Skip to main content

Under attack · Facebook and Meta ads

Facebook ad account hacked? Start here.

Choose what was affected and follow the relevant steps to contain the incident, recover access, inspect connected assets and secure the account.

Before you go further

  • AdFence is an independent advertising-security platform. It is not Meta, is not affiliated with or endorsed by Meta, and cannot access, restore or recover your account through this guide. Account access and restoration decisions remain with Meta.
  • This guide cannot promise account recovery, identification of whoever did this, or the removal of any charge. It sets out the order to work in and what to record.
  • Never type a password, access token, recovery code, payment-card number, identity document or the contents of a support case into this page or send them to AdFence. Nothing on this page asks for them, and no legitimate recovery route needs them from a third party.

Last reviewed . Official Meta destinations and menu names on this page are reviewed every quarter.

Do these first, whichever Meta setup you use.

These three apply before the account-specific recovery paths below.

  1. 01

    Contain active spend

    Pause unauthorized campaigns and check whether any new campaigns, ad sets or advertising accounts are actively spending. If the attacker is still making changes, containment comes before a perfect investigation. If you have lost access, do not spend time trying to force a pause. Ask a trusted administrator who still has access to contain the spend and restrict the compromised user, then go to the recovery path that matches your situation.

  2. 02

    Secure the Facebook profile and the email account

    The personal Facebook profile is usually the identity that business assets are reached through, and the email account behind it is usually how a reset is confirmed. If the email may also be compromised, secure it before you rely on password-reset messages.

    • The Facebook profile
    • The connected email account
    • Recovery email addresses
    • Recovery phone numbers
    • Active login sessions
    • Two-factor authentication methods
  3. 03

    Capture the evidence that is safe and immediately available

    Before you remove suspicious access or change everything, record what you can see right now. Do not delay urgent containment to collect more screenshots.

    • Unknown user names and email addresses
    • Business portfolio and ad account ids
    • Campaign ids
    • Screenshots of unauthorized campaigns
    • Budget changes
    • Destination URLs
    • Timestamps
    • Unauthorized spend
    • Payment-method changes
    • Relevant emails from Meta

Which part of your Meta setup was compromised?

Select one or more. Many incidents affect more than one part of a Meta setup, and the paths below open in the order they should be worked through.

Select everything that happened.

No recovery paths selected yet.

Your selection is saved only in this browser, on this device. It is never sent to AdFence.

Recovery paths

Open the path that matches your situation. Any path can be opened at any time, and more than one usually applies.

Not sure yet is a valid answer. Every recovery path can be opened below, and the final checklist covers the whole setup.

Go to the final checklist

Path 1

Personal Facebook profile compromised

The identity your business assets are reached through.
  1. Step 1. Use Meta’s official recovery flow

    Use a phone or computer you have previously used to access Facebook. Familiar devices and locations may help Meta recognize the account. Meta’s recovery process uses trusted-device recognition and adaptive recovery methods, and the support hub can route you to the options your account is eligible for.

  2. Step 2. Secure the connected email account

    Recovering Facebook is not enough while the attacker still controls the mailbox that confirms a reset.

    • Change the email password
    • Review email forwarding rules
    • Review recovery addresses and phone numbers
    • Sign out unknown sessions
    • Turn on multi-factor authentication
    • Check whether security emails from Meta were deleted or redirected
  3. Step 3. Review Facebook security once access is restored

    Open your Facebook security and account settings, currently shown as Accounts Center or Meta Account depending on your account.

    • Password
    • Contact information
    • Recovery methods
    • Active sessions
    • Recognized devices
    • Two-factor authentication
    • Login alerts
    • Passkeys or security keys
    • Connected Facebook and Instagram accounts

    Meta currently supports login alerts, two-factor authentication, security keys and passkeys as account-protection options. A password change on its own does not end an attacker’s existing session or remove their recovery method.

  4. Step 4. Check the device

    Meta recommends removing malicious software, scanning the device, resetting the password, reviewing previous sessions and turning on login alerts and two-factor authentication after suspected malware exposure.

    • Remove suspicious browser extensions
    • Remove unfamiliar downloaded software
    • Update the browser and the operating system
    • Run an updated antivirus or malware scan
    • Avoid logging back in from a device that may still be infected
  5. Step 5. Inspect every business asset the profile could reach

    A recovered profile is the beginning, not the end. Continue through the Business portfolio, ad account and Page paths below.

My profile is secure. Check my business assets next.

Path 2

Personal Facebook ad account compromised

The profile still opens, but the attached ad account has activity you did not create.
  1. Step 1. Stop unauthorized delivery

    Review every active campaign, ad set and ad, and pause anything you cannot verify.

    • New campaigns
    • Reactivated campaigns
    • Budget increases
    • Unfamiliar creatives
    • Unfamiliar Facebook Pages
    • Changed countries or audiences
    • Changed destination URLs
    • New automated rules
    • Unusual campaign objectives
  2. Step 2. Review ad account access

    Check everyone who can reach or manage the ad account.

    • Who has administrative access
    • Who has advertiser access
    • Whether access was granted through a business
    • Whether an unfamiliar partner or agency is connected
    • Whether a former team member still has access
  3. Step 3. Review billing

    Record the exact unauthorized amount, the currency and the period it covers.

    • Payment methods
    • Billing country
    • Account spending limit
    • Recent charges
    • Outstanding balance
    • New or changed cards
    • Unrecognized billing activity
  4. Step 4. Inspect connected advertising assets

    • Facebook Page
    • Connected Instagram account
    • Pixel or dataset
    • Domains
    • Catalogues
    • Custom audiences
    • Conversion events
    • Destination URLs
  5. Step 5. Contact Meta if you need Meta to act

    If you need Meta to recover access, review unauthorized spend, or take another platform-side action, prepare the facts before opening a support request.

    • Ad account id
    • Facebook profile id
    • The date and time you discovered the incident
    • Unauthorized campaign ids
    • The unauthorized amount and currency
    • Screenshots
    • Actions you have already taken
    • Whether access is currently restored

The ad account is contained. Continue with the Business portfolio checks.

Path 3

Meta Business portfolio or Business Manager compromised

Business portfolio is Meta’s current name for what was called Business Manager. Both names still appear in the interface.
  1. Step 1. Review people

    Record the details of anything unfamiliar before you remove or restrict it.

    • People with full control
    • People with partial access
    • Recently added users
    • Permission increases
    • Pending invitations
    • Former employees
    • Former contractors
    • Compromised personal profiles
  2. Step 2. Review partners

    Removing one unfamiliar user does not remove access that is held through an unfamiliar partner business.

    • Partner businesses
    • Agencies
    • Asset access assigned to partners
    • Recently added partners
    • Permission changes
    • Partners with access to more than one asset
  3. Step 3. Review system and application access

    Where these exist on your business, check them. Review the personal profile’s own connected apps and websites separately when the compromise may have started there.

    • System users
    • Connected applications
    • API integrations
    • Data integrations
    • Tokens
    • Third-party reporting tools
    • Automation tools
    • Ecommerce integrations
  4. Step 4. Review every business asset

    For each asset, confirm the owner, the assigned people, the assigned partners, the current permissions, recent changes, and whether the asset was newly created.

    • Ad accounts
    • Facebook Pages
    • Instagram accounts
    • Pixels and datasets
    • Domains
    • Catalogues
    • Apps
    • Shops
    • Leads access
    • Custom conversions
    • Payment methods
  5. Step 5. Review business-level settings

    • Business name
    • Business email
    • Business information
    • Security settings
    • The two-factor authentication requirement
    • Business notifications
    • Administrative users
    • Payment access
    • Business verification details
    • Business activity records, where available
  6. Step 6. Restore safe administration

    Meta warns that a Page user with full control can grant or remove access, remove other people and even delete the Page, so full control is the permission to review hardest.

    • Keep full control with a small number of trusted people
    • Avoid depending on a single administrator
    • Require strong authentication for everyone with business access
    • Reduce unnecessary permissions
    • Remove former agencies and employees
    • Confirm every important asset still has a legitimate owner

The business is under control. Continue with the Page and Instagram checks.

Path 4

Facebook Page or connected Instagram account compromised

Page access and business access are two different things, and both need checking.
  1. Step 1. Review Page access

    Meta distinguishes Facebook access from task access. People with full control can manage Page settings and access; task access can manage assigned work through tools such as Meta Business Suite and Ads Manager.

    • Facebook access with full control
    • Facebook access with partial control
    • Task access
    • Business portfolio access
    • Community manager access
    • Linked Instagram access
  2. Step 2. Review Page and Instagram activity

    • Recent posts
    • Deleted content
    • Messages
    • Linked accounts
    • Advertising activity
    • Page information
    • Page username
    • Contact information
    • Roles and permissions
    • The connected Instagram profile
  3. Step 3. Remove unauthorized access

    A user with legitimate full control can add, edit or remove Page access. Record the suspicious identity before you remove it, where that is practical.

  4. Step 4. Recover lost Page access

    If no legitimate administrator still has full control, use Meta’s hacked Page route. Recovering the personal profile does not automatically restore every Page or business asset.

  5. Step 5. Continue the Business portfolio audit

    If the Page belongs to a Business portfolio, work through that path too, even after Page access is restored.

Page access is restored. Continue with the final checklist.

Path 5

Lost access to everything

No route into the profile, the Page, the business or the ad account.
  1. Step 1. Begin with the personal profile

    Use Meta’s hacked-account recovery flow from a familiar device. Do not use unofficial recovery agents, phone numbers, or people who contact you through direct messages offering to restore access. They may be scammers exploiting the incident, not legitimate recovery support.

  2. Step 2. Use Meta’s official support tools, in order

    Meta has introduced a centralized account-support hub on Facebook and Instagram with expanded recovery assistance. Which routes appear still varies by account, region and recovery situation, so try them in order rather than expecting a specific one.

    • Facebook’s centralized support hub
    • Meta’s hacked-account recovery process
    • Hacked Page recovery
    • Business Support Home, through another legitimate administrator if you cannot sign in
    • Meta’s in-app support assistant, where it is available to you
  3. Step 3. Ask another trusted administrator to contain the incident

    If a legitimate administrator still has access, they can act while you recover.

    • Pause active campaigns
    • Remove or restrict the compromised profile
    • Remove unfamiliar users and partners
    • Preserve business history
    • Record new campaigns and charges
    • Prevent further asset changes
  4. Step 4. Gather account identifiers from outside the account

    Previous invoices, billing emails, ad receipts, Meta notifications, screenshots, agency records, earlier support cases and business verification documents all carry identifiers you can no longer read from inside.

    • Facebook profile id
    • Page id
    • Business portfolio id
    • Ad account id
    • Campaign ids
    • Payment transaction ids
  5. Step 5. Keep one incident timeline

    • When access was lost
    • When suspicious activity began
    • Which assets were affected
    • Who still has access
    • Which campaigns are active
    • Which support requests were submitted
    • Every case or reference number

Access is coming back. Continue with the final checklist.

Need Meta to act? Prepare one short case.

Only create a Meta case when you need help recovering access, a platform-side action, or a review of unauthorized spend or a refund. If none applies, skip this section.

Which Meta support routes you are offered depends on your account, your role, your region and your eligibility. Try the routes below in order rather than expecting a particular chat, form or phone option to appear.

Include only the essentials

  • Business portfolio id
  • Ad account id
  • Affected campaign ids
  • Unknown users or partners
  • The first suspicious event and containment time
  • The unauthorized amount and currency
  • Screenshots
  • Actions already taken

What you need the platform to do

  • What was compromised
  • What activity or spend was unauthorized
  • When it started and what you already did
  • What resolution you are asking for

Documentation may support an investigation or a refund request, but Meta, your bank or your payment provider makes the final decision.

If you are considering a payment dispute with your card issuer, speak to Meta and to your issuer directly. A dispute can affect billing and account standing, and nothing on this page is legal or financial advice.

Before you consider the incident closed

Your own record of what you have done. It is not confirmation from Meta that a step is accepted or complete.

Open the final checklist

Your browser’s print dialog can also save it as a PDF.

0 of 17 steps recorded.

Saved only in this browser. Not sent to AdFence. On a shared or borrowed device, clear this before you hand it back. Reset removes the record from this browser only.

Questions people ask mid-incident

What should I do first if my Facebook ad account is hacked?

Stop unauthorized advertising activity where you still can, secure the personal Facebook profile and connected email, and capture the evidence that is immediately available. Use Meta’s official recovery or support route only if you need access recovery, a platform-side action, or review of unauthorized spend.

Should I delete the attacker’s campaigns?

Pause them first. Record the campaign ids, settings, timestamps and spend before deleting anything, where that is practical. Do not delay containment purely to preserve evidence.

What if the attacker removed me from the Business portfolio?

Begin with recovery of the personal Facebook profile. If another trusted administrator remains, ask them to restrict the compromised profile and preserve business history. Use Meta’s official business support and Page recovery routes for assets you cannot regain directly.

What if only my Facebook Page was taken over?

Use the Page recovery path and review both Facebook access and Business portfolio access. Also secure every personal profile that has full control of the Page.

Can Meta refund unauthorized ad spend?

Meta reviews refund and unauthorized-charge requests individually. This page helps you prepare the evidence. It cannot promise reimbursement, and neither can anyone else outside Meta.

Can AdFence recover my Facebook account?

No. Facebook profile, Page and Business portfolio recovery remain with Meta. AdFence helps monitor, alert, contain supported advertising activity and document what it recorded.

Can I connect AdFence after being hacked?

Yes, once the account is under legitimate control again. Monitoring begins at connection and cannot recreate a full history of what happened beforehand.

What if I use an agency ad account?

Notify the provider or agency immediately. Confirm who legally controls the Business portfolio and the ad account, which party can pause campaigns, who can contact Meta, and who is responsible for documenting the unauthorized activity.

After recovery

Make the next incident easier to catch.

Monitoring is read-only by default and starts after connection. Coverage varies by platform, integration, permissions, configuration and plan. Where a response is supported, an authorized user controls it; automatic actions run only when explicitly configured and pre-approved.