Facebook Hacked? How to Recover Your Account Right Now

Recover a hacked Facebook account — step by step 2026

Locked out of Facebook, seeing a "your password was changed" alert you never triggered, or watching your name send scam messages you did not write? Your Facebook account has almost certainly been hijacked. Because Facebook is tied to your identity, your Messenger conversations, your photo history, and — for many small businesses — your Page, your ad account, and your customers, a hacked account is more than an inconvenience. It is a fast-moving problem. The good news is that Meta has a structured recovery process, and if you follow it correctly and quickly, you can usually get back in and lock the attacker out for good. Here is exactly how.

Move fast: While an attacker holds your Facebook they can message your friends and family with scams, run unauthorized ads on a linked Business Page, or wipe photos and memories you can never fully recover. The sooner you act, the smaller the damage.

Signs Your Facebook Account Was Hacked

How Facebook Accounts Actually Get Taken Over

Understanding the attack helps you undo it and prevent a repeat. The most common routes in 2026 are:

1. Phishing pages and fake "your account will be disabled" warnings

A message, email, or ad claims your account violated Facebook's rules and will be suspended unless you "verify" by clicking a link. The link leads to a convincing fake login page that captures your password the moment you type it in.

2. Quizzes, giveaways, and "who viewed your profile" apps

Third-party apps and quizzes ask for extensive permissions during login with Facebook. A malicious one can read your profile, post as you, or harvest your session — long after you forgot you ever clicked it.

3. Session and cookie theft via malware

Infostealer malware on a compromised computer can lift your active Facebook session cookies directly, letting an attacker log in without ever needing your password or 2FA code.

4. Business Page and ad account takeovers

Attackers specifically target Facebook Pages with ad spend attached. A phishing message impersonating "Meta Support" asks a Page admin to click a link to "resolve a copyright claim" — the resulting fake login page hands over admin access, which the attacker uses to add themselves, remove the real owners, and run fraudulent ads on the linked card until it is flagged or maxed out.

The golden rule: Facebook will never ask you to "verify" your account by entering your password on a page reached through a message, email, or ad link. Always navigate to facebook.com directly, never through a link someone sent you.

Step 1 — Recover the Account via facebook.com/hacked

This is Meta's dedicated recovery portal, built specifically for compromised accounts.

1

Go to facebook.com/hacked

Enter the email, phone number, username, or full name tied to the account and follow the prompts. Facebook verifies you through your registered email or phone, a trusted contact, or an identity check. Do this from a device, browser, and location you normally use — familiar context significantly improves your odds of a fast, automatic recovery.

2

Still have access to your email or phone? You are nearly done

If the attacker did not change your recovery email or phone, Facebook sends a code there instantly. Enter it, set a new password, and you are back in within minutes.

3

Recovery email/phone changed? Choose "No longer have access to these?"

This routes you into Facebook's identity confirmation flow. You will be asked to enter a new email you control, and Facebook may request a photo of a government-issued ID or a short video selfie to confirm you are the real owner before restoring access. This step can take anywhere from a few hours to a few days for Meta's team to review — be patient and check your new email regularly.

4

Set up in advance? Use a Trusted Contact

If you previously configured Trusted Contacts under Security and Login Settings, ask one of those friends for the recovery code Facebook sends them. This can restore access without needing ID verification at all — one more reason to set trusted contacts up now, before you ever need them.

Locked out and stuck? Skip the trial-and-error.

Our certified bilingual tech remotes in, walks you through every recovery step, and secures the account on the spot — same day, from $119.99. No fix, no fee.

DIY Recovery vs. Professional Help — What Actually Gets You Back In Faster?

Most people can complete a straightforward Facebook recovery on their own. But identity-verification rejections, Business Page takeovers, and cases where an attacker changed everything are where people get stuck for days. Here is how the paths compare:

SituationDoing It YourselfIT Cares Assisted Recovery
Still have access to email/phone Usually fast — 5 to 15 minutes via facebook.com/hacked Not usually needed — you can likely self-recover
Email/phone changed by attacker Hours to several days; ID upload often gets rejected on the first try due to photo quality or mismatched details We prep the ID submission correctly the first time and monitor the case with you
Business Page / ad account hijacked Confusing — requires Business Help Center forms, proof of ownership documents, and ad dispute steps most owners have never seen We assemble the ownership evidence, file the Page recovery report, and help dispute unauthorized ad charges
Cleaning up after recovery (rogue apps, sessions, admins) Easy to miss a hidden admin, linked app, or old session — leaving a door open Full audit of sessions, apps, admins, and linked Pages in one remote visit
Typical total time 30 minutes to several days, depending on the case Usually resolved same day, from $119.99

Step 2 — Recovering a Hijacked Facebook Business Page

For Canadian small businesses, this is the scenario with the highest stakes: a hijacked Page can spend your ad budget on scam campaigns while locking your team out of your own customer channel.

1

Check if you still have partial access

Open Meta Business Suite → Settings → People or Business Settings → Users. If you can still see the Page, immediately remove the unfamiliar admin before they lock you out entirely — attackers often demote or remove the real owners within minutes of gaining access.

2

Fully locked out? File a Page recovery report

Use the Meta Business Help Center's "My Page was hacked" report. Be ready to provide proof of business ownership: business registration documents, an email on your business's own domain, past ad receipts, or screenshots showing your prior admin status.

3

Check the linked ad account and payment method

If ads ran under the attacker's control, note the campaign names and spend, then dispute unauthorized charges with your bank or card issuer. Screenshot everything before it disappears — you will likely need it for both Meta and your bank.

4

Notify your customers through another channel

If the attacker posted or messaged customers from your Page, post a follow-up (once recovered) and email or text your customer list warning them to ignore anything sent during the incident window.

Business Page checklist: Remove unfamiliar admin → File Business Help Center report with ownership proof → Audit ad account and dispute charges → Restore your admins with role-based access, not blanket Admin for everyone → Enable 2FA for every admin, not just the primary owner.

Need This Fixed Right Now?

IT Cares recovers locked and hijacked accounts remotely — usually in 30 minutes or less, from $119.99. No fix = no charge.

Step 3 — Clean Out What the Attacker Left Behind

Regaining access is not the finish line. Attackers plant ways to keep control even after you change your password — check every one of these before you consider the incident closed:

Cleanup order: New password → log out all sessions → remove unfamiliar apps → remove unfamiliar admins → restore recovery email/phone → enable two-factor authentication.

Step 4 — Lock It Down for Good

1

Turn on two-factor authentication — with an authenticator app

Settings and Privacy → Security and Login → Two-Factor Authentication. Use an authenticator app (Google Authenticator, Authy) rather than SMS, which can be defeated by SIM-swap attacks. This single step blocks the vast majority of takeover attempts even if your password leaks.

2

Set up Trusted Contacts now, before you need them

Security and Login Settings → Choose 3 to 5 Trusted Contacts. These friends can help you recover the account instantly if you are ever locked out again — far faster than the ID-verification route.

3

Turn on Login Alerts

Get notified the moment your account is accessed from an unrecognized device or browser, so a future attempt is caught in seconds instead of after the damage is done.

4

Never enter your password after clicking a link

Always type facebook.com directly into your browser. A message, ad, or email claiming urgency ("your account will be disabled in 24 hours") is the single most common trick used to steal Facebook passwords.

Why Facebook Is Such a Valuable Target

Understanding the motive explains the urgency. With your Facebook account, an attacker can:

Real Canadian Case Studies

Case 1 — The "account will be disabled" phishing link (Ottawa, ON)

A small accounting firm's office manager received a message that looked exactly like a Facebook notification: "Your Page violated our Community Standards and will be permanently disabled in 24 hours. Appeal now." The link led to a near-perfect clone of the Facebook login page. Within minutes, the attacker was in the firm's Page as a second admin, changed the payment method, and launched a crypto-investment ad campaign that ran for six hours before it was flagged. The firm recovered admin access the same day by removing the rogue admin (they still had partial access), but had to dispute over $600 in unauthorized ad spend with their card issuer.

Case 2 — Locked out entirely, recovery-info changed (Winnipeg, MB)

A retiree's personal Facebook was compromised through a "who's been viewing your profile" quiz app that requested broad permissions. The attacker changed the recovery email and posted a fake "I'm in trouble, please send me a code" message to family members. Because there was no Trusted Contact set up, recovery required the full identity-verification path: uploading a driver's licence photo through facebook.com/hacked. The first submission was rejected due to glare on the photo; the second, taken flat under better light, was approved within about 36 hours.

Case 3 — Session hijack via malware on a shared computer (Laval, QC)

A restaurant owner's Facebook Business Page was suddenly posting spam links, even though the password had never been shared and no suspicious login alert appeared. The cause: an infostealer picked up from a pirated software download on the shared front-desk computer had lifted the active session cookie directly, bypassing the password entirely. Logging out of all sessions and changing the password only worked after the infected computer was cleaned — otherwise the same cookie theft would have repeated within hours. A remote malware scan and full account/device cleanup resolved it in one visit.

How Much Does Facebook Account Recovery Cost?

Facebook's own recovery tools are entirely free — Meta does not charge to restore an account. What costs money is the time lost, the ad spend an attacker burns through on a hijacked Page, and, if you get stuck, paying for professional help to finish the job properly. Here is a realistic budget picture:

PathCostBest for
Self-recovery via facebook.com/hacked Free You still have your email/phone, or a straightforward case
ID-verification recovery Free (but can take hours to days) Recovery info was changed and no trusted contact was set up
IT Cares remote recovery + security cleanup From $119.99, no fix – no fee You are stuck, out of time, or malware is involved
Business Page recovery + ad account audit From $119.99 (quoted after a quick review for complex cases) Hijacked Page with active ad spend or multiple admins to untangle
Unauthorized ad spend Varies — typically disputable with your card issuer if reported quickly Report to your bank the same day you discover it

The real cost of a Facebook hack is rarely the recovery itself — it is the ad budget an attacker burns, the trust damage from scam messages sent to your contacts, and the hours spent fighting a broken recovery attempt alone. Getting it right the first time is almost always cheaper than a second incident.

When to Call IT Cares

IT Cares connects remotely, walks you through Facebook's recovery process, removes rogue admins and sessions, sets up two-factor authentication correctly, and audits every linked app and Page — same day, anywhere in Canada.

Need This Fixed Right Now?

IT Cares recovers locked and hijacked accounts remotely — usually in 30 minutes or less, from $119.99. No fix = no charge.

Frequently Asked Questions

How do I recover a hacked Facebook account?

Go to facebook.com/hacked (or tap 'Forgot password?' on the login screen) and follow the prompts. Facebook verifies you with your registered email or phone, a trusted contact you set up earlier, or by asking you to upload a government ID. Do it from a device and browser you normally use, since Facebook trusts familiar context. Once back in, change your password, log out of all sessions, and remove any unfamiliar admins, apps, or linked pages the attacker added.

What if the hacker changed my email and phone number on Facebook?

Use the 'No longer have access to these?' option on the recovery screen. Facebook will ask you to enter a new email you control and may require ID verification (a photo of a government-issued ID, or a short video selfie) to confirm you are the real owner before it hands the account back. This can take anywhere from a few hours to a few days for Meta to review.

How do I recover a hacked Facebook Business Page?

First check Meta Business Suite / Business Settings to see if you still have any admin access — if so, remove the unfamiliar admin immediately. If you were fully locked out, use Business Help Center's 'My Page was hacked' report, which asks for proof of business ownership (registration documents, a matching email domain, ad receipts). Also check whether a linked ad account was used to run unauthorized ads and dispute any charges with your payment provider.

Will changing my Facebook password remove the hacker?

Changing your password and choosing 'Log out of all devices' in Security and Login Settings ends the attacker's active sessions. But you should also review 'Where You're Logged In' for unfamiliar locations, remove unrecognized apps under Apps and Websites, revert any changed name/profile photo, and re-check your linked email and recovery phone in case the attacker altered them.

How do I stop my Facebook account from being hacked again?

Turn on two-factor authentication using an authenticator app rather than SMS, set up 3-5 trusted contacts in advance, turn on login alerts for unrecognized devices, review app permissions periodically, and never enter your Facebook password on a page you reached through a link in a message or ad. For Business Pages, limit full Admin access to as few people as possible and use role-based access instead.

Comments

SG
Sébastien G. — Laval, QC
August 3, 2026

Our restaurant's Page started posting spam links out of nowhere, password never changed. Turned out to be malware on the front-desk computer stealing the login session directly. IT Cares cleaned the machine and locked down the Page with 2FA for every admin — didn't realize how exposed we were with three different people all having full Admin.

CB
Chantal B. — Winnipeg, MB
August 3, 2026

Got locked out after clicking a fake "account disabled" link. The ID upload got rejected the first time because of a glare on my licence photo — nobody tells you that. Second try worked after retaking it flat on a table. Wish I'd set up trusted contacts beforehand, would have saved two days.

Leave a Comment