Marketing & creative
Recover a Hacked Facebook Account
Recover a hacked Facebook account using Meta's official routes, then lock the attacker out by fixing the recovery settings most guides never mention.

Treat this as two jobs. First, regain entry. Second, evict the attacker. A password reset can restore access while an unknown email address, active session or mail-forwarding rule still gives the attacker a route back in.
Use only Meta’s official website, Facebook app and Help Center. Type addresses yourself. Do not pay a person who claims they can “recover” or “unlock” the account. No legitimate third party can guarantee that Meta will return an account, and sharing codes or identity documents can make the compromise worse.
Meta changes menus and recovery prompts. The routes below were checked against its current Help Center, but follow the wording shown in your account. Never send a login code to anyone, including someone claiming to be Meta support.
First, identify the kind of lockout
Choose the situation that matches what you can verify:
- You are still logged in on a phone, tablet or browser. This is the most useful position. Act from that known device before signing out or clearing the app.
- The password changed, but you control the linked email or phone. Use the official password-reset route and secure the email account too.
- The password and recovery details changed. Use facebook.com/hacked from a device previously used for Facebook.
- Meta disabled or suspended the account. Read the notice and use the review route it provides. A policy action is different from a forgotten password, although a compromise may have caused the activity.
If you can sign into your personal profile but lost a Page role, use the separate guide to regain Facebook business Page admin access. Do not create a second profile or send identity documents through unofficial forms to solve a Page-permission problem.
Act from any device that is still logged in
Do not log out of the last working session. Do not delete the app. Connect through a network and device you trust.
- Open Facebook settings and go to Accounts Center.
- Open Password and security.
- Change the Facebook password to a new, unique password.
- Open Where you’re logged in, select the Facebook account and end every session you do not recognize. If the interface offers an option to end all other sessions, use it after confirming the current device.
- Check the account contact information and remove any email address or phone number you did not add.
The order matters. Changing the password first creates a credential only you know; ending other sessions then removes access that might survive on another device. Meta’s current account-security guidance identifies the “Where You’re Logged In” list as the place to review recently used devices.
If Facebook blocks a sensitive change because the device appears unfamiliar or applies a security wait, do not fight the flow with repeated new devices. Follow the prompt. Meta documents that some completed security checks can involve a 24-hour access wait. That waiting period cannot be rushed by a paid outsider.

Reset the password with a linked email or phone
From a device you have used with Facebook before:
- Open the Facebook app or type facebook.com/login/identify in the browser.
- Find the account using the email address, phone number, name or username shown by the official flow.
- Select a recovery method you still control.
- Enter the code only on the Facebook app or facebook.com page you opened yourself.
- Create a unique password that is not used by email, banking or any other service.
- Continue immediately to the eviction checklist below.
If a code does not arrive, Meta’s current recovery help recommends checking spam or junk, confirming the phone has a signal, waiting a few minutes and requesting another code. Check that the displayed destination is yours. If the email address itself may be compromised, recover and secure it through the email provider’s official site before relying on it.
Do not send screenshots of the code. Do not enter it on a page opened from an unexpected message. A genuine one-time code proves control; anyone who receives it may be able to take the next recovery step.
Use Meta’s compromised-account route
When the password, email or phone has been changed, go directly to facebook.com/hacked. Meta’s current login-recovery guidance specifically recommends doing this from a device previously used to sign in.
Follow the account-finding and security prompts. Provide only information requested inside the official Facebook domain or app. The flow can differ based on the device, account history, available recovery methods and changes detected. This article cannot create a faster review route.
If the flow asks to confirm identity, use Meta’s official submission screen. Meta’s current identity-document guidance lists accepted government and non-government documents. Its rejection guidance says an image can fail when it is blurry, poorly lit, incomplete, a screenshot or photocopy, or missing the required name plus photo or date-of-birth information.
Send the minimum document set Meta requests. Check the domain before upload. Do not email an ID to an address posted in comments or messaging groups. Ignore old articles that rely on “trusted contacts”; that route is not part of the current official recovery guidance reviewed for this page.
The eviction checklist most guides omit
Run this after recovery even if the password reset appeared successful.
1. Secure the linked email account
Open the email provider’s official security page. Change its password to a different unique value, review recovery email and phone, end unknown sessions, enable multi-factor authentication and review connected applications. Email often controls password resets for every other account.
Check filters and forwarding rules. The UK National Cyber Security Centre’s hacked-account recovery guidance warns that attackers can add a forwarding rule so they receive copies of recovery messages. Remove unknown forwarding addresses, auto-delete rules and filters that hide messages from Facebook or Meta.
2. Remove unknown Facebook contact details
In Accounts Center, review personal details or contact information. Remove unknown email addresses and phone numbers. Confirm at least one secure email and phone you control, subject to the recovery options Meta offers. If an unknown contact cannot be removed, capture evidence and continue through the official security flow.
3. End active sessions
Return to Password and security, then Where you’re logged in. End unknown locations, devices and browsers. When in doubt, sign out other sessions and log back into trusted devices with the new password and two-factor method.
4. Review connected apps and websites
Open Facebook’s Apps and websites settings and remove services you do not recognize or no longer use. Review connected Instagram or other Meta accounts in Accounts Center. A removed connection may have data it obtained earlier, so contact that service separately when necessary.
5. Check payments and activity
Review Meta Pay, ad-account billing and any saved payment methods connected to the compromised profile. Look for unknown transactions, campaigns, Pages, messages, posts, comments, groups and Marketplace activity. Capture dates and references. Contact the bank or card issuer through its official channel for unauthorized charges and follow the appropriate local fraud-reporting route.
6. Review business assets and people
In the business tools you legitimately administer, review people, partners, system users, Pages, ad accounts, pixels or datasets, catalogs, domains and apps. Remove unknown access only after confirming it is not a valid agency, employee or integration. Preserve evidence and avoid deleting business data in panic.
A password reset without these checks is not finished. The attacker may have changed the recovery surface while they had access.
If the attacker reached a Page or ad account
Take three actions.
- Contain spend and publishing. Pause unknown campaigns if you retain authorized access, review scheduled posts and protect payment methods through the official business and bank routes.
- Preserve evidence. Record campaign, transaction, user, Page, post, time, notification and case references. Do not disclose customer data in a public complaint.
- Review business access. Remove unknown people or partners, confirm at least two trusted administrators where the organization permits it, and use Meta’s official support or business-recovery route shown in the affected account.
Unauthorized ads can create direct financial loss; malicious posts or messages can harm customers and reputation. If the personal profile is secure but Page access is missing, follow the dedicated business Page admin recovery guide.
Lock the account down
Turn on two-factor authentication
In Accounts Center, open Password and security, choose Two-factor authentication and select the Facebook account. Meta currently supports methods that can include an authentication app, security key or text message depending on account and device. Use the strongest method you can operate reliably; an authenticator app or hardware security key does not depend on ordinary SMS delivery.
Store recovery codes offline or in a secure password manager you can reach without the Facebook account. Add a second method when appropriate. The stronger method is only useful if you can recover it after a lost phone.
Use a unique stored password
Generate a long, unique password in a reputable password manager. Change every other account that reused the compromised password, beginning with email, financial services and business tools. Never approve a password-manager autofill on an unexpected domain without checking the address.
Enable alerts and maintain business redundancy
Review security checks and login-alert options in Accounts Center. Keep contact details current. For business assets, maintain at least two individually secured, authorized administrators so one profile is not the only recovery path. Do not share one login between staff.


Recognize how takeovers happen
Credential reuse: a password exposed by another service is tried against Facebook and email. Unique passwords stop one breach from becoming several.
Phishing: a message imitates a copyright notice, Page warning, blue-badge invitation, ad problem or friend request and sends the user to a fake login. Open Facebook or Meta Business tools independently instead of using the link.
Malicious software or extensions: an unsafe browser extension, application or infected device can steal credentials or session information. Remove unknown extensions and apps, update the operating system and browser, and run the device’s approved security scan before entering new credentials.
Compromised email: access to email allows password resets and hidden forwarding. Treat Facebook and its recovery email as one incident until both are secured.
What to tell customers and staff
Send a notice only when the compromise could affect them. Keep it factual:
We identified unauthorized access to a Facebook account connected with our business on [date/time zone]. We have contained the account and are reviewing activity. Please disregard unexpected messages, payment requests or links sent from it between [time window]. We will contact affected people directly if our review identifies a specific impact. Use [official channel] to verify any communication.
Do not declare that no data or payment information was affected before the review supports it. Do not publish identity documents, attacker details, private logs or speculative causes. Coordinate legal, privacy, insurance and customer communications where applicable.
When to get help
Escalate business cases when unauthorized spend continues, several administrators or assets changed, a catalog or customer inbox is affected, regulated or customer data may be exposed, or nobody can reconstruct access. Contact Meta only through official in-product, Help Center or business-support routes available to the account. Contact payment providers and relevant authorities independently where needed.
No outside agency can guarantee profile recovery or bypass Meta’s review. A legitimate administrator can help inventory assets, preserve evidence, secure remaining access, review permissions and coordinate the documented route; Meta still controls account decisions.
For help securing the business surface after profile recovery, talk to us about your Page and ad account. OVELITHUB will not ask for your personal password or one-time authentication code.
Never send us or any third party your password, identity document or one-time code. For ongoing, permission-scoped content and account administration after recovery, review marketing administration support. For a wider platform problem that is not an account takeover, use platform troubleshooting services.
Keep reading
Related insights
WordPress vs Custom CMS Development
A custom CMS buys control and a permanent maintenance bill. Compare both against your content model, team and five-year plan before you…
BPO Services for Digital Marketing: Benefits
Marketing teams stall on execution, not ideas. See which marketing functions a BPO model absorbs, what it returns in hours, and where…
What SEO Services Actually Deliver
SEO is four separate disciplines sold as one word. See what each part does, what results it can produce, and how to…



