If someone else has taken over your Facebook account, start at facebook.com/hacked and work through Meta’s guided recovery flow before you try anything else. That page detects whether you are still logged in on some device, whether your login email was swapped, and whether the account has been locked for suspicious activity, then routes you to the right fix. The order matters: secure the email inbox attached to the account first, because whoever controls that inbox can undo every reset you perform.
Recovery usually takes minutes if you still have your email and phone. It takes days if the attacker changed both and you have to prove identity to a review queue. The steps below cover both paths, plus the cleanup that stops the same person walking back in a week later through an app token or a Page role you forgot about.
Step 1: secure the email account before touching Facebook
This is the step people skip, and it is the reason recoveries fail twice. Facebook sends every password reset and every “your email was changed” notice to your inbox. If the attacker still reads that inbox, they intercept the reset link and take the account back immediately.
Sign in to the email provider tied to your Facebook login. Change the password there. Then look at that provider’s active sessions and forwarding rules. Attackers commonly add a hidden forwarding rule or a filter that deletes anything from Facebook so you never see the alerts. In Gmail that lives under Settings > See all settings > Forwarding and POP/IMAP, and under Filters and Blocked Addresses. Turn on two step verification on the email account too. Only then move to Facebook.
Step 2: run the guided flow at facebook.com/hacked
Open facebook.com/hacked in a browser you trust. Facebook asks you to identify the account, then walks through a short sequence: confirm recent activity, reset the password, and review changes made to the account while it was out of your hands. If you are still logged in on a phone, use that device, because an existing session is the strongest signal Facebook has that you are the owner.
If the guided flow does not appear, use the standard reset at facebook.com/login/identify. Enter the email address, phone number, or username on the account. Facebook offers whatever recovery channels are still attached. Choose one you actually control.
Pick a password you have never used anywhere else. A password manager generated string of twenty or more characters is the practical standard. If the same password protects your email, your bank, or your work account, change those too, because credential stuffing across sites is how most of these takeovers start.
Step 3: what to do if the attacker changed your email or phone
When Facebook shows a recovery contact you no longer recognize, look for the link labelled “No longer have access to these?” on the identify screen. That branch lets you enter a new email address you can reach and then verify identity another way.
Meta may also send a notice to your original address saying the email was changed, with a link to reverse it. That link is time limited, so search your inbox and your spam folder for a message from Facebook about a changed email as soon as you notice the problem. Reversing the change from that email is far faster than the identity review queue.
If neither route works, the flow falls back to identity verification. You upload a photo of a government issued ID or, in some cases, two other documents that show your name. Meta states that these uploads are deleted after review. Turnaround varies from a day to a couple of weeks depending on region and volume, and there is no way to escalate it, so submit clean, well lit images the first time.
Step 4: end rogue sessions and revoke access
A password change does not always kill every active session, and it definitely does not revoke third party app tokens. Do this cleanup in one sitting.
| What to check | Where it lives today | What to do |
|---|---|---|
| Active sessions | Accounts Center > Password and security > Where you’re logged in | Log out of every device and location you do not recognize |
| Login alerts | Password and security > Login alerts | Turn on alerts for unrecognized logins |
| Connected apps | Settings & privacy > Settings > Apps and websites | Remove anything you did not install yourself |
| Page and ad account roles | Meta Business Suite > Settings > People, and Billing > Payment settings | Remove unknown admins, check for unfamiliar ad spend |
| Recovery contacts | Accounts Center > Personal details > Contact info | Delete addresses and numbers that are not yours |
| Linked accounts | Accounts Center > Accounts | Remove Instagram or Threads profiles you did not add |
If the account manages a business Page, treat the ad account as the highest priority. Attackers who reach a Page with a stored payment method will launch ads within hours. Pause any active campaign you did not create, then remove the rogue admin. Our walkthrough on how to set up a Facebook ad campaign explains where campaign, ad set, and billing settings live so you can spot changes quickly.
Step 5: turn on two factor authentication and trusted contacts
Once you are back in, add a second factor. In Accounts Center, open Password and security > Two factor authentication, pick the account, and choose a method. An authentication app such as Duo Mobile or Google Authenticator is stronger than SMS, because SIM swap attacks defeat text codes. A hardware security key is stronger still if you have one.
Save the recovery codes Facebook offers and store them somewhere that is not your email inbox. Meta has moved its account security controls under Accounts Center over the past few product cycles, and the labels shift, so if a path here does not match what you see, type “two factor” into the search box at the top of the Facebook help center at facebook.com/help and follow the current article.
Step 6: repair the damage the attacker left behind
Look through the account the way a stranger would. Check your posts and Stories for spam or crypto scam content and delete it. Check Messenger sent items, since the usual playbook is to message your friends asking for money or a verification code. Post a short public note telling contacts to ignore anything odd they received. Review your friends list for accounts added while you were locked out, and review your privacy settings, which attackers often flip to public. If you tightened your friend list before and it is now exposed, our guide on how to hide friends on Facebook covers the audience controls.
Finally, download an archive of the account so you have a snapshot of the current state. See how to download a copy of your Facebook data for the export path and the format choices.
Troubleshooting common recovery failures
The reset code never arrives. Check spam, then confirm the address on file is still yours. If the attacker changed it, the code is going to them. Use the “No longer have access to these?” branch instead of retrying.
Facebook says the account does not exist. The attacker may have changed the name or the username, so searching for your old profile fails. Search by the email address or phone number instead, or ask a friend to open your profile and send you the numeric ID from the URL.
Identity verification keeps getting rejected. Reshoot the document flat on a dark surface, in daylight, with all four corners visible and no glare. Make sure the name on the ID matches the name on the profile. A nickname on the profile is a common cause of rejection.
You get back in and lose the account again within a day. That means a session or an app token survived. Repeat the cleanup table above, especially Where you’re logged in and Apps and websites, then change the password once more so any refreshed session is invalidated.
The account was disabled rather than hacked. Recovery and appeals are separate flows. A disabled account goes through the Help Center appeal form, not facebook.com/hacked, and the outcome depends on the policy that triggered it.
Frequently asked questions
How long does Facebook take to restore a hacked account?
If you still control the email or phone on the account, the guided reset finishes in a few minutes. If you have to submit identity documents, expect anywhere from a day to a couple of weeks. Volume and region drive the difference, and there is no supported way to speed up the review.
Can I recover the account without the original email address?
Yes. On the identify screen, choose “No longer have access to these?” and supply an email address you can reach. Facebook then verifies you another way, usually with a government issued ID or by confirming details only the owner would know. It is slower but it works.
Should I make a new account while I wait?
Avoid it if you can. Facebook’s terms allow one personal account per person, and a duplicate can complicate the review of the original. If you need a presence urgently for business, use a Page managed from a colleague’s account rather than a second personal profile.
Do trusted contacts still exist?
Meta has phased that legacy feature in and out over the years, and the current recovery flows lean on device sessions, email, phone, and identity documents instead. Check what your account actually offers under Password and security rather than assuming a friend based recovery option is available.
Will turning on two factor authentication lock me out later?
Only if you lose both the second factor and the recovery codes. Save the codes when Facebook generates them, register more than one method where possible, and keep at least one method that does not depend on your phone number, since SIM swaps target exactly that.
The bottom line
Recovering a hacked Facebook account is a sequence, not a single button. Secure the email inbox, run facebook.com/hacked, use the “No longer have access to these?” branch if the contact details were swapped, and expect an identity review if the attacker changed everything.
The part that actually keeps the account is the cleanup. End every session, revoke every app you do not recognize, remove strange Page and ad account roles, and put an authenticator app in front of the login. Do that once and the same intrusion does not repeat.
