Facebook Business Account Hacked: Revoke Access First

bolt

Quick Answer

If your Facebook Business account has been hacked, act immediately: revoke all unrecognized admin access, change your password, remove unfamiliar payment methods, and report the compromise to Meta at facebook.com/hacked. Prioritize containment because unauthorized activity can continue while access remains compromised. File a compromised account report through the official flow.

Why This Happens

Phishing attack via fake Meta email or support message

A phishing email that impersonates Meta's policy team, ad review team, or billing department can capture business-account credentials. These emails create urgency (threatening account suspension or requesting verification) and direct the target to a fake login page. Facebook employees will never DM you asking for your password or 2FA codes — any such request is a phishing attempt.

Compromised team member account with admin access

If a freelancer, former employee, or contractor with admin access to your Business Manager is phished or their account is compromised, attackers may gain access to everything that person could access — including ad accounts, payment methods, and Pages. Review each admin's permissions and account security rather than assuming the Business Manager is isolated from that user's compromise.

Malware or session hijacking on an admin's device

Attackers can steal active browser sessions through malware, browser extensions, or man-in-the-middle attacks, bypassing 2FA by capturing a valid session token rather than credentials. Session hijacking may not produce a failed login attempt because the attacker's actions can appear to come from the legitimate user's session. Review active sessions and device access in Facebook settings.

Reused or weak passwords across multiple services

If the password for a Business Manager admin's Facebook account was reused from another service that suffered a data breach, attackers can obtain valid credentials without any phishing. Credential stuffing attacks — using lists of leaked username/password pairs against major platforms — are automated and run continuously. Business accounts connected to personal Facebook profiles are especially vulnerable when personal account security is weak.

Rogue third-party app with overly broad permissions

Marketing tools, scheduling apps, CRM integrations, and other third-party apps that connect to your Facebook Business account sometimes request broad permissions. If one of these apps is compromised, sold to a bad actor, or has security vulnerabilities, attackers can use the app's permissions to make changes to your ad accounts, payment methods, or Business Manager settings without ever logging in directly.

Step-by-Step Recovery

1

Immediately revoke all unrecognized admin access

Go to Business Manager Settings → People and Assets → People. Remove any email addresses or users you don't recognize. Also check Business Settings → Partners and remove any unrecognized partner connections. Do this before changing your password — attackers who still have admin access may have added a backup admin that survives a password reset.

2

Change your password and log out all other sessions

Go to Facebook Settings → Security and Login → Change Password. After changing your password, scroll down to 'Where You're Logged In' and click 'Log Out of All Sessions.' This may terminate active sessions, including one the attacker may be using. Enable login alerts if not already active and monitor the alerts shown in Facebook Security Settings.

3

Enable 2FA on all admin accounts immediately

If 2FA wasn't enabled (or was bypassed), enable it now on every account that has Business Manager access. Use an authenticator app (Google Authenticator, Authy) rather than SMS-based 2FA — SIM swapping makes SMS 2FA vulnerable. Require all other admins on your Business Manager to also enable authenticator-based 2FA as a condition of continued access.

4

Pause all campaigns and remove unrecognized payment methods

Immediately pause all active campaigns to stop budget bleed. Then go to Billing → Payment Settings and remove any payment methods you didn't add. If attackers added their own payment methods, those charges may be fraudulent — document the payment methods before removing them. Check your billing history to understand the full scope of unauthorized spend.

5

Report the compromise to Meta through official channels

Go to facebook.com/hacked and follow the compromised account recovery flow. In your Business Manager, go to Help → Report a Problem and file a detailed report explaining that your account was accessed without authorization. Document everything: dates, unauthorized actions taken, payment amounts charged, pages or assets transferred. Submit the specific records Meta requests through the official channel and monitor the case status.

6

Audit all Pages, pixels, and Business Manager assets

Check whether any Pages were unpublished, removed from your Business Manager, or transferred elsewhere. Check whether pixels were shared with unknown businesses and whether unauthorized applications were added. Record every unexpected ownership, access, or sharing change and report it through the official compromised-account flow.

7

Document all unauthorized charges and file a dispute if appropriate

Compile a complete record of unauthorized ad spend: campaign names, dates, amounts, and targeting details. This documentation is needed for Meta's fraud investigation and for any potential credit card dispute. Note: disputing valid Meta charges (even unauthorized ones) through your bank can complicate your account recovery. Consult Meta's support team first about the appropriate channel for recovering fraudulent charges.

8

Conduct a full security audit before restoring access

Before restoring full operations, audit every access point: review all admin accounts and remove anyone who no longer needs access, revoke all third-party app permissions that aren't actively needed, check email accounts of all admins for signs of phishing compromise, and verify that all admins have enabled 2FA. Consider using dedicated devices or browser profiles for Business Manager access. If using agency infrastructure, verify ownership, access, billing, recovery, and offboarding terms in writing; do not assume isolation or continuity.

Appeal Template

Copy this template and fill in the bracketed sections with your specific information. Customize it — don't send it as-is.

descriptionAppeal Letter Template
Subject: Compromised Business Account Report — Business Manager [BM_ID]

Dear Meta Security Team,

I am reporting unauthorized access to my Facebook Business Manager account [BM_ID] associated with [BUSINESS_NAME].

Incident details:
- Date discovered: [DATE]
- Business Manager ID: [BM_ID]
- Primary ad account affected: [ACCOUNT_ID]
- Estimated unauthorized ad spend: $[AMOUNT]

Unauthorized actions taken by attacker:
- [List each unauthorized action: campaigns created, payment methods added, pages transferred, admins added, etc.]
- [Include dates and specific details for each action]

Actions I have already taken:
- Changed password and logged out all sessions on [DATE]
- Enabled two-factor authentication on [DATE]
- Removed unrecognized users from Business Manager on [DATE]
- Paused all unauthorized campaigns on [DATE]
- Removed unauthorized payment methods on [DATE]

I request:
1. Reversal of unauthorized ad spend charged to my payment method ([LAST 4 DIGITS OF CARD])
2. Restoration of any assets transferred without my authorization
3. Review of account security to identify the attack vector

I am the verified business owner of [BUSINESS_NAME], incorporated in [STATE/COUNTRY] in [YEAR].

Supporting documentation attached:
- Screenshots of unauthorized campaigns and charges
- Business registration or incorporation documents
- Government-issued ID

Please respond to [YOUR EMAIL]. Thank you for your urgent attention to this matter.

[YOUR NAME]
[YOUR TITLE]
[COMPANY NAME]
[PHONE NUMBER]
[DATE]

Prevention Checklist

  • check_box_outline_blankEnable authenticator-based 2FA on every account with Business Manager access
  • check_box_outline_blankAudit Business Manager People and Partners access quarterly — remove anyone who no longer needs it
  • check_box_outline_blankNever click links in emails claiming to be from Meta's policy or billing team — go directly to facebook.com
  • check_box_outline_blankUse a dedicated browser profile or device for Business Manager access
  • check_box_outline_blankReview and revoke third-party app permissions in Business Settings monthly
  • check_box_outline_blankRequire all admins to use unique, strong passwords managed in a password manager
  • check_box_outline_blankSet up login alerts and unusual activity notifications in Facebook Security Settings
  • check_box_outline_blankStore a recovery code for your 2FA method in a secure offline location

Expected Timeline

scheduleResolution Timeline

Meta does not publish a universal restoration schedule. Monitor the status shown in facebook.com/hacked, Business Manager Help, and any case channel, and follow the next action shown there.

Next Steps

Fixing this resolves the immediate problem. It does not change the setup that produced it. These cover the Meta account structure, permissions, and review exposure underneath.

shield_with_heartAdsInfra

Scaling past $50k/mo?

AdsInfra coordinates agency ad-account access, billing, permissions, and restriction-response workflows for high-spend teams across Meta, TikTok, and Google.

  • check_circleCoordinated account access and billing workflows
  • check_circleHuman-led restriction review and escalation
  • check_circlePlatform-specific onboarding and compliance checks

Frequently Asked Questions

Can Meta reverse the unauthorized ad charges from a hack?expand_more
Meta may review unauthorized charges when you report the compromise through facebook.com/hacked and provide detailed documentation. Any credit or dispute outcome depends on the case review. Do not file a chargeback with your bank before checking Meta's internal dispute process, because chargebacks can affect account status.
The attacker added themselves as an admin — can I remove them even though I'm locked out?expand_more
If you're fully locked out of your Facebook account, use facebook.com/hacked to initiate account recovery and follow the identity-verification steps shown there. Available recovery actions and access status depend on the account and the current Meta flow. If your Business Manager was compromised but your personal Facebook account still works, check Business Settings for unauthorized users; if both are compromised, use the official identity-verification path.
How do attackers bypass two-factor authentication?expand_more
Session hijacking is one possible 2FA bypass: attackers steal an existing authenticated browser session rather than logging in fresh. This can involve malware that extracts session cookies, malicious browser extensions, or real-time phishing that relays credentials and 2FA codes. Review active sessions, avoid shared or unfamiliar devices, and consider hardware security keys for high-value accounts.
Do I need to rebuild my pixel and audiences after a hack?expand_more
After recovering access, check Events Manager to confirm which pixel data and custom audiences remain listed. If a pixel shows no recent events, investigate whether it was deleted, replaced, or disconnected; use the asset and activity status shown in Business Manager rather than assuming a data outcome.
How do agency ad accounts protect against hack damage?expand_more
An agency-owned account is a provider arrangement, not a recovery guarantee. Before relying on one, verify ownership, admin access, billing responsibility, support channels, incident handling, and offboarding terms in writing. Keep your own records and follow Meta's official recovery path if your personal or business account is compromised.

Related Guides