Facebook Account Hacked? Do These Steps in Order
Contain a hacked Facebook account: secure your email and device, use Meta's recovery flow, remove the attacker, and check for follow-on damage.
Updated
Treat it as an incident, not just a password problem
If someone changed your password or recovery details, sent messages as you, or logged in from an unfamiliar device, act in this order: secure the email account and device you will recover from, use Meta's hacked-account flow, remove unknown recovery methods and sessions, then check what happened while the account was exposed.
Do not pay a “recovery agent,” call a number found in search results, install remote-access software, or share a password or one-time code. Recovery is not guaranteed, but those actions give an attacker another route into the account.
1. Secure your email and recovery device first
Your email can be used to reset Facebook again, so recovering Facebook while the inbox is still exposed may only give the attacker another chance to take it back.
- Use a device you trust. Update its security software and run a scan if you suspect malicious software or a harmful browser extension.
- Change the email password to a new, unique one, then sign the email account out of other devices.
- Turn on two-factor authentication for the email account and confirm that its recovery phone and email belong to you.
- Check the inbox's forwarding rules, sent folder, deleted folder, and recent security activity. Remove rules and recovery details you did not create.
- Secure the phone number used for recovery too. If your phone service suddenly stopped or the number was moved without your approval, contact the carrier through a number or app you already know is genuine.
If you cannot secure the email yet, start the email provider's recovery process before trusting reset messages delivered to that inbox.
2. If you are logged out, use Meta's hacked-account flow
Open facebook.com/hacked yourself, preferably on a device you previously used to log in. Follow only the verification methods Meta shows for that account.
If the flow cannot find the account, try Meta's account-identification page. Search using an email address, phone number, name, or username previously associated with the account. If all listed contact methods are unavailable or unfamiliar, choose the no-access or hacked-account branch when it appears.
The checks are adaptive. A familiar device or location can help Meta recognize you, and an optional verification method such as a selfie video may appear in some cases. No particular method, response time, or successful recovery is promised. For non-takeover loss of access, use the broader account recovery guide.
3. If you are still logged in, preserve access and reverse changes
Do not sign out of your last trusted session until you have checked what the attacker changed. From that session:
- Save screenshots or notes of unfamiliar login alerts, changed contact details, messages, Page roles, ads, and charges before removing them.
- Review the account's email addresses and phone numbers. Remove any you do not control and restore your own recovery details where Facebook allows it.
- Review password and two-factor settings for methods you did not add.
- Open security notices from the Facebook app or by navigating to Facebook directly. Do not trust a recovery link merely because it arrived by email or message.
- Complete the hacked-account flow even if the profile still opens; access to one session does not show that the rest of the account is clean.
4. After recovery, lock out the attacker
Once you control the account and its recovery channels again:
- Change Facebook to a unique password you have not used elsewhere. The normal steps are in how to change your password.
- Review Facebook's recovery email addresses and phone numbers. Remove any you do not control and restore contact methods you own, even if you already checked them from a trusted session before recovery.
- Review where the account is logged in and end unfamiliar sessions; signing out all other sessions is the safer choice when you cannot identify them confidently.
- Turn on two-factor authentication with a method you control. Remove attacker-added methods and save fresh recovery codes somewhere secure. If the code flow fails, use the two-factor troubleshooting guide.
- Review connected apps and websites and remove anything unfamiliar.
- Check profile details, friends, Pages, groups, Marketplace activity, and any account or Page access the attacker could have changed.
A password change alone is not proof that the attacker is gone. Recovery email, active sessions, two-factor methods, connected apps, and Page or business access all need their own review.
5. Warn contacts and check for financial damage
Look through posts, comments, messages, friend requests, and deleted or archived content for activity you did not create. Tell contacts to ignore recent links, login requests, money requests, or verification-code requests sent from the account.
If the profile managed Pages, ad accounts, or payments, inspect their access lists, campaigns, billing history, and payment methods. Preserve transaction IDs and screenshots. Report unauthorized activity through the relevant Meta surface, and contact the bank, card issuer, or payment provider promptly about charges you did not authorize.
For identity theft, extortion, or financial loss, keep the evidence and report through the appropriate local authorities. In the United States, the FTC's recovery guidance and the FBI's Internet Crime Complaint Center provide next steps. A report does not guarantee account recovery or reimbursement.
6. Use the failure branch that matches what remains broken
- Facebook cannot find the account: try the identification page with earlier contact details, your profile URL, or a familiar device.
- The listed email or phone is not yours: continue through the hacked or no-access option shown; do not send a code to a contact method you do not control.
- Two-factor authentication blocks the login: use a backup code or recognised device if available, then follow the official recovery options shown. Do not ask another person to receive or relay your code.
- The attacker created an impersonating profile: use Facebook's impostor-account reporting route separately from recovery of the original account.
- A Page or business asset is still compromised: use the authenticated business or Page support surface shown for that asset. Access and support options vary; an outside “agent” cannot unlock eligibility.
There is no general public Facebook customer-service phone number to substitute for these flows. Meta may publish specialized contact routes for a particular product, account, legal issue, or jurisdiction; use one only when it appears inside the relevant Meta product or on an exact Meta Help page.
Official recovery sources
Start with Meta's hacked-account flow and hacked-account Help Center page. The flow shown for your account is the authority for the verification methods available in that case.