# How to Tell if Your Facebook Account May Be Compromised

> Review unexpected Facebook activity and login alerts, then use Meta’s official security or hacked-account recovery tools for your situation.

- Canonical HTML: [https://www.followersflys.com/blog/how-to-tell-if-your-facebook-has-been-hacked](https://www.followersflys.com/blog/how-to-tell-if-your-facebook-has-been-hacked)
- Language: en
- Published: 2024-08-08T20:45:00+00:00
- Updated: 2026-10-01T00:00:00+00:00

A strange login alert or a post you do not remember making deserves attention, but a single warning sign does not prove that someone has taken over your Facebook account. Check the activity inside Facebook, secure any access you still have, and use Meta's official hacked-account flow if you are locked out. The steps below separate those situations so you can act without relying on an alarming message or a stranger's offer of “support.”

## Check the signs inside your own account

Look for changes you cannot explain: a new contact address, a password that no longer works, posts or messages you did not create, or unfamiliar active sessions. Ask a friend to show you a suspicious message if they say it came from your profile. Keep a record of the date and content if you may need to tell affected contacts what happened.

Meta offers [login alerts](https://www.meta.com/safety/topics/safety-basics/tools/security/) for attempts from devices it does not recognize and a place to review recent sessions. An alert tells you to investigate. It does not, by itself, identify a person or prove that a successful unauthorized sign-in occurred. Open Facebook directly to review account activity rather than following a link in a message that claims to be from support.

A copied profile is a different problem from someone entering your account. Meta's [hacked-account Help Center](https://www.facebook.com/help/1216349518398524/) points to separate help for an imposter account. If your own account is working and someone else created a profile pretending to be you, use Meta's reporting route for impersonation rather than treating the copy as a sign that your password was stolen.

## If you can still sign in, secure the account

### Review where the account is logged in

Open Facebook's current security settings and find the list of logged-in devices. Compare the sessions with devices you actually use. If a session is unfamiliar, use the account control to sign it out. Meta's [Safety Center](https://www.meta.com/safety/topics/safety-basics/tools/security/) describes “Where You're Logged In” and logging out. The position or name of a device may look different across browsers, app versions, and locations, so examine the full context rather than relying on a single label.

If you cannot locate the control in an older tutorial, use the security settings available on your current Facebook account. Do not give someone remote access to your device to find the menu. A security review is worthwhile even if you have not confirmed a takeover, because it lets you see which sessions remain active.

### Change the password and check your contact methods

Choose a new password that you do not reuse for email, another social account, or any other service. Meta's [Safety Center](https://www.meta.com/safety/topics/safety-basics/tools/security/) recommends different passwords for each account and says not to share login details. After the change, review the email addresses and phone numbers attached to your Facebook account. Remove or correct details you do not recognize, if your account gives you that control.

Protect the email account connected to Facebook as well. If you believe that mailbox was accessed, use the email provider's own security and recovery tools. A Facebook password change cannot repair access to another service. Do not assume it automatically closes every Facebook session either; review the session list separately.

### Add two-factor authentication and login alerts

Meta's [account-security Help Center](https://www.facebook.com/help/235353253505947) identifies two-factor authentication and login alerts as available security features. Turn on a two-factor method offered to your account and store its recovery material somewhere private. Enable alerts where offered so a later unfamiliar login attempt is easier to notice.

Two-factor authentication helps protect future sign-ins. It is not a substitute for the official recovery process when you have already lost access, and no security setting can guarantee that an account will never be compromised. Keep any authentication app, security key, or phone number under your own control.

## If you are locked out, use Facebook's recovery flow

Meta's [Recover a Hacked Account](https://www.facebook.com/help/1216349518398524/) page directs people to [facebook.com/hacked](https://www.facebook.com/hacked) and recommends a device they have previously used to log in. Type that address yourself and follow the options shown for your account. The available checks can differ depending on what contact details and account history Meta has.

If your usual password no longer works, avoid repeated guesses on a page reached from an unexpected email or text. Go directly to Facebook's official recovery path. If you no longer control the email address or phone number linked to the account, look for the official options for that situation; do not assume that a generic support email or paid service can override the checks.

The outcome and time required vary. This guide cannot tell whether Meta will restore a particular account, identify the person who accessed it, or submit a recovery request on your behalf. Do not share a recovery code, password, or identity document with this website.

## After you regain access, review the damage

Once you can sign in, revisit logged-in devices and account contact details. Check recent posts and sent messages for activity you did not create. Review any connected Page or other account you manage if it was affected. If suspicious messages went to friends, warn them through a channel they know is yours and ask them to ignore the questionable content. This is practical safety advice; it does not imply that Facebook can retract every message.

Check the email account linked to Facebook, especially if you saw contact-detail changes. Replace any reused passwords on other services with distinct ones. Return to Meta's [Security Checkup and account-security resources](https://www.meta.com/safety/topics/safety-basics/tools/security/) for ongoing review of password, session, two-factor, and alert settings.

Keep evidence of unauthorized changes if you need to explain a scam to a person affected by a message. Do not publish another person's private information while warning contacts. If financial information or a payment account was affected, review it with the relevant provider; this article cannot inspect transactions or resolve payment disputes.

## Questions people ask about a possible Facebook hack

### Does an unfamiliar login location prove someone entered my account?

No. Treat it as a signal to inspect the account, not a definitive diagnosis. Review the device, time, active session, and other unexpected changes in Facebook's security settings. If you remain unsure, securing the account with a unique password and two-factor authentication is a reasonable precaution supported by [Meta's security guidance](https://www.meta.com/safety/topics/safety-basics/tools/security/).

### What if I can no longer use my email or phone number?

Start with [Facebook's official hacked-account recovery](https://www.facebook.com/help/1216349518398524/) and follow the choices offered for your account. You may also need to recover the email address or number with its provider. Neither step guarantees that Facebook will restore access, so avoid anyone who promises a bypass.

### Should I call a number in a recovery message?

Use the recovery pages reached from Meta's own domains. This guide does not provide a phone number, paid recovery service, or a way to skip identity checks. Never read a login code to a stranger who contacts you about your account.
