Skip to main content

Under attack · Facebook and Meta ads

Facebook ad account hacked? Start here.

Choose what was affected and follow the relevant steps to contain the incident, recover access, inspect connected assets and secure the account.

Meta recommends opening its recovery flow from a device you have previously used to log in to the affected Facebook profile.

Is unauthorized spend still active?

If you still have access, pause the suspicious campaigns, or pause all campaigns in the affected ad account while you investigate. If another trusted administrator still has access, ask them to contain the spend and restrict the compromised user immediately.

If you have already lost access, do not spend time trying to force a pause. Go to the recovery path that matches your situation and ask any remaining administrator to contain the spend for you.

Before you go further

  • AdFence is an independent advertising-security platform. It is not Meta, is not affiliated with or endorsed by Meta, and cannot access, restore or recover your account through this guide. Account access and restoration decisions remain with Meta.
  • This guide cannot promise account recovery, identification of whoever did this, or the removal of any charge. It sets out the order to work in and what to record.
  • Never type a password, access token, recovery code, payment-card number, identity document or the contents of a support case into this page or send them to AdFence. Nothing on this page asks for them, and no legitimate recovery route needs them from a third party.
  • Which Meta support routes you are offered depends on your account, your role, your region and your eligibility. Try the routes below in order rather than expecting a particular chat, form or phone option to appear.
  • Everything on this page is readable without an account, a signup or an email address.

Last reviewed . Official Meta destinations and menu names on this page are reviewed every quarter.

Do these first, whichever Meta setup you use.

These four apply before the account-specific recovery paths below.

  1. 01

    Contain active spend

    Pause unauthorized campaigns and check whether any new campaigns, ad sets or advertising accounts are actively spending. If the attacker is still making changes, containment comes before a perfect investigation.

  2. 02

    Secure the Facebook profile and the email account

    The personal Facebook profile is usually the identity that business assets are reached through, and the email account behind it is usually how a reset is confirmed. If the email may also be compromised, secure it before you rely on password-reset messages.

    • The Facebook profile
    • The connected email account
    • Recovery email addresses
    • Recovery phone numbers
    • Active login sessions
    • Two-factor authentication methods
  3. 03

    Capture the evidence that is safe and immediately available

    Before you remove suspicious access or change everything, record what you can see right now. Do not delay urgent containment to collect more screenshots.

    • Unknown user names and email addresses
    • Business portfolio and ad account ids
    • Campaign ids
    • Screenshots of unauthorized campaigns
    • Budget changes
    • Destination URLs
    • Timestamps
    • Unauthorized spend
    • Payment-method changes
    • Relevant emails from Meta
  4. 04

    Assume more than one asset is affected

    Do not stop after finding one unfamiliar campaign or one unfamiliar user. A single compromise commonly reaches several of these at once.

    • Facebook profile
    • Meta Business portfolio
    • Ad accounts
    • Facebook Pages
    • Instagram accounts
    • Pixels and datasets
    • Domains
    • Catalogues
    • Payment methods
    • Partner businesses
    • Connected applications

Which part of your Meta setup was compromised?

Select one or more. Many incidents affect more than one part of a Meta setup, and the paths below open in the order they should be worked through.

Select everything that happened.

No recovery paths selected yet.

Your selection is saved only in this browser, on this device. It is never sent to AdFence.

Recovery paths

Open the path that matches your situation. Any path can be opened at any time, and more than one usually applies.

Not sure yet is a valid answer. Every recovery path can be opened below, and the full post-recovery audit lists what to check across the whole setup.

Go to the full post-recovery audit

Path 1

Personal Facebook profile compromised

The identity your business assets are reached through.

When this path applies

  • The password no longer works
  • The login email or phone number was changed
  • Unknown sessions appear
  • Password-reset emails arrived unexpectedly
  • The profile was disabled after suspicious activity
  • The profile can no longer reach business assets
  1. Step 1. Use Meta’s official recovery flow

    Use a phone or computer you have previously used to access Facebook. Familiar devices and locations may help Meta recognize the account. Meta’s recovery process uses trusted-device recognition and adaptive recovery methods, and the support hub can route you to the options your account is eligible for.

  2. Step 2. Secure the connected email account

    Recovering Facebook is not enough while the attacker still controls the mailbox that confirms a reset.

    • Change the email password
    • Review email forwarding rules
    • Review recovery addresses and phone numbers
    • Sign out unknown sessions
    • Turn on multi-factor authentication
    • Check whether security emails from Meta were deleted or redirected
  3. Step 3. Review Facebook security once access is restored

    Open your Facebook security and account settings, currently shown as Accounts Center or Meta Account depending on your account.

    • Password
    • Contact information
    • Recovery methods
    • Active sessions
    • Recognized devices
    • Two-factor authentication
    • Login alerts
    • Passkeys or security keys
    • Connected Facebook and Instagram accounts

    Meta currently supports login alerts, two-factor authentication, security keys and passkeys as account-protection options. A password change on its own does not end an attacker’s existing session or remove their recovery method.

  4. Step 4. Check the device

    Meta recommends removing malicious software, scanning the device, resetting the password, reviewing previous sessions and turning on login alerts and two-factor authentication after suspected malware exposure.

    • Remove suspicious browser extensions
    • Remove unfamiliar downloaded software
    • Update the browser and the operating system
    • Run an updated antivirus or malware scan
    • Avoid logging back in from a device that may still be infected
  5. Step 5. Inspect every business asset the profile could reach

    A recovered profile is the beginning, not the end. Continue through the Business portfolio, ad account and Page paths below.

My profile is secure. Check my business assets next.

Path 2

Personal Facebook ad account compromised

The profile still opens, but the attached ad account has activity you did not create.

When this path applies

  • The Facebook profile is still accessible
  • The ad account attached to it holds unfamiliar advertising activity
  1. Step 1. Stop unauthorized delivery

    Review every active campaign, ad set and ad, and pause anything you cannot verify.

    • New campaigns
    • Reactivated campaigns
    • Budget increases
    • Unfamiliar creatives
    • Unfamiliar Facebook Pages
    • Changed countries or audiences
    • Changed destination URLs
    • New automated rules
    • Unusual campaign objectives
  2. Step 2. Review ad account access

    Check everyone who can reach or manage the ad account.

    • Who has administrative access
    • Who has advertiser access
    • Whether access was granted through a business
    • Whether an unfamiliar partner or agency is connected
    • Whether a former team member still has access
  3. Step 3. Review billing

    Record the exact unauthorized amount, the currency and the period it covers.

    • Payment methods
    • Billing country
    • Account spending limit
    • Recent charges
    • Outstanding balance
    • New or changed cards
    • Unrecognized billing activity
  4. Step 4. Inspect connected advertising assets

    • Facebook Page
    • Connected Instagram account
    • Pixel or dataset
    • Domains
    • Catalogues
    • Custom audiences
    • Conversion events
    • Destination URLs
  5. Step 5. Report it to Meta

    A support request is easier to act on when it already contains the facts.

    • Ad account id
    • Facebook profile id
    • The date and time you discovered the incident
    • Unauthorized campaign ids
    • The unauthorized amount and currency
    • Screenshots
    • Actions you have already taken
    • Whether access is currently restored

The ad account is contained. Continue with the Business portfolio checks.

Path 3

Meta Business portfolio or Business Manager compromised

Business portfolio is Meta’s current name for what was called Business Manager. Both names still appear in the interface.

When this path applies

  • Unfamiliar users, partners or assets appear in the business
  • Advertising accounts you did not create appear under it
  • Administrative settings or permissions changed
  1. Step 1. Review people

    Record the details of anything unfamiliar before you remove or restrict it.

    • People with full control
    • People with partial access
    • Recently added users
    • Permission increases
    • Pending invitations
    • Former employees
    • Former contractors
    • Compromised personal profiles
  2. Step 2. Review partners

    Removing one unfamiliar user does not remove access that is held through an unfamiliar partner business.

    • Partner businesses
    • Agencies
    • Asset access assigned to partners
    • Recently added partners
    • Permission changes
    • Partners with access to more than one asset
  3. Step 3. Review system and application access

    Where these exist on your business, check them. Review the personal profile’s own connected apps and websites separately when the compromise may have started there.

    • System users
    • Connected applications
    • API integrations
    • Data integrations
    • Tokens
    • Third-party reporting tools
    • Automation tools
    • Ecommerce integrations
  4. Step 4. Review every business asset

    For each asset, confirm the owner, the assigned people, the assigned partners, the current permissions, recent changes, and whether the asset was newly created.

    • Ad accounts
    • Facebook Pages
    • Instagram accounts
    • Pixels and datasets
    • Domains
    • Catalogues
    • Apps
    • Shops
    • Leads access
    • Custom conversions
    • Payment methods
  5. Step 5. Review business-level settings

    • Business name
    • Business email
    • Business information
    • Security settings
    • The two-factor authentication requirement
    • Business notifications
    • Administrative users
    • Payment access
    • Business verification details
    • Business activity records, where available
  6. Step 6. Restore safe administration

    Meta warns that a Page user with full control can grant or remove access, remove other people and even delete the Page, so full control is the permission to review hardest.

    • Keep full control with a small number of trusted people
    • Avoid depending on a single administrator
    • Require strong authentication for everyone with business access
    • Reduce unnecessary permissions
    • Remove former agencies and employees
    • Confirm every important asset still has a legitimate owner

The business is under control. Continue with the Page and Instagram checks.

Path 4

Facebook Page or connected Instagram account compromised

Page access and business access are two different things, and both need checking.

When this path applies

  • Page access was removed
  • An unfamiliar person gained full control
  • Page content was changed
  • The Page began running unfamiliar ads
  • The connected Instagram account changed
  • The Page was moved into an unfamiliar business
  • The Page name or settings changed
  1. Step 1. Review Page access

    Meta distinguishes Facebook access from task access. People with full control can manage Page settings and access; task access can manage assigned work through tools such as Meta Business Suite and Ads Manager.

    • Facebook access with full control
    • Facebook access with partial control
    • Task access
    • Business portfolio access
    • Community manager access
    • Linked Instagram access
  2. Step 2. Review Page and Instagram activity

    • Recent posts
    • Deleted content
    • Messages
    • Linked accounts
    • Advertising activity
    • Page information
    • Page username
    • Contact information
    • Roles and permissions
    • The connected Instagram profile
  3. Step 3. Remove unauthorized access

    A user with legitimate full control can add, edit or remove Page access. Record the suspicious identity before you remove it, where that is practical.

  4. Step 4. Recover lost Page access

    If no legitimate administrator still has full control, use Meta’s hacked Page route. Recovering the personal profile does not automatically restore every Page or business asset.

  5. Step 5. Continue the Business portfolio audit

    If the Page belongs to a Business portfolio, work through that path too, even after Page access is restored.

Page access is restored. Continue with the full post-recovery audit.

Path 5

Lost access to everything

No route into the profile, the Page, the business or the ad account.

When this path applies

  • You cannot reach the Facebook profile
  • You cannot reach the Page
  • You cannot reach the Business portfolio
  • You cannot reach the ad account
  1. Step 1. Begin with the personal profile

    Use Meta’s hacked-account recovery flow from a familiar device. Do not use unofficial recovery agents, phone numbers, or people who contact you through direct messages offering to restore access. They may be scammers exploiting the incident, not legitimate recovery support.

  2. Step 2. Use Meta’s official support tools, in order

    Meta has introduced a centralized account-support hub on Facebook and Instagram with expanded recovery assistance. Which routes appear still varies by account, region and recovery situation, so try them in order rather than expecting a specific one.

    • Facebook’s centralized support hub
    • Meta’s hacked-account recovery process
    • Hacked Page recovery
    • Business Support Home, through another legitimate administrator if you cannot sign in
    • Meta’s in-app support assistant, where it is available to you
  3. Step 3. Ask another trusted administrator to contain the incident

    If a legitimate administrator still has access, they can act while you recover.

    • Pause active campaigns
    • Remove or restrict the compromised profile
    • Remove unfamiliar users and partners
    • Preserve business history
    • Record new campaigns and charges
    • Prevent further asset changes
  4. Step 4. Gather account identifiers from outside the account

    Previous invoices, billing emails, ad receipts, Meta notifications, screenshots, agency records, earlier support cases and business verification documents all carry identifiers you can no longer read from inside.

    • Facebook profile id
    • Page id
    • Business portfolio id
    • Ad account id
    • Campaign ids
    • Payment transaction ids
  5. Step 5. Keep one incident timeline

    • When access was lost
    • When suspicious activity began
    • Which assets were affected
    • Who still has access
    • Which campaigns are active
    • Which support requests were submitted
    • Every case or reference number

Access is coming back. Continue with the full post-recovery audit.

Regaining access does not mean the incident is over.

Once control is restored, inspect the full Meta setup for changes that survive a password reset or an access recovery.

Access

  • Personal profile sessions
  • Contact and recovery information
  • People
  • Administrators
  • Partners
  • Pending invitations
  • System users
  • Connected apps
  • Third-party integrations

Campaigns and spend

  • New campaigns
  • Reactivated campaigns
  • Budget increases
  • Bid changes
  • Automated rules
  • Campaign objectives
  • Account spending limits
  • New ad accounts
  • Unrecognized charges

Destinations and identity

  • Final URLs
  • Redirects
  • Domains
  • Subdomains
  • Facebook Pages
  • Instagram accounts
  • Creative
  • Advertiser identity
  • Catalogue destinations

Targeting

  • Countries
  • Regions
  • Languages
  • Audiences
  • Placements
  • Age and gender
  • Devices
  • Exclusions

Tracking and data

  • Pixels
  • Datasets
  • Conversion events
  • Custom conversions
  • Catalogues
  • Custom audiences
  • Offline events
  • Ecommerce integrations

Billing and business settings

  • Payment methods
  • Billing details
  • Credit lines
  • Financial access
  • Business name
  • Business email
  • Verification information
  • Security settings
  • Notifications

Do not reopen campaigns simply because access has been restored. Reopen them only after the relevant settings, destinations, identities, targeting, tracking and billing have been verified.

Give Meta a clear incident record.

A support request should make it easy to see what happened, when it happened, and what amount is being disputed.

Information to collect

  • Business portfolio id
  • Ad account id
  • Affected campaign ids
  • Date and time of the first suspicious event
  • Date and time the incident was contained
  • Unknown users or partners
  • Access and permission changes
  • Budget changes
  • Destination changes
  • The unauthorized amount
  • The currency
  • Payment transaction ids
  • Screenshots
  • Relevant emails
  • The support case number
  • Actions already taken

A timeline in this shape is enough

  1. 02:47Unknown administrator added
  2. 02:51New campaign created
  3. 02:53Daily budget increased
  4. 02:56Destination changed
  5. 03:18Incident discovered
  6. 03:24Campaigns paused
  7. 03:31Unknown administrator removed
  8. 04:05Support request submitted

Then write it as one short statement

  1. 1.What was compromised
  2. 2.Which assets were affected
  3. 3.Which activity was unauthorized
  4. 4.How much was spent
  5. 5.When the activity began and ended
  6. 6.Which containment steps were taken
  7. 7.What resolution you are asking for

Documentation may support an investigation or a refund request, but Meta, your bank or your payment provider makes the final decision. If you are considering a payment dispute with your card issuer, speak to Meta and to your issuer directly. A dispute can affect billing and account standing, and nothing on this page is legal or financial advice.

Close the doors that made the incident possible.

Personal security

  • Use a unique password
  • Secure the connected email account
  • Turn on two-factor authentication
  • Add a passkey or a security key where appropriate
  • Turn on login alerts
  • Review active sessions
  • Remove suspicious applications
  • Scan affected devices
  • Remove suspicious browser extensions

Meta recommends two-factor authentication, login alerts, Security Checkup and session review, and supports passkeys on Facebook as a phishing-resistant sign-in option.

Business security

  • Require strong authentication for business users
  • Restrict full-control access
  • Remove former employees and agencies
  • Review partner access
  • Review business notifications
  • Keep more than one trusted recovery administrator
  • Review access after every staffing or agency change
  • Document who owns each asset
  • Schedule recurring access reviews

A note on Meta’s changing names

Open your Facebook security and account settings, currently shown as Accounts Center or Meta Account depending on your account. Meta is gradually moving accounts from Accounts Center to Meta Account, and Business Manager is now called Business portfolio, so menu names on your screen may not match a guide written a few months ago.

Every official destination on this page

Make the next incident easier to catch.

This part is about AdFence. It comes last on purpose: nothing here helps you recover the account you are trying to recover today.

If AdFence was already connected

  • Review alerts from the affected period
  • See recorded access changes
  • Review campaign and budget changes
  • Check unusual domains and destinations
  • Review related account activity
  • Use Kill Switch, if it was configured before the incident
  • Generate an Evidence Pack from the activity that was recorded

AdFence monitors user and partner changes, account activity, campaign and budget changes, destinations and other supported signals. Kill Switch lets an authorized user pause covered campaigns through a controlled, logged response flow, and only when it was explicitly enabled beforehand. Evidence Packs organize recorded changes, access events, spend and timelines for support or dispute documentation, and do not guarantee a refund.

If AdFence was not connected

AdFence cannot reconstruct activity that happened before the account was connected. Once the recovered account is under your control again, it can begin monitoring supported changes from that point forward.

Secure the account you recovered

Read-only monitoring by default. Response permissions remain under your control.

Questions people ask mid-incident

What should I do first if my Facebook ad account is hacked?
Stop unauthorized advertising activity where you still can, secure the personal Facebook profile and the connected email account, capture the evidence that is immediately available, and begin Meta’s official account-recovery process.
Should I delete the attacker’s campaigns?
Pause them first. Record the campaign ids, settings, timestamps and spend before deleting anything, where that is practical. Do not delay containment purely to preserve evidence.
What if the attacker removed me from the Business portfolio?
Begin with recovery of the personal Facebook profile. If another trusted administrator remains, ask them to restrict the compromised profile and preserve business history. Use Meta’s official business support and Page recovery routes for assets you cannot regain directly.
What if only my Facebook Page was taken over?
Use the Page recovery path and review both Facebook access and Business portfolio access. Also secure every personal profile that has full control of the Page.
Can Meta refund unauthorized ad spend?
Meta reviews refund and unauthorized-charge requests individually. This page helps you prepare the evidence. It cannot promise reimbursement, and neither can anyone else outside Meta.
Can AdFence recover my Facebook account?
No. Facebook profile, Page and Business portfolio recovery remain with Meta. AdFence helps monitor, alert, contain supported advertising activity and document what it recorded.
Can I connect AdFence after being hacked?
Yes, once the account is under legitimate control again. Monitoring begins at connection and cannot recreate a full history of what happened beforehand.
What if I use an agency ad account?
Notify the provider or agency immediately. Confirm who legally controls the Business portfolio and the ad account, which party can pause campaigns, who can contact Meta, and who is responsible for documenting the unauthorized activity.

Before you consider the incident closed

Your own record of what you have done. It is not confirmation from Meta that a step is accepted or complete.

Your browser’s print dialog can also save it as a PDF.

0 of 17 steps recorded.

Saved only in this browser. Not sent to AdFence. On a shared or borrowed device, clear this before you hand it back. Reset removes the record from this browser only.

Back in control? Keep it that way.

AdFence monitors connected advertising accounts for the changes that turn a compromised login into lost spend.

Related reading

Not published yet

  • Google Ads account hacked
  • TikTok Ads account hacked

These emergency guides are not written yet. When they are, they will appear in the Under attack column in the footer.

AdFence is an independent advertising-security platform. It is not Meta, is not affiliated with or endorsed by Meta, and cannot access, restore or recover your account through this guide. Account access and restoration decisions remain with Meta. Your selection is saved only in this browser, on this device. It is never sent to AdFence.