Locked out of Facebook, seeing a "your password was changed" alert you never triggered, or watching your name send scam messages you did not write? Your Facebook account has almost certainly been hijacked. Because Facebook is tied to your identity, your Messenger conversations, your photo history, and — for many small businesses — your Page, your ad account, and your customers, a hacked account is more than an inconvenience. It is a fast-moving problem. The good news is that Meta has a structured recovery process, and if you follow it correctly and quickly, you can usually get back in and lock the attacker out for good. Here is exactly how.
Signs Your Facebook Account Was Hacked
- You are signed out and your password no longer works.
- Facebook sent you a "your password was changed" or "new login detected" alert you did not trigger.
- Friends report messages from you asking for money, gift cards, or a "verification code".
- Your name, profile photo, or email/phone on the account changed without you doing it.
- Posts, ads, or Marketplace listings appear that you never created.
- A Business Page you manage shows an admin you do not recognize, or is suddenly running ads you did not approve.
How Facebook Accounts Actually Get Taken Over
Understanding the attack helps you undo it and prevent a repeat. The most common routes in 2026 are:
1. Phishing pages and fake "your account will be disabled" warnings
A message, email, or ad claims your account violated Facebook's rules and will be suspended unless you "verify" by clicking a link. The link leads to a convincing fake login page that captures your password the moment you type it in.
2. Quizzes, giveaways, and "who viewed your profile" apps
Third-party apps and quizzes ask for extensive permissions during login with Facebook. A malicious one can read your profile, post as you, or harvest your session — long after you forgot you ever clicked it.
3. Session and cookie theft via malware
Infostealer malware on a compromised computer can lift your active Facebook session cookies directly, letting an attacker log in without ever needing your password or 2FA code.
4. Business Page and ad account takeovers
Attackers specifically target Facebook Pages with ad spend attached. A phishing message impersonating "Meta Support" asks a Page admin to click a link to "resolve a copyright claim" — the resulting fake login page hands over admin access, which the attacker uses to add themselves, remove the real owners, and run fraudulent ads on the linked card until it is flagged or maxed out.
Step 1 — Recover the Account via facebook.com/hacked
This is Meta's dedicated recovery portal, built specifically for compromised accounts.
Go to facebook.com/hacked
Enter the email, phone number, username, or full name tied to the account and follow the prompts. Facebook verifies you through your registered email or phone, a trusted contact, or an identity check. Do this from a device, browser, and location you normally use — familiar context significantly improves your odds of a fast, automatic recovery.
Still have access to your email or phone? You are nearly done
If the attacker did not change your recovery email or phone, Facebook sends a code there instantly. Enter it, set a new password, and you are back in within minutes.
Recovery email/phone changed? Choose "No longer have access to these?"
This routes you into Facebook's identity confirmation flow. You will be asked to enter a new email you control, and Facebook may request a photo of a government-issued ID or a short video selfie to confirm you are the real owner before restoring access. This step can take anywhere from a few hours to a few days for Meta's team to review — be patient and check your new email regularly.
Set up in advance? Use a Trusted Contact
If you previously configured Trusted Contacts under Security and Login Settings, ask one of those friends for the recovery code Facebook sends them. This can restore access without needing ID verification at all — one more reason to set trusted contacts up now, before you ever need them.
Locked out and stuck? Skip the trial-and-error.
Our certified bilingual tech remotes in, walks you through every recovery step, and secures the account on the spot — same day, from $119.99. No fix, no fee.
DIY Recovery vs. Professional Help — What Actually Gets You Back In Faster?
Most people can complete a straightforward Facebook recovery on their own. But identity-verification rejections, Business Page takeovers, and cases where an attacker changed everything are where people get stuck for days. Here is how the paths compare:
| Situation | Doing It Yourself | IT Cares Assisted Recovery |
|---|---|---|
| Still have access to email/phone | Usually fast — 5 to 15 minutes via facebook.com/hacked | Not usually needed — you can likely self-recover |
| Email/phone changed by attacker | Hours to several days; ID upload often gets rejected on the first try due to photo quality or mismatched details | We prep the ID submission correctly the first time and monitor the case with you |
| Business Page / ad account hijacked | Confusing — requires Business Help Center forms, proof of ownership documents, and ad dispute steps most owners have never seen | We assemble the ownership evidence, file the Page recovery report, and help dispute unauthorized ad charges |
| Cleaning up after recovery (rogue apps, sessions, admins) | Easy to miss a hidden admin, linked app, or old session — leaving a door open | Full audit of sessions, apps, admins, and linked Pages in one remote visit |
| Typical total time | 30 minutes to several days, depending on the case | Usually resolved same day, from $119.99 |
Step 2 — Recovering a Hijacked Facebook Business Page
For Canadian small businesses, this is the scenario with the highest stakes: a hijacked Page can spend your ad budget on scam campaigns while locking your team out of your own customer channel.
Check if you still have partial access
Open Meta Business Suite → Settings → People or Business Settings → Users. If you can still see the Page, immediately remove the unfamiliar admin before they lock you out entirely — attackers often demote or remove the real owners within minutes of gaining access.
Fully locked out? File a Page recovery report
Use the Meta Business Help Center's "My Page was hacked" report. Be ready to provide proof of business ownership: business registration documents, an email on your business's own domain, past ad receipts, or screenshots showing your prior admin status.
Check the linked ad account and payment method
If ads ran under the attacker's control, note the campaign names and spend, then dispute unauthorized charges with your bank or card issuer. Screenshot everything before it disappears — you will likely need it for both Meta and your bank.
Notify your customers through another channel
If the attacker posted or messaged customers from your Page, post a follow-up (once recovered) and email or text your customer list warning them to ignore anything sent during the incident window.
Need This Fixed Right Now?
IT Cares recovers locked and hijacked accounts remotely — usually in 30 minutes or less, from $119.99. No fix = no charge.
Step 3 — Clean Out What the Attacker Left Behind
Regaining access is not the finish line. Attackers plant ways to keep control even after you change your password — check every one of these before you consider the incident closed:
- Log out everywhere: Settings and Privacy → Security and Login → Where You're Logged In → Log Out of All Sessions.
- Apps and Websites: Settings → Apps and Websites — revoke access for anything you do not recognize or no longer use.
- Admins and Page roles: Business Settings → People — remove anyone you did not personally add.
- Name, profile photo, and bio: revert anything the attacker changed, which they sometimes use to impersonate you elsewhere.
- Linked email and phone: confirm both are yours and remove any the attacker added.
- Ad accounts and payment methods: check Ads Manager for unfamiliar cards or campaigns.
Step 4 — Lock It Down for Good
Turn on two-factor authentication — with an authenticator app
Settings and Privacy → Security and Login → Two-Factor Authentication. Use an authenticator app (Google Authenticator, Authy) rather than SMS, which can be defeated by SIM-swap attacks. This single step blocks the vast majority of takeover attempts even if your password leaks.
Set up Trusted Contacts now, before you need them
Security and Login Settings → Choose 3 to 5 Trusted Contacts. These friends can help you recover the account instantly if you are ever locked out again — far faster than the ID-verification route.
Turn on Login Alerts
Get notified the moment your account is accessed from an unrecognized device or browser, so a future attempt is caught in seconds instead of after the damage is done.
Never enter your password after clicking a link
Always type facebook.com directly into your browser. A message, ad, or email claiming urgency ("your account will be disabled in 24 hours") is the single most common trick used to steal Facebook passwords.
Why Facebook Is Such a Valuable Target
Understanding the motive explains the urgency. With your Facebook account, an attacker can:
- Scam your friends and family using the trust built into your name and photo.
- Access years of private Messenger history, photos, and personal details.
- Take over linked Instagram or Business Pages using the same "Login with Facebook" connection.
- Spend real ad budget if a payment method is attached to a Page you manage.
- Hold the account for ransom, particularly business Pages with years of reviews and followers.
Real Canadian Case Studies
Case 1 — The "account will be disabled" phishing link (Ottawa, ON)
A small accounting firm's office manager received a message that looked exactly like a Facebook notification: "Your Page violated our Community Standards and will be permanently disabled in 24 hours. Appeal now." The link led to a near-perfect clone of the Facebook login page. Within minutes, the attacker was in the firm's Page as a second admin, changed the payment method, and launched a crypto-investment ad campaign that ran for six hours before it was flagged. The firm recovered admin access the same day by removing the rogue admin (they still had partial access), but had to dispute over $600 in unauthorized ad spend with their card issuer.
Case 2 — Locked out entirely, recovery-info changed (Winnipeg, MB)
A retiree's personal Facebook was compromised through a "who's been viewing your profile" quiz app that requested broad permissions. The attacker changed the recovery email and posted a fake "I'm in trouble, please send me a code" message to family members. Because there was no Trusted Contact set up, recovery required the full identity-verification path: uploading a driver's licence photo through facebook.com/hacked. The first submission was rejected due to glare on the photo; the second, taken flat under better light, was approved within about 36 hours.
Case 3 — Session hijack via malware on a shared computer (Laval, QC)
A restaurant owner's Facebook Business Page was suddenly posting spam links, even though the password had never been shared and no suspicious login alert appeared. The cause: an infostealer picked up from a pirated software download on the shared front-desk computer had lifted the active session cookie directly, bypassing the password entirely. Logging out of all sessions and changing the password only worked after the infected computer was cleaned — otherwise the same cookie theft would have repeated within hours. A remote malware scan and full account/device cleanup resolved it in one visit.
How Much Does Facebook Account Recovery Cost?
Facebook's own recovery tools are entirely free — Meta does not charge to restore an account. What costs money is the time lost, the ad spend an attacker burns through on a hijacked Page, and, if you get stuck, paying for professional help to finish the job properly. Here is a realistic budget picture:
| Path | Cost | Best for |
|---|---|---|
| Self-recovery via facebook.com/hacked | Free | You still have your email/phone, or a straightforward case |
| ID-verification recovery | Free (but can take hours to days) | Recovery info was changed and no trusted contact was set up |
| IT Cares remote recovery + security cleanup | From $119.99, no fix – no fee | You are stuck, out of time, or malware is involved |
| Business Page recovery + ad account audit | From $119.99 (quoted after a quick review for complex cases) | Hijacked Page with active ad spend or multiple admins to untangle |
| Unauthorized ad spend | Varies — typically disputable with your card issuer if reported quickly | Report to your bank the same day you discover it |
The real cost of a Facebook hack is rarely the recovery itself — it is the ad budget an attacker burns, the trust damage from scam messages sent to your contacts, and the hours spent fighting a broken recovery attempt alone. Getting it right the first time is almost always cheaper than a second incident.
When to Call IT Cares
- You cannot complete recovery and fear permanent loss of years of photos, messages, or a business Page.
- A Business Page or ad account was hijacked and is actively spending money.
- You suspect malware on the computer or phone you use for Facebook.
- The same attacker hit multiple accounts (Facebook + email + WhatsApp) and you need a coordinated clean-up.
- You want a full security audit of every device, app, and admin connected to your account after the incident.
IT Cares connects remotely, walks you through Facebook's recovery process, removes rogue admins and sessions, sets up two-factor authentication correctly, and audits every linked app and Page — same day, anywhere in Canada.
Need This Fixed Right Now?
IT Cares recovers locked and hijacked accounts remotely — usually in 30 minutes or less, from $119.99. No fix = no charge.
Frequently Asked Questions
Go to facebook.com/hacked (or tap 'Forgot password?' on the login screen) and follow the prompts. Facebook verifies you with your registered email or phone, a trusted contact you set up earlier, or by asking you to upload a government ID. Do it from a device and browser you normally use, since Facebook trusts familiar context. Once back in, change your password, log out of all sessions, and remove any unfamiliar admins, apps, or linked pages the attacker added.
Use the 'No longer have access to these?' option on the recovery screen. Facebook will ask you to enter a new email you control and may require ID verification (a photo of a government-issued ID, or a short video selfie) to confirm you are the real owner before it hands the account back. This can take anywhere from a few hours to a few days for Meta to review.
First check Meta Business Suite / Business Settings to see if you still have any admin access — if so, remove the unfamiliar admin immediately. If you were fully locked out, use Business Help Center's 'My Page was hacked' report, which asks for proof of business ownership (registration documents, a matching email domain, ad receipts). Also check whether a linked ad account was used to run unauthorized ads and dispute any charges with your payment provider.
Changing your password and choosing 'Log out of all devices' in Security and Login Settings ends the attacker's active sessions. But you should also review 'Where You're Logged In' for unfamiliar locations, remove unrecognized apps under Apps and Websites, revert any changed name/profile photo, and re-check your linked email and recovery phone in case the attacker altered them.
Turn on two-factor authentication using an authenticator app rather than SMS, set up 3-5 trusted contacts in advance, turn on login alerts for unrecognized devices, review app permissions periodically, and never enter your Facebook password on a page you reached through a link in a message or ad. For Business Pages, limit full Admin access to as few people as possible and use role-based access instead.

Comments
Our restaurant's Page started posting spam links out of nowhere, password never changed. Turned out to be malware on the front-desk computer stealing the login session directly. IT Cares cleaned the machine and locked down the Page with 2FA for every admin — didn't realize how exposed we were with three different people all having full Admin.
Got locked out after clicking a fake "account disabled" link. The ID upload got rejected the first time because of a glare on my licence photo — nobody tells you that. Second try worked after retaking it flat on a table. Wish I'd set up trusted contacts beforehand, would have saved two days.
Leave a Comment