Facebook and Meta ads: incident recovery checklist
Printed from https://adfence.io/under-attack/facebook-ads
Guidance last reviewed 5 September 2026
AdFence is an independent advertising-security platform. It is not Meta, is not affiliated with or endorsed by Meta, and cannot access, restore or recover your account through this guide. Account access and restoration decisions remain with Meta.
Under attack · Facebook and Meta ads
Facebook ad account hacked? Start here.
Choose what was affected and follow the relevant steps to contain the incident, recover access, inspect connected assets and secure the account.
Meta recommends opening its recovery flow from a device you have previously used to log in to the affected Facebook profile.
Is unauthorized spend still active?
If you still have access, pause the suspicious campaigns, or pause all campaigns in the affected ad account while you investigate. If another trusted administrator still has access, ask them to contain the spend and restrict the compromised user immediately.
If you have already lost access, do not spend time trying to force a pause. Go to the recovery path that matches your situation and ask any remaining administrator to contain the spend for you.
Before you go further
- AdFence is an independent advertising-security platform. It is not Meta, is not affiliated with or endorsed by Meta, and cannot access, restore or recover your account through this guide. Account access and restoration decisions remain with Meta.
- This guide cannot promise account recovery, identification of whoever did this, or the removal of any charge. It sets out the order to work in and what to record.
- Never type a password, access token, recovery code, payment-card number, identity document or the contents of a support case into this page or send them to AdFence. Nothing on this page asks for them, and no legitimate recovery route needs them from a third party.
- Which Meta support routes you are offered depends on your account, your role, your region and your eligibility. Try the routes below in order rather than expecting a particular chat, form or phone option to appear.
- Everything on this page is readable without an account, a signup or an email address.
Last reviewed . Official Meta destinations and menu names on this page are reviewed every quarter.
Do these first, whichever Meta setup you use.
These four apply before the account-specific recovery paths below.
01
Contain active spend
Pause unauthorized campaigns and check whether any new campaigns, ad sets or advertising accounts are actively spending. If the attacker is still making changes, containment comes before a perfect investigation.
02
Secure the Facebook profile and the email account
The personal Facebook profile is usually the identity that business assets are reached through, and the email account behind it is usually how a reset is confirmed. If the email may also be compromised, secure it before you rely on password-reset messages.
- The Facebook profile
- The connected email account
- Recovery email addresses
- Recovery phone numbers
- Active login sessions
- Two-factor authentication methods
03
Capture the evidence that is safe and immediately available
Before you remove suspicious access or change everything, record what you can see right now. Do not delay urgent containment to collect more screenshots.
- Unknown user names and email addresses
- Business portfolio and ad account ids
- Campaign ids
- Screenshots of unauthorized campaigns
- Budget changes
- Destination URLs
- Timestamps
- Unauthorized spend
- Payment-method changes
- Relevant emails from Meta
04
Assume more than one asset is affected
Do not stop after finding one unfamiliar campaign or one unfamiliar user. A single compromise commonly reaches several of these at once.
- Facebook profile
- Meta Business portfolio
- Ad accounts
- Facebook Pages
- Instagram accounts
- Pixels and datasets
- Domains
- Catalogues
- Payment methods
- Partner businesses
- Connected applications
Which part of your Meta setup was compromised?
Select one or more. Many incidents affect more than one part of a Meta setup, and the paths below open in the order they should be worked through.
No recovery paths selected yet.
Your selection is saved only in this browser, on this device. It is never sent to AdFence.
Recovery paths
Open the path that matches your situation. Any path can be opened at any time, and more than one usually applies.
Not sure yet is a valid answer. Every recovery path can be opened below, and the full post-recovery audit lists what to check across the whole setup.
Go to the full post-recovery audit
Path 1Personal Facebook profile compromised
The identity your business assets are reached through.
When this path applies
- The password no longer works
- The login email or phone number was changed
- Unknown sessions appear
- Password-reset emails arrived unexpectedly
- The profile was disabled after suspicious activity
- The profile can no longer reach business assets
Step 1. Use Meta’s official recovery flow
Use a phone or computer you have previously used to access Facebook. Familiar devices and locations may help Meta recognize the account. Meta’s recovery process uses trusted-device recognition and adaptive recovery methods, and the support hub can route you to the options your account is eligible for.
- Meta account recovery for a hacked account (opens in a new tab)
Meta’s recovery flow for a compromised personal Facebook profile. Open it from a phone or computer you have used to log in to that profile before.
- Facebook Help Center: my account was hacked (opens in a new tab)
The help article behind the recovery flow. Useful when the flow itself does not offer a route that fits your situation.
- Meta account recovery for a hacked account (opens in a new tab)
Step 2. Secure the connected email account
Recovering Facebook is not enough while the attacker still controls the mailbox that confirms a reset.
- Change the email password
- Review email forwarding rules
- Review recovery addresses and phone numbers
- Sign out unknown sessions
- Turn on multi-factor authentication
- Check whether security emails from Meta were deleted or redirected
Step 3. Review Facebook security once access is restored
Open your Facebook security and account settings, currently shown as Accounts Center or Meta Account depending on your account.
- Password
- Contact information
- Recovery methods
- Active sessions
- Recognized devices
- Two-factor authentication
- Login alerts
- Passkeys or security keys
- Connected Facebook and Instagram accounts
Meta currently supports login alerts, two-factor authentication, security keys and passkeys as account-protection options. A password change on its own does not end an attacker’s existing session or remove their recovery method.
- Facebook Security Checkup (opens in a new tab)
Meta’s guided pass over password, sessions and login alerts. Availability varies by account.
- Facebook two-factor authentication (opens in a new tab)
How to turn on two-factor authentication and which methods your account supports.
- Facebook Help Center: keeping your account secure (opens in a new tab)
Passwords, contact details, recognized devices and login alerts, in Meta’s own words.
Step 4. Check the device
Meta recommends removing malicious software, scanning the device, resetting the password, reviewing previous sessions and turning on login alerts and two-factor authentication after suspected malware exposure.
- Remove suspicious browser extensions
- Remove unfamiliar downloaded software
- Update the browser and the operating system
- Run an updated antivirus or malware scan
- Avoid logging back in from a device that may still be infected
Step 5. Inspect every business asset the profile could reach
A recovered profile is the beginning, not the end. Continue through the Business portfolio, ad account and Page paths below.
Path 2Personal Facebook ad account compromised
The profile still opens, but the attached ad account has activity you did not create.
When this path applies
- The Facebook profile is still accessible
- The ad account attached to it holds unfamiliar advertising activity
Step 1. Stop unauthorized delivery
Review every active campaign, ad set and ad, and pause anything you cannot verify.
- New campaigns
- Reactivated campaigns
- Budget increases
- Unfamiliar creatives
- Unfamiliar Facebook Pages
- Changed countries or audiences
- Changed destination URLs
- New automated rules
- Unusual campaign objectives
Step 2. Review ad account access
Check everyone who can reach or manage the ad account.
- Who has administrative access
- Who has advertiser access
- Whether access was granted through a business
- Whether an unfamiliar partner or agency is connected
- Whether a former team member still has access
Step 3. Review billing
Record the exact unauthorized amount, the currency and the period it covers.
- Payment methods
- Billing country
- Account spending limit
- Recent charges
- Outstanding balance
- New or changed cards
- Unrecognized billing activity
- Meta Business Help Center: ad payment history (opens in a new tab)
Where charges, payment methods and transaction ids are listed, so you can record the exact amount in dispute.
Step 4. Inspect connected advertising assets
- Facebook Page
- Connected Instagram account
- Pixel or dataset
- Domains
- Catalogues
- Custom audiences
- Conversion events
- Destination URLs
Step 5. Report it to Meta
A support request is easier to act on when it already contains the facts.
- Ad account id
- Facebook profile id
- The date and time you discovered the incident
- Unauthorized campaign ids
- The unauthorized amount and currency
- Screenshots
- Actions you have already taken
- Whether access is currently restored
- Meta Business Help Center: unrecognized ad account activity (opens in a new tab)
What Meta asks for when advertising activity or charges on an ad account are not yours.
The ad account is contained. Continue with the Business portfolio checks.
Path 3Meta Business portfolio or Business Manager compromised
Business portfolio is Meta’s current name for what was called Business Manager. Both names still appear in the interface.
When this path applies
- Unfamiliar users, partners or assets appear in the business
- Advertising accounts you did not create appear under it
- Administrative settings or permissions changed
Step 1. Review people
Record the details of anything unfamiliar before you remove or restrict it.
- People with full control
- People with partial access
- Recently added users
- Permission increases
- Pending invitations
- Former employees
- Former contractors
- Compromised personal profiles
Step 2. Review partners
Removing one unfamiliar user does not remove access that is held through an unfamiliar partner business.
- Partner businesses
- Agencies
- Asset access assigned to partners
- Recently added partners
- Permission changes
- Partners with access to more than one asset
Step 3. Review system and application access
Where these exist on your business, check them. Review the personal profile’s own connected apps and websites separately when the compromise may have started there.
- System users
- Connected applications
- API integrations
- Data integrations
- Tokens
- Third-party reporting tools
- Automation tools
- Ecommerce integrations
Step 4. Review every business asset
For each asset, confirm the owner, the assigned people, the assigned partners, the current permissions, recent changes, and whether the asset was newly created.
- Ad accounts
- Facebook Pages
- Instagram accounts
- Pixels and datasets
- Domains
- Catalogues
- Apps
- Shops
- Leads access
- Custom conversions
- Payment methods
Step 5. Review business-level settings
- Business name
- Business email
- Business information
- Security settings
- The two-factor authentication requirement
- Business notifications
- Administrative users
- Payment access
- Business verification details
- Business activity records, where available
- Meta Business Help Center: compromised Business portfolio (opens in a new tab)
Meta’s guidance for a business portfolio with unfamiliar people, partners or activity in it.
Step 6. Restore safe administration
Meta warns that a Page user with full control can grant or remove access, remove other people and even delete the Page, so full control is the permission to review hardest.
- Keep full control with a small number of trusted people
- Avoid depending on a single administrator
- Require strong authentication for everyone with business access
- Reduce unnecessary permissions
- Remove former agencies and employees
- Confirm every important asset still has a legitimate owner
The business is under control. Continue with the Page and Instagram checks.
Path 4Facebook Page or connected Instagram account compromised
Page access and business access are two different things, and both need checking.
When this path applies
- Page access was removed
- An unfamiliar person gained full control
- Page content was changed
- The Page began running unfamiliar ads
- The connected Instagram account changed
- The Page was moved into an unfamiliar business
- The Page name or settings changed
Step 1. Review Page access
Meta distinguishes Facebook access from task access. People with full control can manage Page settings and access; task access can manage assigned work through tools such as Meta Business Suite and Ads Manager.
- Facebook access with full control
- Facebook access with partial control
- Task access
- Business portfolio access
- Community manager access
- Linked Instagram access
- Facebook Help Center: managing Page access (opens in a new tab)
Facebook access versus task access, and how full control differs from assigned work.
Step 2. Review Page and Instagram activity
- Recent posts
- Deleted content
- Messages
- Linked accounts
- Advertising activity
- Page information
- Page username
- Contact information
- Roles and permissions
- The connected Instagram profile
Step 3. Remove unauthorized access
A user with legitimate full control can add, edit or remove Page access. Record the suspicious identity before you remove it, where that is practical.
Step 4. Recover lost Page access
If no legitimate administrator still has full control, use Meta’s hacked Page route. Recovering the personal profile does not automatically restore every Page or business asset.
- Facebook Help Center: recovering a hacked Page (opens in a new tab)
The route for a Page you have lost access to. Recovering your profile does not automatically restore every Page or business asset.
- Facebook Help Center: recovering a hacked Page (opens in a new tab)
Step 5. Continue the Business portfolio audit
If the Page belongs to a Business portfolio, work through that path too, even after Page access is restored.
Page access is restored. Continue with the full post-recovery audit.
Path 5Lost access to everything
No route into the profile, the Page, the business or the ad account.
When this path applies
- You cannot reach the Facebook profile
- You cannot reach the Page
- You cannot reach the Business portfolio
- You cannot reach the ad account
Step 1. Begin with the personal profile
Use Meta’s hacked-account recovery flow from a familiar device. Do not use unofficial recovery agents, phone numbers, or people who contact you through direct messages offering to restore access. They may be scammers exploiting the incident, not legitimate recovery support.
- Meta account recovery for a hacked account (opens in a new tab)
Meta’s recovery flow for a compromised personal Facebook profile. Open it from a phone or computer you have used to log in to that profile before.
- Meta account recovery for a hacked account (opens in a new tab)
Step 2. Use Meta’s official support tools, in order
Meta has introduced a centralized account-support hub on Facebook and Instagram with expanded recovery assistance. Which routes appear still varies by account, region and recovery situation, so try them in order rather than expecting a specific one.
- Facebook’s centralized support hub
- Meta’s hacked-account recovery process
- Hacked Page recovery
- Business Support Home, through another legitimate administrator if you cannot sign in
- Meta’s in-app support assistant, where it is available to you
- Meta Business Help Center: what Business Support Home offers (opens in a new tab)
What support routes exist and who can reach them. Which ones you are offered depends on your account, role, region and eligibility.
- Business Support Home (opens in a new tab)
Login-gated. Reachable only by someone who still has legitimate access to the business, which may be another administrator rather than you.
Step 3. Ask another trusted administrator to contain the incident
If a legitimate administrator still has access, they can act while you recover.
- Pause active campaigns
- Remove or restrict the compromised profile
- Remove unfamiliar users and partners
- Preserve business history
- Record new campaigns and charges
- Prevent further asset changes
Step 4. Gather account identifiers from outside the account
Previous invoices, billing emails, ad receipts, Meta notifications, screenshots, agency records, earlier support cases and business verification documents all carry identifiers you can no longer read from inside.
- Facebook profile id
- Page id
- Business portfolio id
- Ad account id
- Campaign ids
- Payment transaction ids
Step 5. Keep one incident timeline
- When access was lost
- When suspicious activity began
- Which assets were affected
- Who still has access
- Which campaigns are active
- Which support requests were submitted
- Every case or reference number
Access is coming back. Continue with the full post-recovery audit.
Regaining access does not mean the incident is over.
Once control is restored, inspect the full Meta setup for changes that survive a password reset or an access recovery.
Access
- Personal profile sessions
- Contact and recovery information
- People
- Administrators
- Partners
- Pending invitations
- System users
- Connected apps
- Third-party integrations
Campaigns and spend
- New campaigns
- Reactivated campaigns
- Budget increases
- Bid changes
- Automated rules
- Campaign objectives
- Account spending limits
- New ad accounts
- Unrecognized charges
Destinations and identity
- Final URLs
- Redirects
- Domains
- Subdomains
- Facebook Pages
- Instagram accounts
- Creative
- Advertiser identity
- Catalogue destinations
Targeting
- Countries
- Regions
- Languages
- Audiences
- Placements
- Age and gender
- Devices
- Exclusions
Tracking and data
- Pixels
- Datasets
- Conversion events
- Custom conversions
- Catalogues
- Custom audiences
- Offline events
- Ecommerce integrations
Billing and business settings
- Payment methods
- Billing details
- Credit lines
- Financial access
- Business name
- Business email
- Verification information
- Security settings
- Notifications
Do not reopen campaigns simply because access has been restored. Reopen them only after the relevant settings, destinations, identities, targeting, tracking and billing have been verified.
Close the doors that made the incident possible.
Personal security
- Use a unique password
- Secure the connected email account
- Turn on two-factor authentication
- Add a passkey or a security key where appropriate
- Turn on login alerts
- Review active sessions
- Remove suspicious applications
- Scan affected devices
- Remove suspicious browser extensions
Meta recommends two-factor authentication, login alerts, Security Checkup and session review, and supports passkeys on Facebook as a phishing-resistant sign-in option.
Business security
- Require strong authentication for business users
- Restrict full-control access
- Remove former employees and agencies
- Review partner access
- Review business notifications
- Keep more than one trusted recovery administrator
- Review access after every staffing or agency change
- Document who owns each asset
- Schedule recurring access reviews
A note on Meta’s changing names
Open your Facebook security and account settings, currently shown as Accounts Center or Meta Account depending on your account. Meta is gradually moving accounts from Accounts Center to Meta Account, and Business Manager is now called Business portfolio, so menu names on your screen may not match a guide written a few months ago.
Every official destination on this page
- Meta account recovery for a hacked account (opens in a new tab)
Meta’s recovery flow for a compromised personal Facebook profile. Open it from a phone or computer you have used to log in to that profile before.
- Facebook Help Center: my account was hacked (opens in a new tab)
The help article behind the recovery flow. Useful when the flow itself does not offer a route that fits your situation.
- Facebook Help Center: keeping your account secure (opens in a new tab)
Passwords, contact details, recognized devices and login alerts, in Meta’s own words.
- Facebook Security Checkup (opens in a new tab)
Meta’s guided pass over password, sessions and login alerts. Availability varies by account.
- Facebook two-factor authentication (opens in a new tab)
How to turn on two-factor authentication and which methods your account supports.
- Meta Business Help Center: compromised Business portfolio (opens in a new tab)
Meta’s guidance for a business portfolio with unfamiliar people, partners or activity in it.
- Meta Business Help Center: unrecognized ad account activity (opens in a new tab)
What Meta asks for when advertising activity or charges on an ad account are not yours.
- Meta Business Help Center: ad payment history (opens in a new tab)
Where charges, payment methods and transaction ids are listed, so you can record the exact amount in dispute.
- Facebook Help Center: recovering a hacked Page (opens in a new tab)
The route for a Page you have lost access to. Recovering your profile does not automatically restore every Page or business asset.
- Facebook Help Center: managing Page access (opens in a new tab)
Facebook access versus task access, and how full control differs from assigned work.
- Meta Business Help Center: what Business Support Home offers (opens in a new tab)
What support routes exist and who can reach them. Which ones you are offered depends on your account, role, region and eligibility.
- Business Support Home (opens in a new tab)
Login-gated. Reachable only by someone who still has legitimate access to the business, which may be another administrator rather than you.
Make the next incident easier to catch.
This part is about AdFence. It comes last on purpose: nothing here helps you recover the account you are trying to recover today.
If AdFence was already connected
- Review alerts from the affected period
- See recorded access changes
- Review campaign and budget changes
- Check unusual domains and destinations
- Review related account activity
- Use Kill Switch, if it was configured before the incident
- Generate an Evidence Pack from the activity that was recorded
AdFence monitors user and partner changes, account activity, campaign and budget changes, destinations and other supported signals. Kill Switch lets an authorized user pause covered campaigns through a controlled, logged response flow, and only when it was explicitly enabled beforehand. Evidence Packs organize recorded changes, access events, spend and timelines for support or dispute documentation, and do not guarantee a refund.
If AdFence was not connected
AdFence cannot reconstruct activity that happened before the account was connected. Once the recovered account is under your control again, it can begin monitoring supported changes from that point forward.
Read-only monitoring by default. Response permissions remain under your control.
Questions people ask mid-incident
- What should I do first if my Facebook ad account is hacked?
- Stop unauthorized advertising activity where you still can, secure the personal Facebook profile and the connected email account, capture the evidence that is immediately available, and begin Meta’s official account-recovery process.
- Should I delete the attacker’s campaigns?
- Pause them first. Record the campaign ids, settings, timestamps and spend before deleting anything, where that is practical. Do not delay containment purely to preserve evidence.
- What if the attacker removed me from the Business portfolio?
- Begin with recovery of the personal Facebook profile. If another trusted administrator remains, ask them to restrict the compromised profile and preserve business history. Use Meta’s official business support and Page recovery routes for assets you cannot regain directly.
- What if only my Facebook Page was taken over?
- Use the Page recovery path and review both Facebook access and Business portfolio access. Also secure every personal profile that has full control of the Page.
- Can Meta refund unauthorized ad spend?
- Meta reviews refund and unauthorized-charge requests individually. This page helps you prepare the evidence. It cannot promise reimbursement, and neither can anyone else outside Meta.
- Can AdFence recover my Facebook account?
- No. Facebook profile, Page and Business portfolio recovery remain with Meta. AdFence helps monitor, alert, contain supported advertising activity and document what it recorded.
- Can I connect AdFence after being hacked?
- Yes, once the account is under legitimate control again. Monitoring begins at connection and cannot recreate a full history of what happened beforehand.
- What if I use an agency ad account?
- Notify the provider or agency immediately. Confirm who legally controls the Business portfolio and the ad account, which party can pause campaigns, who can contact Meta, and who is responsible for documenting the unauthorized activity.
Before you consider the incident closed
Your own record of what you have done. It is not confirmation from Meta that a step is accepted or complete.
Your browser’s print dialog can also save it as a PDF.
0 of 17 steps recorded.
Saved only in this browser. Not sent to AdFence. On a shared or borrowed device, clear this before you hand it back. Reset removes the record from this browser only.
Notes
Case and reference numbers, who you spoke to, amounts in dispute, and what you are waiting on.
Back in control? Keep it that way.
AdFence monitors connected advertising accounts for the changes that turn a compromised login into lost spend.
Related reading
- Ad account hacked: how monitoring helps
How AdFence detects and documents a compromise, rather than what to do during one.
- Security practices
How AdFence connects to advertising accounts and what it can and cannot do.
Not published yet
- Google Ads account hacked
- TikTok Ads account hacked
These emergency guides are not written yet. When they are, they will appear in the Under attack column in the footer.
AdFence is an independent advertising-security platform. It is not Meta, is not affiliated with or endorsed by Meta, and cannot access, restore or recover your account through this guide. Account access and restoration decisions remain with Meta. Your selection is saved only in this browser, on this device. It is never sent to AdFence.