Facebook Account Hacked? Take These 7 Steps Immediately to Secure and Recover Your Account
A hacked Facebook account can quickly become a serious privacy and security problem. Someone who gains unauthorized access may change your password, send suspicious messages to your contacts, publish unwanted posts or attempt to take complete control of your account.
Warning signs can include login alerts from unfamiliar devices, messages you did not send, unexpected changes to your profile, a password that suddenly stops working, or changes to the email address or phone number linked to your account.
If you notice anything suspicious, acting quickly can help limit the damage. Here are seven important steps you should take.
1. Change Your Facebook Password Immediately
If you can still access your Facebook account, changing the password should be one of your first actions.
Go to your account's security settings and create a new password that is strong and unique. Avoid using easily guessed information such as your name, mobile number, birthday or simple combinations.
Most importantly, don't reuse a password that you already use for your email, banking, shopping or other social media accounts.
Password reuse creates an additional risk because if credentials from one service are compromised, attackers may try the same combination on other websites.
After changing your Facebook password, store it securely rather than sharing it through messages or notes that other people could access.
2. Check Where Your Account Is Logged In
Changing the password is important, but you should also check whether your account remains signed in on an unfamiliar phone, computer or browser.
Open Facebook's security settings through Accounts Center > Password and security and review the available login or device information.
Look carefully for devices, browsers or locations you don't recognize. If you find a suspicious session, sign it out.
If Facebook provides an option to log out of multiple or all sessions, consider using it when you believe the account has been compromised. You can then sign back in on your trusted devices using your new password.
Keep in mind that location information associated with a login may not always be perfectly accurate, so evaluate the device, browser and other available details as well.
3. Review Your Email Address and Phone Number
Attackers sometimes try to maintain access to an account by adding or changing recovery information.
Check the email addresses and phone numbers associated with your Facebook account. Make sure they all belong to you.
If you notice an unfamiliar email address or phone number, follow Facebook's security and recovery process to remove or correct it.
Also check whether your own recovery email address or mobile number has been removed or changed.
Accurate recovery information is particularly important because Facebook may use it to verify your identity if you lose access to the account later.
4. Turn On Two-Factor Authentication
Once you have regained control, strengthen the account by enabling two-factor authentication (2FA).
With 2FA enabled, a password alone may not be enough to access your account from a new or unrecognized device. An additional verification step is required.
This creates another layer of protection if your password is exposed in the future.
While reviewing your security settings, also check whether Facebook offers login alerts or other security notifications and enable the options that are useful to you.
Never share authentication codes with anyone. A person claiming to be from Facebook support who asks for your verification code may be attempting to take over your account.
5. Can't Log In? Start Facebook Account Recovery
If the attacker has already changed your password and you can no longer sign in, use Facebook's official account recovery process.
Facebook's hacked-account recovery page
Follow the instructions displayed by Facebook. Depending on your situation, you may be asked to identify your account, verify access to an email address or phone number, reset your password or complete other security checks.
Use a device and browser that you have previously used for Facebook when possible, as familiar account information may help during recovery.
Avoid unofficial websites or individuals claiming they can recover your Facebook account in exchange for money, passwords or verification codes.
6. Warn Your Friends About Suspicious Messages
A compromised Facebook account doesn't only put your information at risk. Attackers may use your identity to target your friends and relatives.
For example, they could send messages containing phishing links, ask contacts for money, request OTPs or verification codes, or impersonate you to obtain personal information.
If suspicious messages have already been sent from your account, inform your contacts through another trusted communication method.
Tell them not to click unexpected links or send money, passwords, OTPs or other sensitive information in response to messages that appeared to come from your compromised account.
7. Secure the Email Account Connected to Facebook
Your Facebook account and email account are closely connected because email is commonly used for password resets and security notifications.
If an attacker has access to your email, changing only your Facebook password may not fully solve the problem.
Change your email password as well if you suspect unauthorized access. Use a completely different password from the one you use on Facebook and enable two-factor authentication for your email account.
Also review your email account's recent login activity, recovery details and forwarding settings for unexpected changes.
Check What the Hacker Changed
After recovering the account, review it carefully rather than assuming everything is back to normal.
Look through recent posts, messages, profile information, Pages or other account activity you control. Remove content you did not create and check for unauthorized changes.
Also inspect connected apps and websites where possible. Revoke access for services you don't recognize or no longer use.
How to Reduce the Risk of Another Facebook Hack
Most account compromises can be made harder by following a few basic security habits: use a unique password, enable 2FA, avoid suspicious login links, never share verification codes, and keep your recovery email address and phone number current.
Be especially cautious with messages claiming that your Facebook account has violated a policy and will be permanently deleted unless you "verify" it immediately. Instead of signing in through an unexpected link, open Facebook directly and check your account notifications.
What Should You Do First?
If you still have access, prioritize changing your password, reviewing active sessions and enabling stronger authentication.
If you cannot access the account, begin recovery through Facebook's official recovery system as soon as possible.
Quick action matters because the longer an attacker controls an account, the more opportunity they have to change recovery details, impersonate the owner and target their contacts.