Someone Is Running Ads on Your Facebook Account: Do This Now
Immediate steps to preserve evidence, stop unfamiliar Meta campaigns, review account access, and report unauthorized advertising activity.
If Ads Manager shows campaigns you did not create, preserve evidence before changing anything. Then stop unfamiliar delivery, secure the people and devices with access, review billing, and contact Meta.
For immediate guided recovery, use AdFence's Facebook Ads emergency recovery guide. For the longer cleanup process, keep our Facebook ad account hacked recovery guide open too.
Key takeaways
- Capture campaigns, ads, charges, and access changes before removing anything.
- Pause unfamiliar campaigns and ads; do not delete the evidence yet.
- End active sessions, change compromised credentials, require two-factor authentication, and remove unauthorized access.
- Review each unfamiliar transaction in Meta, then contact Meta Support. A bank dispute is a separate fallback with operational consequences.
Confirm what happened and preserve evidence
Unrecognized campaigns, new or reactivated ad accounts, unauthorized access changes, and unexplained spend are among the signs Meta lists for a compromised business portfolio. They do not prove how the intrusion happened, so document what you can before drawing conclusions.
Capture:
- campaign, ad-set, and ad names and IDs;
- status, creation date, budget, spend, targeting, creative, and destination URL;
- unfamiliar transactions, their dates, amounts, payment methods, and transaction IDs;
- security emails and notifications with timestamps; and
- relevant entries in Business history in Meta Business Suite Settings, including new people or changed permissions.
Save copies outside the affected Meta account. Keep suspicious campaigns paused rather than deleting them while a support or payment review is open.
Stop unfamiliar ad delivery
In Ads Manager, select each campaign you do not recognize and switch it off. Also review ads and ad sets marked scheduled or in review. Do not assume that pausing one ad stops other ads in the same campaign.
Check the business portfolio for ad accounts, Pages, Instagram accounts, pixels or datasets, catalogs, and payment methods you do not recognize. Meta identifies unfamiliar campaigns, access changes, and spend as reasons to use its compromised-business recovery process.
If you cannot access the business portfolio, ask a known person with full control to preserve evidence and pause the unfamiliar activity. Contact Meta Business Support for a compromised business portfolio. Use facebook.com/hacked only when the personal Facebook profile itself may be compromised; personal-profile recovery and business-portfolio recovery are separate paths.
If charges are still being authorized, contact the card issuer about available controls. Freezing or replacing a card may stop some future authorizations, but it can interrupt legitimate campaigns and does not reverse charges already accrued.
Remove the attacker's access
A password change alone may not remove every access path. Meta and WithSecure have documented malware that targets browser cookies, saved credentials, and Facebook business access: NodeStealer and Ducktail. Phishing, credential theft, malicious software, unauthorized people, partner access, and integrations should all be considered during review.
Work through these controls:
- End Facebook sessions. Go to Accounts Center → Password and security → Where you're logged in, select the affected account, choose the devices to end or Select all, and log out. These are Meta's current remote logout steps.
- Change affected passwords. Change the Facebook password and, if compromise is possible, the password for its recovery email. Use unique passwords.
- Enable two-factor authentication or a passkey. Require stronger authentication for everyone with portfolio access. Meta's business security guidance recommends removing users who have neither a passkey nor two-factor authentication.
- Review people and permissions. Remove unknown or inactive people. Limit full control to people who need it; use partial access and asset-specific permissions for everyone else.
- Review partners. Remove unfamiliar partners and withdraw assets or tasks a legitimate partner no longer needs.
- Review integrations and system users. In Meta Business Suite Settings, inspect Business integrations, apps, and system users. Tokens differ in permissions and lifetime, so revoke anything unauthorized rather than assuming a password change invalidated it.
- Clean affected devices. Update the operating system and browser, remove untrusted extensions and software, and run reputable malware scans before signing in again. If compromise is suspected, involve your IT or incident-response provider.
Review charges and report the incident
Meta's documented starting point is Billing & payments → Payment activity. Open the Transaction ID for each unfamiliar charge and compare the receipt with the ads and payment method shown. Meta explains this process in its guide to unrecognized ad-account activity.
Meta notes that charges can occur after ads stop because costs are not always billed immediately. That is why the transaction receipt and associated ads matter.
If the activity remains unrecognized:
- Contact Meta Support from an account associated with the business.
- Provide the campaign and ad IDs, transaction IDs, screenshots, Business history entries, and a concise timeline.
- Record the case number and preserve all replies.
- Ask Meta what additional identity, ownership, or payment evidence it needs.
Platform reviews and payment adjustments are case-specific. No recovery, credit, or reimbursement is guaranteed. If Meta does not resolve the charges, ask the card issuer about its dispute process and explain that a bank-level action may also interrupt legitimate ad billing.
Verify containment
Pausing campaigns and changing a password can reduce immediate risk, but neither proves the incident is over. Before treating it as contained, verify:
- no unfamiliar campaigns, ads, users, partners, apps, system users, or payment methods remain;
- sessions have been ended and affected devices checked;
- business and asset permissions match current responsibilities;
- recent Payment activity has been reviewed; and
- Meta support cases and card controls have an owner and status.
Then continue with the complete Facebook ad account hacked recovery guide and document what changed. For background on common entry points, see how ad accounts get hacked.
Keep reading
More practical notes for protecting your ad operations.
Why Are My Facebook Ads So Expensive? 12 Causes to Check
Twelve possible reasons Facebook ad costs rise, from auction pressure and campaign structure to tracking errors and unauthorized activity.
AdFence Team
How Ad Accounts Get Hacked: Five Common Attack Paths
Five common routes into advertising accounts: infostealers, phishing, malicious app access, stale permissions, and credential stuffing.
AdFence Team
Google Ads Account Hacked: Your First 24 Hours
A practical first-day checklist for containing a compromised Google Ads account, preserving evidence, reporting it, and reviewing billing.
AdFence Team