Is Someone Using Your Facebook Account? Here’s How to Check Active Login Sessions

 | 
s

If you suspect that another person has accessed your Facebook account, you can review every active login session through the platform’s security settings. Facebook’s “Where you’re logged in” section displays the devices and browsers currently connected to your account and allows you to end any session you do not recognise.

The list may include your phone, tablet, computer and other devices on which Facebook or Messenger has been used. It can also show an approximate location, the type of device and details about recent activity.

Reviewing this section regularly can help you detect suspicious access before an intruder changes your password, sends messages, modifies account information or misuses your profile.

How to Check Facebook Login Activity on a Phone

The location of the Menu button may differ slightly between Android phones and iPhones. Follow these general steps:

  1. Open the Facebook application and sign in.

  2. Tap the Menu icon, represented by three horizontal lines.

  3. Select Settings & privacy.

  4. Open Settings.

  5. Tap Accounts Center.

  6. Select Password and security.

  7. Tap Where you’re logged in.

  8. Choose your Facebook account if more than one Meta account appears.

Facebook will display the sessions in which the selected account is currently logged in. You can review the listed device, browser, approximate location and activity information before deciding whether a session is familiar.

Meta’s official instructions confirm that active sessions can be managed through Accounts Center under Password and security.

How to Review Facebook Sessions on a Computer

Users accessing Facebook through a desktop browser can follow a similar process:

  1. Sign in to Facebook through its official website.

  2. Click the profile picture or account menu.

  3. Open Settings & privacy, followed by Settings.

  4. Go to Accounts Center.

  5. Select Password and security.

  6. Open Where you’re logged in.

  7. Choose the relevant Facebook account.

Review each session carefully. A session may display the operating system, browser or type of device, which can help you determine whether it belongs to you.

The interface can change as Facebook updates its application and website. If a menu option appears in a different location, search Settings for “Where you’re logged in” or “Password and security.”

What Information Does Facebook Show?

The session list can provide useful clues about account activity, including:

  • Device category, such as a phone or computer

  • Browser or Facebook application

  • Approximate login location

  • Time of recent activity

  • Whether the current device is being used

The information does not usually reveal the identity of the person who signed in. Instead, it helps you determine whether a device or session matches your own activity.

For example, you may recognise a Windows computer used at work, an old phone still connected to Facebook or a browser session created during a recent trip.

Why the Displayed Location May Be Incorrect

An unfamiliar city in the session list does not always mean that an attacker has accessed your account. Login locations are generally estimated from an internet connection’s IP address rather than a phone’s precise GPS position.

Mobile networks sometimes route traffic through servers located in another city. A VPN, workplace network, internet service provider or travelling connection can also cause an unexpected location to appear.

Facebook advises users to check whether an unfamiliar location may be linked to their mobile device before treating it as unauthorised access. 

Compare the device, browser, time and location with your recent activity. If the device itself is unknown or the activity occurred when you were not using Facebook, treat the session as suspicious.

How to Log Out an Unknown Device

If you find a session you do not recognise, select it and choose the option to log out. This will remove access from that browser or device.

If several unfamiliar sessions appear, use the available option to select multiple sessions or log out of other devices. You may then need to sign in again on your trusted phones and computers.

Logging out the suspicious session is only the first step. If another person knows your password, they may be able to access the account again.

Change Your Facebook Password Immediately

After removing an unknown session, create a new password through:

Accounts Center > Password and security > Change password

Choose a long, unique password that you do not use for email, banking or any other social-media account. Avoid names, birthdays, mobile numbers and commonly guessed combinations.

If the same password was used elsewhere, change it on those accounts as well. Securing the email account connected to Facebook is particularly important because an attacker may use it to reset the Facebook password.

Facebook provides its current password-changing route through Accounts Center.

Turn On Two-Factor Authentication

Two-factor authentication adds another verification step when someone attempts to sign in from an unfamiliar device or browser.

To enable it:

  1. Open Accounts Center.

  2. Select Password and security.

  3. Tap Two-factor authentication.

  4. Choose the Facebook account.

  5. Select an available verification method and follow the instructions.

Depending on the account, Facebook may offer an authentication app, security key or SMS verification. An authentication app or security key can provide stronger protection against some forms of phishing and SIM-related fraud.

Meta explains that two-factor authentication can require an additional login code when access is attempted from an unrecognised device.  

Additional Steps to Secure the Account

After reviewing active sessions, users should also:

  • Remove unknown email addresses or phone numbers.

  • Check whether the profile name, birthday or recovery details changed.

  • Review recent posts, messages and friend requests.

  • Remove unfamiliar connected applications.

  • Avoid clicking login links sent through email or messages.

  • Enter credentials only in the official Facebook app or on facebook.com.

  • Never share a password, OTP or authentication code.

If you can no longer access the account, use Facebook’s official account-recovery process from a device previously used for login.

Regularly reviewing “Where you’re logged in,” using a unique password and enabling two-factor authentication can significantly reduce the risk of unauthorised access.

Tags