Skip to main content

Facebook Ad Account Hacked? The Complete Recovery Guide

An ordered guide to containing and reporting a compromised Meta advertising account while preserving evidence and limiting further exposure.

If Ads Manager contains campaigns, users, destinations, or charges you do not recognize, investigate immediately. These signs warrant containment; no invented threshold such as “two signs confirms a hack” is necessary.

Key takeaways

  • Preserve evidence and pause unauthorized activity while securing affected profiles and business access.
  • Use facebook.com/hacked for a compromised personal Facebook profile; use Meta Business Support Home for the business or ad-account case.
  • Notify the payment issuer promptly so you do not miss its dispute deadlines, and coordinate the billing dispute with your Meta case.
  • Access recovery and refunds are case-specific and not guaranteed.

Confirm What Changed

Ask teammates and agencies whether they recognize the activity, then inspect:

  • campaigns, ads, rules, budgets, destinations, and targeting;
  • people, partners, system users, and ad-account roles;
  • payment methods and transaction IDs;
  • profile sessions, security alerts, recovery details, and emails from Meta.

Unfamiliar campaigns or access are stronger evidence than a late-night timestamp alone. Preserve screenshots and IDs before deleting anything. If activity remains unexplained, treat the account as potentially compromised and contain it.

Contain Spend and Secure Access

There is no safe universal order between payment controls and account security. Work in parallel where possible, based on the access you still have.

  1. Pause unauthorized campaigns. If you cannot tell what was modified, consider pausing all campaigns temporarily. Preserve evidence rather than deleting campaigns.
  2. Secure the affected personal profile. From a trusted device, change the password, review Where you're logged in, log out unfamiliar sessions, verify recovery details, and enable two-factor authentication. Meta recommends using a device previously used to log in when following its hacked-profile recovery guidance.
  3. Review business access. In Meta Business Suite settings, audit people, partners, system users, ad-account access, Pages, connected apps, and automated rules. “Business portfolio” is Meta's current term for what was formerly called Business Manager, according to its business-portfolio 2FA documentation.
  4. Limit payment exposure. Notify the issuer promptly, ask about card controls and deadlines, and record every disputed charge. Remove a payment method only if appropriate and available.

Meta says a payment method can be removed only with the relevant permission and no outstanding balance; active ads must be paused and an outstanding balance cleared. Review the exact prerequisites in Meta's payment-method removal instructions. Do not delay profile security because removal is blocked.

If your billing setup supports an ad-account spending limit, lowering it can limit cumulative account spend. It is not available for accounts using available funds, and the amount already spent counts toward the limit. See Meta's spending-limit documentation.

Use a Trusted Device, Then Remediate Malware

Do not postpone containment while scanning a suspect computer. Use a trusted device immediately, then isolate and scan affected devices before reusing them.

Meta documented business-targeting malware families including NodeStealer and Ducktail that used phishing, malicious extensions, apps, and other lures to target people connected to business accounts. Meta also notes that malware can lead to re-compromise if it remains on a device; see its business malware report. This evidence supports checking for malware, but it does not prove that every incident uses a token that survives every security action.

Audit the Business Portfolio

In Meta Business Suite settings, review each category methodically:

  • People: remove unfamiliar accounts and reduce unnecessary full-control access.
  • Partners: remove businesses you did not authorize.
  • System users: verify the owner, permissions, and purpose of each one.
  • Ad accounts and Pages: confirm assigned people and partners.
  • Apps and integrations: remove anything unauthorized or obsolete.
  • Automated rules: disable rules the team cannot verify.
  • Payment methods and billing contacts: confirm ownership.

Require two-factor authentication where appropriate. Meta says people with full control can require 2FA for admins or everyone in a business portfolio, subject to portfolio-specific settings; see how to require 2FA.

Report the Right Asset Through the Right Flow

Personal profile recovery

Use facebook.com/hacked if the personal Facebook profile used to manage the business was compromised. This flow is for the personal profile; it is not the complete business or ad-account support path. Meta recommends using a previously used device if possible. AdFence's Facebook Ads recovery guide provides a separate incident checklist to use alongside Meta's process.

Business and ad-account support

Once you can authenticate—or from another authorized administrator if one remains—open Meta Business Support Home and follow the options available for the affected business portfolio or ad account. Support channels vary by account and region, so do not assume live chat will appear.

Include complete evidence to reduce avoidable follow-up:

  • business portfolio ID and ad account ID;
  • a chronological incident timeline;
  • screenshots and IDs for unauthorized campaigns, users, partners, rules, and payment changes;
  • transaction IDs, dates, currencies, and amounts;
  • security and containment steps completed;
  • a clear statement identifying what you did not authorize.

Do not open duplicate cases unless Meta instructs you to do so. Complete documentation can make review easier, but it does not guarantee faster handling or a particular outcome, and response time should not be assumed to depend on ad spend.

Billing Disputes and Refunds

Request review of unauthorized ad charges through the available Meta billing or support route and reference the security case. At the same time, notify the card issuer promptly and ask what is required to preserve card-network rights and deadlines. Coordinate any chargeback with the Meta case and understand that it may affect account billing status.

Do not assume pending charges are easier to recover, that Meta will issue an ad credit, or that waiting weeks is safe. Refunds, credits, reversals, and account effects are case-specific. Keep copies of statements, receipts, case numbers, and messages.

Recover the Existing Account or Use Another One?

Prefer a fully secured existing account when Meta restores it and the business can verify all access, assets, and billing. If the account remains restricted, follow Meta's case instructions rather than creating accounts to evade enforcement.

Dataset continuity depends on ownership and permissions, not simply on whether the original ad account survives. Meta says a business portfolio that owns a dataset can assign access to another ad account added to that portfolio, provided the operator has full control; see Meta's dataset assignment instructions. Verify ownership before assuming that pixel data, audiences, or conversion history will transfer—or be lost.

Before relaunching:

  1. verify people, partners, system users, apps, and rules;
  2. confirm Page, dataset, domain, and ad-account permissions;
  3. review payment methods and billing contacts;
  4. verify destinations, creatives, and tracking;
  5. relaunch only activity the team recognizes and monitor it closely.

Reduce Risk and Shorten Detection Time

These habits can reduce risk or shorten detection time; they cannot stop every attack:

  • require two-factor authentication for people with business access;
  • keep full-control access limited and review people and partners regularly;
  • use unique passwords, trusted software, and vetted browser extensions;
  • train staff to verify downloads, job offers, partnership files, and login pages;
  • remove access promptly when an employee or agency relationship ends;
  • monitor available access, spend, billing, delivery, and destination signals.

FAQ

Can an attacker retain access after a password change?

Potentially. Other sessions, business users, partners, system users, apps, or malware may provide separate access paths. Change the password, review sessions, audit the business portfolio, and remediate affected devices rather than relying on one action.

Will Meta refund unauthorized spend?

Possibly, after review. Submit the disputed transaction details and evidence through the available support route, notify the issuer promptly, and preserve deadlines. No refund format, timing, or approval is guaranteed.

Are the Google Ads recovery steps the same?

The containment principles overlap, but the interfaces, access model, billing process, and support routes differ. Use our Google Ads first-24-hours guide for Google-specific procedures.

Platform recovery, billing review, and reimbursement remain with Meta and the payment provider. Detection, prevention, recovery, and refunds are not guaranteed.

Keep reading

More practical notes for protecting your ad operations.