Quick answer: To recover a hacked Facebook account, go to facebook.com/hacked from a device you’ve used to log in before, enter your email, phone, or username, and follow the compromised-account flow — it lets you reclaim the account even if the hacker changed the email and password. Check your inbox for a “your email was changed” message from Facebook, which contains a reverse-the-change link valid for a limited time. If both fail, use identity verification (government ID upload) through Facebook’s recovery flow. Then secure everything: new passwords, app-based 2FA, and removal of the hacker’s sessions and recovery methods. If the account was also disabled for the hacker’s activity, or the trail is cold, a professional recovery service can run the escalation.
By the Viral Spike Marketing Recovery Team · Updated August 2026 · 24-minute read
A hacked Facebook account is a race. In the first hour, the attacker changes your password. In the first day, they swap the email and phone number, kick your sessions, and add their own two-factor device — turning Facebook’s security features into their shield against you. Within days they’re messaging your friends with scams, running ads on your saved payment card, hijacking any Pages and Business Managers you admin, and sometimes deliberately posting policy-violating content so Meta disables the account and slams the door behind them.
We recover hacked Meta accounts every week, and the single biggest predictor of success is how fast and how correctly you act. Facebook has real, working recovery mechanisms for compromised accounts — including flows specifically designed for the “email was changed” scenario — but each has time limits, and every wrong move (like frantically resetting passwords to the hacker’s email) wastes hours you don’t have. This guide is the complete emergency response: the first fifteen minutes, the facebook.com/hacked flow step by step, the email-reversal trick most people miss, ID verification, what to do when the account was also disabled, protecting your Pages and money, and hardening the account so it never happens again.
First 15 minutes: the emergency checklist
- Check your email for messages from Facebook — specifically “Your password was changed,” “Your email was changed,” or “Two-factor authentication was added.” The email-change notice contains a link to reverse the change. This link is the single most valuable object in your recovery. It expires, so act on it the moment you find it.
- Secure your email account first. If the attacker got into your email (very common — it’s how many Facebook hacks start), everything you do next feeds through a compromised channel. Change the email password from a clean device, enable 2FA on the email, and check for forwarding rules the attacker may have added (they love silent auto-forwards).
- Go to facebook.com/hacked from a device and network you’ve previously used with Facebook — your home Wi-Fi, your usual phone. Familiar device signals materially improve the flow’s willingness to trust you.
- Do not spam password resets to the account’s current email — if the hacker already swapped it, you’re resetting their access, notifying them, and accelerating their timeline.
- Warn your people fast — from any channel you still control (Instagram, WhatsApp, text), tell close contacts to ignore money requests and “is this you in this video?” links from your profile. Every scammed friend becomes another report against your account.
Understanding what the hacker did (it predicts your path)
Scenario A: Password changed, email still yours
The easy case. Use “Forgot password” with your email or phone, reset, log in, then immediately kick all other sessions (Settings → Security → Where you’re logged in → Log out of all sessions) and enable 2FA. Ten minutes, done — then still do the full hardening pass at the end of this guide.
Scenario B: Email and phone changed — the classic takeover
You can’t reset the password because codes go to the hacker. Two tools exist precisely for this: the email-reversal link in the “your email was changed” notice sent to your old address, and the facebook.com/hacked flow, which lets you identify the account by its old identifiers and prove ownership. This scenario is the heart of this guide — full walkthrough below.
Scenario C: Hacker added 2FA you can’t pass
Even after proving ownership, login demands a code from the attacker’s authenticator. Facebook’s recovery includes alternate verification for exactly this (ID upload, approved-device confirmation). It adds days, not impossibility. Our companion guide on recovering accounts without two-factor authentication covers this layer across platforms.
Scenario D: Account hacked, then disabled by Meta
The hacker posted scams or prohibited content and Meta disabled the account for it. You now have two nested problems, and order matters: establish the compromise first, then appeal the enforcement. Details in the dedicated section below.
The facebook.com/hacked flow, step by step
Step 1 — Start from the right device
Open facebook.com/hacked (or the “Get help” path from a login error) on a browser or device where you’ve logged into this account before. Facebook’s recovery weighs device recognition heavily; a familiar device is silent evidence you’re the owner.
Step 2 — Identify the account by any old identifier
Click “My account is compromised” and identify the account with your original email, phone number, username, or even your full name plus friends’ names. The flow can locate the account by identifiers that were on it before the hacker’s changes — this is the key difference from the ordinary password reset, and the reason this flow works when “Forgot password” doesn’t.
Step 3 — Prove ownership
Depending on the case, Facebook offers one or more of: a current-or-old-password check (an old password you remember counts as evidence), codes to original contact points, trusted-contact style verification, security questions on legacy accounts, or government ID upload. Take whatever path appears; if offered multiple, prefer the one anchored to things the hacker couldn’t change (old password, ID).
Step 4 — Reverse the damage inside the flow
When the flow succeeds, Facebook walks you through resetting the password and reviewing recent changes — email swaps, phone swaps, added 2FA, new admin grants. Reverse all of it: restore your email and phone, remove the attacker’s, strip their 2FA method, and log out all sessions. Don’t rush past this screen; leaving one attacker artifact behind (their phone number as “recovery,” a lingering session, an app password) is how re-hacks happen the same week.
Step 5 — If the flow dead-ends, use ID verification
When automated verification can’t establish ownership, Facebook’s help paths route to an ID upload form (the Help Center’s “Confirm your identity with Facebook” flows). Submit a clear, uncropped photo of a government ID matching the name on the account, from the same device you used in the flow, and add a brief note if your account name differs from your legal name (nicknames, maiden names). Responses typically take 1–7 days. Unreadable photos and name mismatches without explanation are the two failure modes that matter.
The email-reversal link: the tool almost everyone misses
Every time an email address is changed on a Facebook account, Facebook sends a notice to the old address that says, in effect, “If you didn’t do this, you can reverse this change” — with a direct link that undoes the swap and initiates a secure recovery. In our casework, this link resolves more email-swap takeovers than any other single mechanism, and most victims never see it because they don’t dig through their inbox for it, or they find it after it expired.
So: search your email — including spam, trash, and archived mail — for messages from Facebook (facebookmail.com) around the time of the hack. Look for subject lines about email changes, password changes, and new logins. If you find the email-change notice, use its reversal link immediately, then continue with password reset and session cleanup. The same pattern applies to “primary contact changed” notices on Meta Accounts Center. And a note for the future that will feel unfair right now: this is why security notifications should never be filtered to a folder you don’t read.
Hacked, then disabled: the two-stage recovery
If Meta disabled the account because of what the hacker posted, understand the sequencing — it decides these cases. Stage one: establish the compromise. Use the hacked flow and/or ID verification to get on record as the legitimate owner reporting a takeover, with the timeline: when you lost access, the notification emails showing email/phone changes, the content you didn’t post. Stage two: appeal the enforcement — through the standard disabled-account appeal, but framed around the documented compromise: “This account was taken over on [date] (reported via the compromised-account flow); the violating content was posted by the attacker; I request restoration as the verified owner.” Appeals that skip stage one and argue “I didn’t violate the guidelines” fail against evidence that the account plainly did — the reviewer needs the compromise narrative to resolve that contradiction. Our guides on disabled Instagram accounts and disabled Business Managers cover the enforcement-appeal machinery in depth.
How Facebook accounts actually get hacked (know your enemy)
Understanding the attack tells you what to fix and what evidence exists. The five dominant vectors in current casework:
Phishing pages and fake violation notices. The workhorse. You receive a message or email — “Your Page will be permanently deleted for policy violations, appeal here” — leading to a pixel-perfect fake Meta login. Business Page admins are targeted constantly because their profiles unlock commercial assets. The evidence trail: the phishing message itself, still sitting in your inbox or DMs; keep it for your case.
Credential-stuffing from breached passwords. A password you used on some breached site years ago, retried on Facebook at scale. No trickery involved, which is why “but I never clicked anything” victims are common. Fix is structural: unique passwords everywhere, breach monitoring (haveibeenpwned.com), and 2FA.
Session hijacking via malware and malicious extensions. Infostealer malware — often bundled with cracked software or fake browser updates — exfiltrates session cookies, letting attackers walk in without a password and without triggering login alerts. If your account was taken with no reset emails at all, suspect this vector, and run a proper malware scan before you type a single new password on that machine.
SIM swapping. The attacker ports your phone number, receives your SMS codes, and resets everything. This is why authenticator-app 2FA beats SMS, and why a carrier-account PIN belongs in your defenses.
Social engineering of recovery flows. Attackers abuse the same recovery machinery you’re reading about — old identifiers, trusted contacts, support impersonation. If someone claiming to be “Meta support” ever asks you for a login code “to verify your identity,” that’s the attack itself: codes are things support never asks for.
A real recovery pattern from casework
The restaurant owner’s 11-day chase. A restaurateur’s profile — sole admin of a 60K-follower Page — was phished via a fake copyright notice. Within a day: email swapped, SMS 2FA replaced with the attacker’s authenticator, scam ads running on the saved card, and the Page renamed to a crypto brand. She found the email-change notice on day 3, but the reversal link had expired. What worked, in order: securing her Gmail (which had a silent forwarding rule to the attacker), the facebook.com/hacked flow from her home laptop (device recognition passed), an old-password ownership check, then ID verification when attacker 2FA blocked final login — access restored day 9. Billing dispute refunded the fraudulent spend; the Page name and admin roster took two more days to untangle. Lessons: the forwarding rule would have silently re-compromised everything (“secure your email first” is not a formality); expired reversal links don’t end the case; and sole-admin Pages turn one person’s phishing click into a business-wide crisis.
Hacker moved faster than you?
Cold trails, swapped emails, attacker 2FA, disabled accounts — we untangle hacked Meta cases every week for individuals, brands, and public figures. Confidential, and we never need your password.
Protect the assets attached to your profile
Pages and Business Managers
Your profile is a key to every Page and Business Manager you admin. While fighting for the profile, check whether those assets are compromised too: from any other admin’s access, review Business Settings → People for attacker additions, demote/remove them, and confirm two legitimate full-control admins remain. If the attacker seized sole control of a Business Manager, that becomes its own recovery case — our Business Manager guide covers it, including the fraud-spend refund process.
Money: ads, Marketplace, and saved cards
Hackers monetize fast: fraudulent ad campaigns on your saved card, Marketplace scams under your name. Once you’re back in, go to billing in Ads Manager and screenshot every charge you didn’t authorize, then dispute them inside Meta’s billing support — verified fraud is generally refunded. Resist the instinct to issue bank chargebacks first; chargebacks against Meta trigger advertising restrictions that outlive the hack.
Friends and reputation
Post a brief note (or have a friend do it) telling contacts what happened and what to ignore. Report any impersonation clones of your profile that appeared during the incident (facebook.com/help lists the impersonation report path). If the hacker ran romance or crypto scams broadly from your name, keep a screenshot log — it occasionally matters for police reports and identity-theft claims (identitytheft.gov in the US).
How long does hacked-Facebook recovery take?
With the email-reversal link or a same-day hacked-flow success: minutes to hours. ID-verification paths: 1 to 7 days. Attacker-2FA complications: 3 days to 3 weeks. Hacked-then-disabled two-stage cases: 2 to 8 weeks. Cold cases — takeovers discovered weeks later, with every identifier swapped and sessions long gone — are the slowest and benefit most from professional escalation, because they depend on evidence assembly rather than automated flows.
The hardening pass: 20 minutes that prevents the sequel
- New password, unique, from a password manager — never reused from any other site. Most Facebook takeovers start with a password leaked from somewhere else.
- Two-factor authentication with an authenticator app (or hardware key) rather than SMS — SIM-swap attacks turn SMS 2FA into a vulnerability. Store backup codes offline.
- Session audit: Settings → Security → Where you’re logged in → log out everything you don’t recognize.
- Recovery audit: confirm every email and phone on the account is yours and current; delete stale ones. Do the same in Meta Accounts Center, which links Facebook and Instagram recovery surfaces.
- Connected apps audit: remove third-party apps you don’t use — old quiz apps and dead integrations are standing attack surface.
- Email fortress: the account securing your Facebook is your email. 2FA on it, forwarding rules checked, recovery methods current.
- Phishing immunity: the attack that got you was probably a fake “your Page violated policy” message or a fake login screen. Facebook never asks for your password by DM or email. Bookmark the real login page and use it exclusively.
- For business owners: require 2FA for everyone in Business Settings, keep a second full-control admin, and verify the business — a verified, multi-admin Business Manager survives an individual’s hack.
Frequently asked questions
Can I recover my Facebook account if the hacker changed the email and phone number?
Yes. The facebook.com/hacked flow identifies your account by its old identifiers, the email-change notice sent to your old address contains a reversal link, and ID verification exists as the fallback. Speed matters — start immediately.
What if the hacker enabled two-factor authentication?
Facebook’s recovery flows include alternate verification for unreachable 2FA, typically ID upload plus recognized-device signals. It adds days but is routinely successful.
Facebook keeps sending reset codes to the hacker’s email. How do I stop that?
Stop using “Forgot password” and switch to facebook.com/hacked, which works from old identifiers instead of the current (attacker-controlled) contact points.
The hacker deleted my account. Is it gone?
Deletion requests have a grace window (Facebook has long used a roughly 30-day cancellation period) during which logging back in — or recovering, then logging in — cancels the deletion. After the window and final purge, recovery is generally impossible, which is another argument for acting fast.
Will Meta refund ads the hacker ran on my card?
Verified fraudulent spend is generally refundable through Meta’s billing dispute process. Dispute inside Meta first; bank chargebacks trigger advertising restrictions.
My account was hacked and then disabled by Facebook. Which do I fix first?
Establish the compromise first through the hacked-account flow, then appeal the disable with the compromise documented. Appeals that skip the first step usually fail.
Should I report the hack to police?
For financial loss, extortion, or identity theft, yes — file with local police and (in the US) identitytheft.gov and the FBI’s IC3. It won’t recover the account directly, but it documents the crime for banks, insurers, and disputes.
Is it safe to hire someone to recover a hacked Facebook account?
A legitimate company working through Meta’s real recovery and escalation channels — and never asking for your password — is safe. Anyone claiming they can “hack it back” or requesting crypto payment via Telegram is a scam, and often the same ecosystem that hacked you.
Related guides: Locked out without 2FA · Facebook Business Manager disabled · Recover a disabled Instagram account · or see our full Social Media Recovery service.