised.
13. Protect Marketplace Conversations and Payments
Marketplace scams often start with a normal-looking buyer or seller. The account may have a real profile photo and ordinary history, but the behavior is what matters.
Warning signs in Marketplace
- The buyer immediately wants to continue on WhatsApp, text, email, or Telegram.
- A fake courier, payment service, or delivery company sends a link or QR code.
- The buyer asks for your email address or phone number, then asks you to send back a code.
- A screenshot replaces a payment that you can verify inside your real banking or payment app.
- You are asked to pay an insurance, upgrade, release, verification, or courier fee.
- The buyer overpays and asks you to return the difference.
- A link claims you must sign in again to receive money.
Keep early communication inside Facebook or Messenger when possible. Meta warns that moving conversations outside Facebook makes suspected scams harder to track.
Read Facebook’s Marketplace scam guidance
The code rule for Marketplace
A Facebook code is not for confirming a buyer, proving you are real, receiving payment, unlocking a courier, or verifying a listing. If a person asks you to repeat a code that arrived on your phone or email, assume they are trying to access an account.
A buyer knowing your phone number or email address does not automatically hack you. The risk is the next step: a password reset, fake payment email, fake delivery link, or security-code request.
14. Remove Unnecessary Apps, Games, and Websites
Facebook Login makes it convenient to use apps, games, and websites, but forgotten permissions can remain for years.
Review connected services
- Open Facebook Settings.
- Find Apps and websites.
- Review active, expired, and removed connections.
- Remove anything you no longer use, recognize, or trust.
- Inspect individual permissions where available.
Review Facebook’s connected-app privacy guidance
Removing a connection stops future access according to Facebook’s current controls, but it may not delete data the developer already collected. Contact the developer separately if you want retained information removed.
Also inspect browser extensions and business integrations
Some risks do not appear only as consumer apps. Review:
- Meta Business integrations.
- Advertising and analytics tools.
- Customer-support dashboards.
- Social scheduling platforms.
- Browser extensions that can read or change data on Facebook.
- Former agencies or contractors with business access.
A browser extension with permission to read and change website data can be more dangerous than a forgotten Facebook game. Remove extensions you do not actively need.
15. Protect Browsers, Devices, and Logged-In Sessions
A secure Facebook setup cannot fully protect an infected or unlocked device. Session-stealing malware may copy authenticated browser data, allowing an attacker to return even after you change the password.
Device-security basics
- Keep the operating system, browser, Facebook app, and security software updated.
- Use a strong screen lock and enable device encryption where supported.
- Install apps only from official or trusted sources.
- Remove browser extensions you no longer use.
- Review extensions that can read or change data on websites.
- Do not install cracked apps, game cheats, “account tools,” fake ad tools, or supposed Facebook-hacking software.
- Do not grant remote-control access to unknown support workers.
- Enable remote location and erasure features on phones and laptops.
Signs the device may be the real problem
- Unknown apps, extensions, or remote-access tools are installed.
- Security software keeps turning off.
- The browser redirects to strange pages.
- New Facebook sessions return after you remove them.
- The account is compromised again immediately after password changes.
- Clipboard contents, pop-ups, or login pages behave strangely.
If session theft or malware is suspected, stop using that device for sensitive logins. From a clean device, secure the recovery email, terminate Facebook sessions, change credentials, and review Page or business assets. Then scan, reset, or reinstall the affected device as needed.
16. Protect Your Mobile Number From SIM Swapping
A SIM-swap attack occurs when a criminal tricks or persuades a mobile provider into moving your phone number to another SIM or eSIM. If your Facebook recovery or two-factor setup depends on SMS, the attacker may then receive messages intended for you.
Reduce the risk by:
- Using a strong password for your mobile-provider account.
- Adding a carrier PIN, port-out lock, or account-change restriction where available.
- Removing unnecessary personal details from public profiles.
- Using an authenticator app, passkey, or security key over SMS where practical.
- Investigating an unexplained loss of mobile service immediately.
You may also want to know how cellphone activity can be monitored without the user noticing.
If your phone suddenly loses service while nearby phones still work:
- Contact the carrier through an official number or physical store.
- Ask whether the SIM, eSIM, or porting status changed.
- Secure email, Facebook, banking, and other important accounts from a trusted device.
- Review recovery details and active sessions.
17. Avoid Unsafe Shared and Public Devices
The safest approach is not to access Facebook from an internet café, hotel terminal, public kiosk, school computer, workplace device you do not control, or borrowed computer.
Private browsing can reduce local history after the window closes, but it does not protect against:
- Keyloggers.
- Screen recording.
- Malicious browser extensions.
- Remote administration.
- A compromised operating system.
- A fake login page.
- Someone physically watching the screen.
If you have no safe alternative:
- Use a private-browsing window.
- Do not save the password.
- Do not create a passkey.
- Do not mark the device as trusted.
- Do not enter recovery codes.
- Sign out manually when finished.
- Close every private window.
- Review active sessions from your own device afterward.
Never manage Page ownership, advertising payments, business access, or recovery settings from an untrusted public device.
18. Reduce Social-Engineering Opportunities
Attackers use public information to make scams feel personal. They may mention your workplace, Page name, family, hometown, current trip, recent listing, business partner, or visible email address.
Review the visibility of:
- Date of birth.
- Email addresses and phone numbers.
- Home address and workplace.
- Family relationships.
- Travel plans and live location.
- Answers that resemble verification questions.
- Page administrators and agency relationships.
- Posts revealing which devices, banks, carriers, or services you use.
Privacy settings do not directly stop password theft, but reducing unnecessary exposure makes targeted phishing, impersonation, and carrier fraud more difficult.
Read our broader Online Fraud Prevention Guide for additional scam-prevention measures.
Do not trust a request only because it came from a friend
A friend’s account may already be compromised. Verify through another channel when someone asks for:
- A login or recovery code.
- Your phone number followed by a code.
- Money, gift cards, cryptocurrency, or an urgent transfer.
- A vote in a contest.
- Help recovering their Facebook account.
- Opening a video, archive, document, or browser extension.
- Adding them as a Page administrator or business partner.
19. Protect Facebook Pages, Ads, and Business Assets
For a business owner, the personal Facebook profile can be the key to Pages, groups, advertising accounts, pixels, catalogs, datasets, payment methods, Messenger inboxes, and Meta Business Suite. A profile takeover can therefore become a financial and operational incident.
Understand Page access before granting it
Someone with full control may be able to manage settings, add or remove people, remove the owner, connect accounts, manage ads, or potentially delete the Page. Task access can be safer when someone only needs limited business-tool access.
Review Facebook’s explanation of Page access
Business-access rules that prevent expensive mistakes
- Give every worker an individual account; never share the owner’s password.
- Require two-factor authentication for every administrator and collaborator.
- Reserve full control for the smallest practical number of trusted people.
- Use task or partial access when full control is unnecessary.
- Remove former employees, agencies, freelancers, and vendors immediately.
- Review people, partners, system users, and business portfolios regularly.
- Keep at least two trusted administrators where appropriate, but do not give broad access to convenience accounts.
Verify business warnings inside Meta
A common scam says a Page violated policy and will be deleted unless an appeal form is completed. The form may copy Meta branding and request a password, code, downloadable “case document,” or Page access.
Instead:
- Open Meta Business Suite or Business Support Home independently.
- Check Account Status, Page Quality, support cases, notifications, and Recent Emails.
- Review the actual Page access and business-partner lists.
- Do not add an unknown “Meta partner” to solve a warning.
Audit advertising and payment activity
An attacker may leave the personal profile looking normal while abusing the ad account. Review:
- Active, scheduled, and recently edited campaigns.
- Daily and account spending limits.
- Payment methods and billing activity.
- New advertisers, partners, agencies, or system users.
- Pixels, catalogs, datasets, domains, and linked Instagram profiles.
- Automated rules that could restart spending.
If a Page was taken over, use Facebook’s official recovery route rather than paying a third-party “Page recovery expert.”
Recover a hacked Facebook Page you manage
20. Enable Advanced Protection If Available
Facebook Protect was renamed Advanced Protection. It is designed for selected accounts that may face elevated risk and can require stronger security measures.
Availability is not universal. If Facebook invites you to enable it:
- Do not rely only on the email link.
- Open Facebook directly.
- Check whether Advanced Protection appears in account security settings.
- Verify the invitation through Recent Emails.
- Complete the required review.
Read Facebook’s Advanced Protection guidance
Even with Advanced Protection, still review recovery details, active sessions, business permissions, connected applications, and trusted devices.
Before You Log Out of Everything
Many guides say “log out of all devices” immediately. That can be correct when you clearly see an attacker, but there is one practical warning: if you are close to being locked out and only one trusted device still works, do not destroy your last recovery path before you are ready.
Before logging out of every session, make sure you have:
- Access to the recovery email.
- Access to the phone number or stronger 2FA method.
- Saved recovery codes.
- Confirmed your password manager entry.
- Access to a clean device.
- Reviewed whether the current device is the only trusted recovery session.
Once recovery paths are safe, remove unfamiliar sessions. If you are already certain the attacker is active, prioritize containment from a clean device.
Signs Your Facebook Account May Be Hacked
A takeover does not always start with the password failing. Quiet changes can appear first.
- Your password no longer works.
- Facebook reports an email, phone number, password, passkey, or authentication change you did not make.
- An unfamiliar authenticator app, security key, recovery method, or passkey appears.
- Unknown devices appear under Where you’re logged in.
- Messages, posts, comments, reactions, friend requests, or group activity appear without your action.
- Your name, profile image, biography, or personal details change.
- Friends receive voting links, investment offers, money requests, or recovery stories from you.
- An unfamiliar Instagram, WhatsApp, or Meta profile appears in Accounts Center or Meta Account.
- Unknown apps, websites, or business integrations are connected.
- A Page gains a new administrator, partner, or person with full control.
- You lose access to a Page while the personal profile still works.
- Unexpected ad campaigns, invoices, spending, or card charges appear.
- Marketplace listings or conversations appear that you did not create.
- You receive login, password-reset, or recovery codes you did not request.
- Removed sessions reappear soon afterward.
One approximate location mismatch is not proof. A combination of device, time, browser, account activity, recovery changes, Page changes, and business events provides stronger evidence.
You Might be Interested to Learn:
>> How Instagram Accounts Get Hacked
What to Do If Your Facebook Account Is Hacked
If you can still access the account
The order matters. Do not spend ten minutes deleting spam while the attacker still controls the recovery inbox, an active session, or business access.
- Move to a clean, trusted device. Avoid changing credentials on a device that may contain malware.
- Secure the recovery email. Change its password, remove unknown sessions, remove forwarding rules, and review recovery details.
- Preserve evidence. Save alerts, session details, messages, business changes, and ad charges before deleting everything.
- Terminate unfamiliar Facebook sessions. Use Where you’re logged in.
- Change the Facebook password. Create a new unique password.
- Review contact information. Remove email addresses and phone numbers you do not recognize.
- Review authentication methods. Remove unknown authenticator apps, security keys, passkeys, or phone numbers.
- Configure your own strong authentication. Use an authenticator app or security key where practical.
- Generate new recovery codes. Store the replacement set securely.
- Review Meta Account or Accounts Center. Remove unfamiliar profiles and cross-account login connections.
- Review apps and business integrations. Remove anything suspicious or obsolete.
- Audit Pages and business assets. Check access, partners, system users, ads, spending limits, payment methods, and linked accounts.
- Pause unauthorized advertising. Preserve invoices and campaign IDs before cleanup.
- Warn contacts and customers. Tell them not to trust recent links, payment requests, Marketplace messages, or investment offers.
- Clean affected devices. Remove malware, suspicious extensions, and unknown remote-access tools; reset the system if necessary.
If you cannot access the account
- Use a device, browser, and internet connection previously used with Facebook where possible.
- Type facebook.com/hacked directly into the browser.
- Follow the prompts to identify and recover the account.
- Check the original email inbox for a legitimate Facebook message about an unauthorized email or password change.
- Complete Facebook’s identity-confirmation process when offered.
- After regaining access, perform the complete session, recovery, app, Page, and advertising audit above.
Do not pay someone on Facebook, Instagram, Telegram, WhatsApp, Reddit, or another platform who guarantees recovery or claims to bypass Meta’s ownership checks. A legitimate professional can help secure devices, preserve evidence, and guide you through the official process, but cannot promise secret access to Meta’s internal systems.
If a Page or advertising account was affected
- Check who has full, partial, and task access.
- Remove rogue people, partners, agencies, and system users.
- Inspect recently changed Page settings and linked accounts.
- Pause unauthorized campaigns and review automated rules.
- Document unexpected charges and contact the payment provider when necessary.
- Use Meta Business Support Home and the official Page-recovery process.
Preserve evidence before cleaning everything
- Security-alert emails.
- Dates, times, and unfamiliar session details.
- Messages and links sent by the attacker.
- Changed Page access and business-partner records.
- Advertising campaign IDs, invoices, and payment charges.
- Marketplace listings and conversations.
- Transaction identifiers.
- Relevant screenshots.
Facebook Security Checklist
- Create a Facebook passkey on a private trusted device when available.
- Use a unique password stored in a reputable password manager.
- Enable two-factor authentication with an authenticator app or security key.
- Save recovery codes away from the authentication phone.
- Protect the recovery email with a different password and strong authentication.
- Check email forwarding rules, deleted security messages, and connected email apps.
- Review email addresses and mobile numbers connected to Facebook.
- Review Meta Account or Accounts Center for unfamiliar profiles and login connections.
- Run Security Checkup after important account or device changes.
- Enable alerts for unrecognized logins.
- Review active sessions regularly and terminate unfamiliar ones.
- Verify urgent messages through Recent Emails, Account Status, or Business Support Home.
- Never send a password, authentication code, recovery code, or login approval to support.
- Verify unusual Messenger requests through another channel.
- Keep Marketplace conversations inside Facebook or Messenger when practical.
- Never use a Facebook security code to confirm a Marketplace payment.
- Remove old apps, games, websites, integrations, and browser extensions.
- Keep phones, computers, browsers, and Facebook updated.
- Protect the carrier account with a PIN or port-out lock.
- Avoid sensitive account management on public or shared computers.
- Minimize public personal information that supports targeted scams.
- Give Page users only the access they need.
- Require two-factor authentication for Page and business administrators.
- Remove former employees, agencies, contractors, and partners promptly.
- Review ad campaigns, spending limits, payment methods, and business assets.
- Know how to reach
facebook.com/hackedbefore an emergency.
Frequently Asked Questions
Why might the Facebook passkey option be missing?
Passkeys may not yet be available for every account, device, country, or app version. Keep Facebook and your operating system updated, but do not install third-party tools that claim to unlock Facebook passkeys.
Is a Facebook passkey better than a password?
Yes, when available on a trusted device. A passkey is more resistant to guessing, reuse, and conventional phishing. However, it does not remove the need to secure fallback passwords, recovery email, active sessions, connected accounts, and devices.
Should I use a passkey and two-factor authentication together?
Yes. A passkey strengthens the login itself, while two-factor authentication, recovery codes, and a secure recovery email help protect fallback and recovery scenarios.
Can Facebook still be hacked when two-factor authentication is enabled?
Yes. Two-factor authentication reduces risk, but attackers may steal active sessions, compromise the recovery email, trick the owner into sharing a code, access an unlocked device, abuse a connected app, or compromise a Page administrator.
Is an authenticator app safer than SMS?
Usually yes. An authenticator app is less exposed to SIM swapping than SMS. SMS is still better than password-only access, but it depends on the security of the phone number and mobile-provider account.
What if Facebook does not send my SMS code?
Check whether your authenticator app, login approval, recovery codes, or another trusted device can be used instead. Also check mobile signal, spam folders, rate limits, and whether the phone number on the account is still correct. Do not enter your password into a random page that appears while searching for a fix.
What happens if I lose the phone containing my authenticator app?
Use a recovery code, another configured method, a trusted logged-in device, or Facebook’s official recovery process. This is why backup codes should be saved before the phone is lost, reset, repaired, or replaced.
How many Facebook recovery codes are provided?
Facebook currently provides ten single-use recovery codes. Generating a new set invalidates the old set.
I received a Facebook code I did not request. Am I already hacked?
Not necessarily. Someone may have entered your email or phone number during a login or recovery attempt. Do not share the code. Review Recent Emails, active sessions, contact information, authentication methods, and Page or business activity.
What should I do if Facebook asks for an authenticator code I never configured?
Treat it as possible compromise. Try recovery from a familiar device, visit facebook.com/hacked, and follow the official prompts. Do not pay anyone who claims they can manually remove the unknown authenticator for you.
Why does Facebook show a login location where I have never been?
Location is estimated from network information and may reflect a mobile carrier, VPN server, internet-provider gateway, or nearby city. Compare device, browser, time, and account activity before deciding.
Is an email from facebookmail.com always safe?
facebookmail.com is an official Meta email-domain family, but you should still verify sensitive messages through Facebook’s Recent Emails area and open the claimed issue directly inside Facebook.
Will Facebook ever ask for my password by email?
Facebook says it will not request your password by email or send your password as an attachment. Treat those requests as phishing.
Can a Facebook employee ask me for a two-factor or recovery code?
No legitimate support process should require you to send private login, authentication, or recovery codes through email, Messenger, WhatsApp, Telegram, comments, or phone calls.
Does changing my Facebook password log every attacker out?
Do not rely on that alone. Review Where you’re logged in, terminate unfamiliar sessions, secure the recovery email, remove unknown authentication methods, inspect connected apps, audit business assets, and clean compromised devices.
What if removed sessions keep coming back?
Assume the attacker still has a route in. Check the recovery email, browser extensions, malware, connected Meta profiles, app permissions, Page access, and whether you are changing credentials from an infected device.
How often should I change my Facebook password?
Change it when it is weak, reused, exposed, shared, entered into a suspicious page, or connected with compromise. A long unique password does not need arbitrary frequent changes that create predictable patterns.
Can someone hack my Facebook by sending a friend request?
A friend request alone does not provide access. The risk is later social engineering: phishing links, code requests, impersonation, money requests, or fake support messages.
Can opening a Messenger message hack Facebook?
Reading ordinary text is not normally enough. Risk increases when you open external links, download files, install apps or extensions, approve a login, enter credentials into a fake page, or disclose a code.
Can a hacked friend’s Messenger account endanger mine?
Yes, through persuasion rather than automatic access. A hacked friend’s account can send convincing links or requests because the message appears to come from someone you trust.
Can a Marketplace buyer hack me using only my phone number?
A phone number alone is usually not enough. The danger is when the buyer uses it for a password-reset attempt or asks you to send back a code. Never share Facebook codes to confirm a sale.
Why should Marketplace conversations stay inside Facebook or Messenger?
Keeping communication on-platform preserves context and makes suspicious activity easier to report. Moving to text, email, WhatsApp, or Telegram can make scams harder to track.
Does incognito mode protect Facebook from hackers?
No. Incognito mainly limits local browsing history and cookies after the private window closes. It does not stop phishing, keyloggers, malicious extensions, screen recording, remote administration, or a compromised computer.
Can antivirus prevent Facebook phishing or session theft?
Security software may block known malicious files and websites, but it cannot protect you if you willingly enter credentials into a convincing fake page or send a security code to a scammer.
Should I remove my phone number from Facebook?
A phone number can help with recovery and alerts, but it also depends on carrier security. Keep only numbers you control, protect the carrier account, and maintain a secure email recovery route.
Can a connected Instagram or Meta profile create additional risk?
Yes. Shared login, contact information, or connected profiles can create recovery and impersonation routes. Review every profile in Accounts Center or Meta Account and secure each one.
Does removing a connected Facebook app delete all data held by that company?
Not necessarily. Removing access stops the connection according to Facebook’s platform controls, but the developer may retain information collected previously. Contact the developer directly for deletion requests.
How do I protect a Facebook Page from being stolen?
Require two-factor authentication, use individual accounts, limit full control, remove former workers promptly, verify business invitations, and review Page access, partners, ads, and payment methods regularly.
What should I do if an unknown person has full control of my Page?
Remove them immediately if you still have authority, review every other access level, secure legitimate administrators, inspect ads and payment methods, and use Facebook’s official hacked-Page recovery process if you were removed.
What is Facebook Advanced Protection?
Advanced Protection is the newer name for Facebook Protect. It applies stronger security requirements to selected higher-risk accounts and is not available to everyone.
Can a “recovery hacker” restore my Facebook account?
A legitimate cybersecurity professional can help inspect devices, remove malware, preserve evidence, secure email, and guide you through Meta’s official process. A third party cannot legitimately guarantee restoration or secretly bypass Meta’s ownership verification.
What is the official Facebook hacked-account address?
Type facebook.com/hacked directly into the browser. Where possible, use a device, browser, and internet connection previously associated with the account.
Final Verdict
The strongest Facebook protection is layered. A passkey and unique password protect the main login; two-factor authentication and recovery codes reduce the damage from a stolen password; a secure email protects the recovery route; session reviews reveal access that already exists; and careful Page, Marketplace, Messenger, and business controls protect the parts of Facebook that generic advice often misses.
The most important habit is independent verification. When a message threatens to delete a Page, a Marketplace buyer sends a payment link, or a friend asks for a code, do not continue inside the story created by the sender. Open Facebook yourself, check Recent Emails, Security Checkup, Account Status, Business Support Home, active sessions, Page access, and ad activity.
For personal users, this protects private messages, identity, photos, and contacts. For Page owners and advertisers, it also protects customer conversations, ad budgets, payment methods, business relationships, and brand reputation.
To secure the connected Instagram side with the same depth, read our Instagram Hacking Protection Guide.
Owners of websites, hosting plans &/or domains, check out how to protect website from hackers.
Thanks for reading!
