My Facebook Account Was Stolen: Recovery and Protection Guide
When your Facebook account is stolen the official recovery path is facebook.com/hacked. Password and 2FA if you have access, identity verification if you cannot log in, the revert link if the email changed, Meta Business for a business page and steps to close the root cause.
Quick answer: When your Facebook account is stolen, the official way to recover it is facebook.com/hacked; from there Facebook starts a recovery flow with the email and phone linked to your account or with identity verification. If you still have access, immediately change the password, log out of all sessions from settings and enable two step verification. If you cannot log in, request the account back by verifying your identity through facebook.com/hacked; if the attacker changed the email, use the revert this change link in the change notification. If the account manages a business page, also apply through the Meta Business help channel. After recovery, revoke connected apps and make the password unique everywhere; otherwise the account is stolen again.
Because Facebook sits at the center of both personal and business identity, its compromise causes large harm: messages, pages, ad accounts and connected apps come under risk. This article gives the official way to recover a Facebook account and the steps to secure it again, in a clear order. Read it together with our first hour emergency response guide.
Facebook account recovery steps
| Situation | What to do | Official channel |
|---|---|---|
| You still have access | Change password, log out sessions, enable 2FA | Settings, Security |
| You cannot log in | Start account recovery | facebook.com/hacked |
| Email was changed | Revert change link | Notification email |
| Business page affected | Meta Business support | business.facebook.com help |
| Identity verification requested | Upload official ID | Facebook recovery flow |
The essence of this table: if you have access you drop the attacker in seconds; if not, the only correct address is facebook.com/hacked. Other recovery sites in search results are fake.
If you still have access
If you can log in, act fast. From Settings and Security, change the password to a strong and unique one, then log out of all unfamiliar sessions in the where you're logged in list. Right after, enable two step verification; an authenticator app or a passkey is more secure than an SMS code because a SIM swap attack can capture the SMS. For method choice, see the two step verification comparison.
If you cannot log in: facebook.com/hacked
If the attacker changed the password, the only official recovery path is facebook.com/hacked. Facebook here asks for the registered email, phone or official ID to verify who owns the account. If the attacker changed the email address, Facebook sends a notification to your old address, and that notification contains a revert link meaning I did not make this change; this link is often the shortest way to recover the account quickly. This platform specific flow resembles the Instagram account recovery logic, because both are under the Meta umbrella.
If a business page or ad account is affected
If your Facebook account manages a business page or an ad account, recovering the personal account may not be enough. The attacker may have changed page roles or the ad budget. In this case a separate application through the Meta Business help channel is needed. We detailed the path for corporate brand accounts in the corporate social media account takeover article. If there is unauthorized spend on the ad account, the bank steps in the I was defrauded online, what to do guide also apply.
After recovery, close the root
Recovering the account is half the job. If the same open door stays open, the account is stolen again. From the connected apps section, revoke all unfamiliar apps; attackers often leave persistent access through a third party app. Assume the entry likely came from a phishing page or a reused password from another leak, and switch to a unique password and a passkey for every account. For the right setup, see the password, 2FA and passkey security guide.
If it cannot be recovered
The Facebook recovery flow may not yield results in some cases, especially if the attacker changed all recovery information. In this case collecting evidence with screenshots, notification emails and event logs becomes important. You can find the legal path and evidence process in the social media account cannot be recovered, digital evidence and legal process article, and the chain of custody rules in the digital evidence and chain of custody article.
The KAOS and DSET approach
DSET offers a security approach that protects organizations' social media and digital identity assets. Our local AI engine KAOS scans an organization's external surface to detect leaked credentials, weak configurations and open access paths, and reports every finding with a working proof, without false positives. The goal is to close the root cause before a Facebook business or ad account is taken over.
Frequently asked questions
Where do I recover my Facebook account? The official address is facebook.com/hacked. Facebook verifies your identity there with a registered email, phone or official ID. If the attacker changed the email, the revert link in the notification email sent to your old address is the fastest way. Other recovery sites in search results are fake; use only the official address.
What if my email was also changed? When the email is changed, Facebook sends a notification to your old address and offers a link to revert this change. This link is often the shortest way to recover the account quickly. If the link has expired, start the recovery flow with official ID through facebook.com/hacked.
My business page was also taken over, is recovering the personal account enough? Usually not. A business page and ad account carry separate permission layers; the attacker may have changed page roles or the ad budget. After recovering the personal account, you need to apply separately for the page and ad account through the Meta Business help channel.
Sources
- Facebook Help Center, hacked accounts: https://www.facebook.com/hacked
- DSET Cyber Security and Digital Forensics Services: https://dset.com.tr/hizmetler
To protect your corporate Facebook, page and ad accounts and be prepared for takeover scenarios, contact DSET. We provide security consulting from our Ankara Hacettepe Teknokent laboratory.
Kimliğinizi doğrulayın
Yetkilendirilmiş erişim alanı. Tüm giriş denemeleri kayıt altına alınır.