Facebook and Meta ads: incident recovery checklist
Printed from https://adfence.io/under-attack/facebook-ads
Guidance last reviewed 5 September 2026
AdFence is an independent advertising-security platform. It is not Meta, is not affiliated with or endorsed by Meta, and cannot access, restore or recover your account through this guide. Account access and restoration decisions remain with Meta.
Under attack · Facebook and Meta ads
Facebook ad account hacked? Start here.
Choose what was affected and follow the relevant steps to contain the incident, recover access, inspect connected assets and secure the account.
Before you go further
- AdFence is an independent advertising-security platform. It is not Meta, is not affiliated with or endorsed by Meta, and cannot access, restore or recover your account through this guide. Account access and restoration decisions remain with Meta.
- This guide cannot promise account recovery, identification of whoever did this, or the removal of any charge. It sets out the order to work in and what to record.
- Never type a password, access token, recovery code, payment-card number, identity document or the contents of a support case into this page or send them to AdFence. Nothing on this page asks for them, and no legitimate recovery route needs them from a third party.
Last reviewed . Official Meta destinations and menu names on this page are reviewed every quarter.
Do these first, whichever Meta setup you use.
These three apply before the account-specific recovery paths below.
01
Contain active spend
Pause unauthorized campaigns and check whether any new campaigns, ad sets or advertising accounts are actively spending. If the attacker is still making changes, containment comes before a perfect investigation. If you have lost access, do not spend time trying to force a pause. Ask a trusted administrator who still has access to contain the spend and restrict the compromised user, then go to the recovery path that matches your situation.
02
Secure the Facebook profile and the email account
The personal Facebook profile is usually the identity that business assets are reached through, and the email account behind it is usually how a reset is confirmed. If the email may also be compromised, secure it before you rely on password-reset messages.
- The Facebook profile
- The connected email account
- Recovery email addresses
- Recovery phone numbers
- Active login sessions
- Two-factor authentication methods
03
Capture the evidence that is safe and immediately available
Before you remove suspicious access or change everything, record what you can see right now. Do not delay urgent containment to collect more screenshots.
- Unknown user names and email addresses
- Business portfolio and ad account ids
- Campaign ids
- Screenshots of unauthorized campaigns
- Budget changes
- Destination URLs
- Timestamps
- Unauthorized spend
- Payment-method changes
- Relevant emails from Meta
Which part of your Meta setup was compromised?
Select one or more. Many incidents affect more than one part of a Meta setup, and the paths below open in the order they should be worked through.
No recovery paths selected yet.
Your selection is saved only in this browser, on this device. It is never sent to AdFence.
Recovery paths
Open the path that matches your situation. Any path can be opened at any time, and more than one usually applies.
Not sure yet is a valid answer. Every recovery path can be opened below, and the final checklist covers the whole setup.
Path 1Personal Facebook profile compromised
The identity your business assets are reached through.
Step 1. Use Meta’s official recovery flow
Use a phone or computer you have previously used to access Facebook. Familiar devices and locations may help Meta recognize the account. Meta’s recovery process uses trusted-device recognition and adaptive recovery methods, and the support hub can route you to the options your account is eligible for.
- Meta account recovery for a hacked account (opens in a new tab)
Meta’s recovery flow for a compromised personal Facebook profile. Open it from a phone or computer you have used to log in to that profile before.
- Facebook Help Center: my account was hacked (opens in a new tab)
The help article behind the recovery flow. Useful when the flow itself does not offer a route that fits your situation.
- Meta account recovery for a hacked account (opens in a new tab)
Step 2. Secure the connected email account
Recovering Facebook is not enough while the attacker still controls the mailbox that confirms a reset.
- Change the email password
- Review email forwarding rules
- Review recovery addresses and phone numbers
- Sign out unknown sessions
- Turn on multi-factor authentication
- Check whether security emails from Meta were deleted or redirected
Step 3. Review Facebook security once access is restored
Open your Facebook security and account settings, currently shown as Accounts Center or Meta Account depending on your account.
- Password
- Contact information
- Recovery methods
- Active sessions
- Recognized devices
- Two-factor authentication
- Login alerts
- Passkeys or security keys
- Connected Facebook and Instagram accounts
Meta currently supports login alerts, two-factor authentication, security keys and passkeys as account-protection options. A password change on its own does not end an attacker’s existing session or remove their recovery method.
- Facebook Security Checkup (opens in a new tab)
Meta’s guided pass over password, sessions and login alerts. Availability varies by account.
- Facebook two-factor authentication (opens in a new tab)
How to turn on two-factor authentication and which methods your account supports.
- Facebook Help Center: keeping your account secure (opens in a new tab)
Passwords, contact details, recognized devices and login alerts, in Meta’s own words.
Step 4. Check the device
Meta recommends removing malicious software, scanning the device, resetting the password, reviewing previous sessions and turning on login alerts and two-factor authentication after suspected malware exposure.
- Remove suspicious browser extensions
- Remove unfamiliar downloaded software
- Update the browser and the operating system
- Run an updated antivirus or malware scan
- Avoid logging back in from a device that may still be infected
Step 5. Inspect every business asset the profile could reach
A recovered profile is the beginning, not the end. Continue through the Business portfolio, ad account and Page paths below.
Path 2Personal Facebook ad account compromised
The profile still opens, but the attached ad account has activity you did not create.
Step 1. Stop unauthorized delivery
Review every active campaign, ad set and ad, and pause anything you cannot verify.
- New campaigns
- Reactivated campaigns
- Budget increases
- Unfamiliar creatives
- Unfamiliar Facebook Pages
- Changed countries or audiences
- Changed destination URLs
- New automated rules
- Unusual campaign objectives
Step 2. Review ad account access
Check everyone who can reach or manage the ad account.
- Who has administrative access
- Who has advertiser access
- Whether access was granted through a business
- Whether an unfamiliar partner or agency is connected
- Whether a former team member still has access
Step 3. Review billing
Record the exact unauthorized amount, the currency and the period it covers.
- Payment methods
- Billing country
- Account spending limit
- Recent charges
- Outstanding balance
- New or changed cards
- Unrecognized billing activity
- Meta Business Help Center: ad payment history (opens in a new tab)
Where charges, payment methods and transaction ids are listed, so you can record the exact amount in dispute.
Step 4. Inspect connected advertising assets
- Facebook Page
- Connected Instagram account
- Pixel or dataset
- Domains
- Catalogues
- Custom audiences
- Conversion events
- Destination URLs
Step 5. Contact Meta if you need Meta to act
If you need Meta to recover access, review unauthorized spend, or take another platform-side action, prepare the facts before opening a support request.
- Ad account id
- Facebook profile id
- The date and time you discovered the incident
- Unauthorized campaign ids
- The unauthorized amount and currency
- Screenshots
- Actions you have already taken
- Whether access is currently restored
- Meta Business Help Center: unrecognized ad account activity (opens in a new tab)
What Meta asks for when advertising activity or charges on an ad account are not yours.
The ad account is contained. Continue with the Business portfolio checks.
Path 3Meta Business portfolio or Business Manager compromised
Business portfolio is Meta’s current name for what was called Business Manager. Both names still appear in the interface.
Step 1. Review people
Record the details of anything unfamiliar before you remove or restrict it.
- People with full control
- People with partial access
- Recently added users
- Permission increases
- Pending invitations
- Former employees
- Former contractors
- Compromised personal profiles
Step 2. Review partners
Removing one unfamiliar user does not remove access that is held through an unfamiliar partner business.
- Partner businesses
- Agencies
- Asset access assigned to partners
- Recently added partners
- Permission changes
- Partners with access to more than one asset
Step 3. Review system and application access
Where these exist on your business, check them. Review the personal profile’s own connected apps and websites separately when the compromise may have started there.
- System users
- Connected applications
- API integrations
- Data integrations
- Tokens
- Third-party reporting tools
- Automation tools
- Ecommerce integrations
Step 4. Review every business asset
For each asset, confirm the owner, the assigned people, the assigned partners, the current permissions, recent changes, and whether the asset was newly created.
- Ad accounts
- Facebook Pages
- Instagram accounts
- Pixels and datasets
- Domains
- Catalogues
- Apps
- Shops
- Leads access
- Custom conversions
- Payment methods
Step 5. Review business-level settings
- Business name
- Business email
- Business information
- Security settings
- The two-factor authentication requirement
- Business notifications
- Administrative users
- Payment access
- Business verification details
- Business activity records, where available
- Meta Business Help Center: compromised Business portfolio (opens in a new tab)
Meta’s guidance for a business portfolio with unfamiliar people, partners or activity in it.
Step 6. Restore safe administration
Meta warns that a Page user with full control can grant or remove access, remove other people and even delete the Page, so full control is the permission to review hardest.
- Keep full control with a small number of trusted people
- Avoid depending on a single administrator
- Require strong authentication for everyone with business access
- Reduce unnecessary permissions
- Remove former agencies and employees
- Confirm every important asset still has a legitimate owner
The business is under control. Continue with the Page and Instagram checks.
Path 4Facebook Page or connected Instagram account compromised
Page access and business access are two different things, and both need checking.
Step 1. Review Page access
Meta distinguishes Facebook access from task access. People with full control can manage Page settings and access; task access can manage assigned work through tools such as Meta Business Suite and Ads Manager.
- Facebook access with full control
- Facebook access with partial control
- Task access
- Business portfolio access
- Community manager access
- Linked Instagram access
- Facebook Help Center: managing Page access (opens in a new tab)
Facebook access versus task access, and how full control differs from assigned work.
Step 2. Review Page and Instagram activity
- Recent posts
- Deleted content
- Messages
- Linked accounts
- Advertising activity
- Page information
- Page username
- Contact information
- Roles and permissions
- The connected Instagram profile
Step 3. Remove unauthorized access
A user with legitimate full control can add, edit or remove Page access. Record the suspicious identity before you remove it, where that is practical.
Step 4. Recover lost Page access
If no legitimate administrator still has full control, use Meta’s hacked Page route. Recovering the personal profile does not automatically restore every Page or business asset.
- Facebook Help Center: recovering a hacked Page (opens in a new tab)
The route for a Page you have lost access to. Recovering your profile does not automatically restore every Page or business asset.
- Facebook Help Center: recovering a hacked Page (opens in a new tab)
Step 5. Continue the Business portfolio audit
If the Page belongs to a Business portfolio, work through that path too, even after Page access is restored.
Path 5Lost access to everything
No route into the profile, the Page, the business or the ad account.
Step 1. Begin with the personal profile
Use Meta’s hacked-account recovery flow from a familiar device. Do not use unofficial recovery agents, phone numbers, or people who contact you through direct messages offering to restore access. They may be scammers exploiting the incident, not legitimate recovery support.
- Meta account recovery for a hacked account (opens in a new tab)
Meta’s recovery flow for a compromised personal Facebook profile. Open it from a phone or computer you have used to log in to that profile before.
- Meta account recovery for a hacked account (opens in a new tab)
Step 2. Use Meta’s official support tools, in order
Meta has introduced a centralized account-support hub on Facebook and Instagram with expanded recovery assistance. Which routes appear still varies by account, region and recovery situation, so try them in order rather than expecting a specific one.
- Facebook’s centralized support hub
- Meta’s hacked-account recovery process
- Hacked Page recovery
- Business Support Home, through another legitimate administrator if you cannot sign in
- Meta’s in-app support assistant, where it is available to you
- Meta Business Help Center: what Business Support Home offers (opens in a new tab)
What support routes exist and who can reach them. Which ones you are offered depends on your account, role, region and eligibility.
- Business Support Home (opens in a new tab)
Login-gated. Reachable only by someone who still has legitimate access to the business, which may be another administrator rather than you.
Step 3. Ask another trusted administrator to contain the incident
If a legitimate administrator still has access, they can act while you recover.
- Pause active campaigns
- Remove or restrict the compromised profile
- Remove unfamiliar users and partners
- Preserve business history
- Record new campaigns and charges
- Prevent further asset changes
Step 4. Gather account identifiers from outside the account
Previous invoices, billing emails, ad receipts, Meta notifications, screenshots, agency records, earlier support cases and business verification documents all carry identifiers you can no longer read from inside.
- Facebook profile id
- Page id
- Business portfolio id
- Ad account id
- Campaign ids
- Payment transaction ids
Step 5. Keep one incident timeline
- When access was lost
- When suspicious activity began
- Which assets were affected
- Who still has access
- Which campaigns are active
- Which support requests were submitted
- Every case or reference number
Before you consider the incident closed
Your own record of what you have done. It is not confirmation from Meta that a step is accepted or complete.
Open the final checklist
Your browser’s print dialog can also save it as a PDF.
0 of 17 steps recorded.
Saved only in this browser. Not sent to AdFence. On a shared or borrowed device, clear this before you hand it back. Reset removes the record from this browser only.
Notes
Case and reference numbers, who you spoke to, amounts in dispute, and what you are waiting on.
Questions people ask mid-incident
What should I do first if my Facebook ad account is hacked?
Stop unauthorized advertising activity where you still can, secure the personal Facebook profile and connected email, and capture the evidence that is immediately available. Use Meta’s official recovery or support route only if you need access recovery, a platform-side action, or review of unauthorized spend.
Should I delete the attacker’s campaigns?
Pause them first. Record the campaign ids, settings, timestamps and spend before deleting anything, where that is practical. Do not delay containment purely to preserve evidence.
What if the attacker removed me from the Business portfolio?
Begin with recovery of the personal Facebook profile. If another trusted administrator remains, ask them to restrict the compromised profile and preserve business history. Use Meta’s official business support and Page recovery routes for assets you cannot regain directly.
What if only my Facebook Page was taken over?
Use the Page recovery path and review both Facebook access and Business portfolio access. Also secure every personal profile that has full control of the Page.
Can Meta refund unauthorized ad spend?
Meta reviews refund and unauthorized-charge requests individually. This page helps you prepare the evidence. It cannot promise reimbursement, and neither can anyone else outside Meta.
Can AdFence recover my Facebook account?
No. Facebook profile, Page and Business portfolio recovery remain with Meta. AdFence helps monitor, alert, contain supported advertising activity and document what it recorded.
Can I connect AdFence after being hacked?
Yes, once the account is under legitimate control again. Monitoring begins at connection and cannot recreate a full history of what happened beforehand.
What if I use an agency ad account?
Notify the provider or agency immediately. Confirm who legally controls the Business portfolio and the ad account, which party can pause campaigns, who can contact Meta, and who is responsible for documenting the unauthorized activity.
After recovery
Make the next incident easier to catch.
Monitoring is read-only by default and starts after connection. Coverage varies by platform, integration, permissions, configuration and plan. Where a response is supported, an authorized user controls it; automatic actions run only when explicitly configured and pre-approved.