# What to Do If Your Facebook Messenger Account Is Hacked

> Strange Messenger messages or lost access? Check whether your Facebook account or an impersonator is involved, use Meta's recovery flow, secure sessions, and warn contacts.

- Canonical HTML: [https://www.followersflys.com/blog/what-to-do-when-your-facebook-messenger-account-is-hacked](https://www.followersflys.com/blog/what-to-do-when-your-facebook-messenger-account-is-hacked)
- Language: en
- Published: 2024-11-28T05:24:06+00:00
- Updated: 2026-10-02T00:00:00+00:00

**Start with the account, not the chat.** If unexpected Messenger messages appear to come from your own profile, or you can no longer sign in, open [Meta's Facebook hacked-account recovery page](https://www.facebook.com/hacked) yourself. Meta recommends using a device you have used to log in before. If you can still access the account, change its password, review signed-in devices and contact details, and turn on two-factor authentication. If somebody has made a separate profile that looks like yours, report the impersonator instead. These are different problems, so the first useful step is to check which one you are facing.

An odd message is a warning sign, not proof that an attacker has your password. A friend might be describing a lookalike profile, an old device may still be signed in, or your own account may have been accessed. Do not enter a password into a link from the suspicious conversation to find out. Open Facebook or Messenger directly, and compare what you can actually see in your account with what your contacts received.

## First, find out what happened

Ask a trusted contact to show you the suspicious message or the profile it came from. If it appears in your own sent-message history and you did not send it, treat your account as potentially compromised. If it came from a second profile with your name and picture, that may be impersonation even when your own login still works. Check the profile address or account details rather than assuming a familiar photo proves ownership. Meta has a separate [Messenger impersonation reporting path](https://www.facebook.com/help/messenger-app/1770700349678682/) for a fake account.

Next, check for other changes you did not make: password-reset or login alerts, an unfamiliar email address or phone number, new posts, app connections, or devices shown under your security settings. A login location can be approximate, and a single alert does not identify who accessed an account. The combination of unexplained messages and account changes is enough reason to use Meta's recovery tools promptly.

If the message came from a friend's account rather than yours, do not try to sign into their account or send them a recovery link from the conversation. Reach them through a known phone number or another channel and suggest that **they** open [facebook.com/hacked](https://www.facebook.com/hacked) directly. A person controlling a compromised chat could read or answer messages sent there.

## If you can still sign in to Facebook

Secure the Facebook login connected to your Messenger conversations. Menu names can differ by device and account, so use the security and password options shown in Facebook or its Accounts Center rather than relying on a fixed sequence of taps.

1. **Change the password to a unique one.** Use a password that you do not use for your email or any other site. Do this from Facebook's settings or its [Security Checkup Help](https://www.facebook.com/help/799880743466869/), reached directly after signing in, rather than from a message claiming to be support. Meta advises separate passwords and warns against sharing login details.
2. **Review contact information and recovery methods.** Look for email addresses or phone numbers you did not add. Correct any unauthorized change that the account interface lets you change. If you no longer control a listed contact method, use the hacked-account flow rather than assuming a password change alone has removed someone else's access.
3. **Review where you are logged in.** In Facebook's security settings, look at the recently used devices and sessions. Sign out of sessions you do not recognize, then recheck the list. Meta documents the **Where you're logged in** control as the place to review recently used devices. Device and location information may not establish who used the session.
4. **Turn on two-factor authentication and login alerts.** These add checks for later sign-ins and notify you about attempts from unrecognized devices. They are protections for future access, not a substitute for investigating current changes. Meta's [account-security resources](https://www.meta.com/safety/topics/safety-basics/tools/security/) explain both controls.
5. **Review recent activity and connected apps.** Check messages, posts, account changes, and apps with access for anything you did not authorize. Remove unfamiliar access through the account's own settings. If a suspect app is installed on your device, remove it from the device too; Meta warns that malicious apps can collect login credentials.

If an unfamiliar address, session, or message appears again after these steps, return to the [official hacked-account flow](https://www.facebook.com/hacked). Do not assume the issue is resolved because the Messenger app has been reinstalled, the conversation has been deleted, or app lock is enabled on one phone. Those actions do not address a Facebook login or another session you have not secured.

## If you cannot sign in

Type **facebook.com/hacked** into your browser or open the [official recovery page](https://www.facebook.com/hacked) from a trusted bookmark. Meta advises trying a device you have used for Facebook before. Follow the options shown for your account; they can differ according to which email address, phone number, device, and recovery methods you can still use. If the listed email or phone is no longer yours, continue through Meta's recovery guidance for that situation rather than sending codes to a stranger.

If you receive an account-change or recovery email, verify it through Facebook's own settings or a destination you opened directly before using any link. Meta warns that messages claiming to be from a company can be scams and advises checking the sender rather than clicking a suspicious link. Never give a password, one-time code, or identity document to someone who contacts you through Messenger and promises to restore the account. A third party cannot guarantee a successful Meta recovery, and the steps Meta offers can change.

An account recovery attempt may ask for additional checks or a waiting period. Follow the status and instructions shown by Meta. Repeatedly trying unofficial forms or paying a person who claims they can bypass the process is not a reliable substitute for Meta's own recovery path.

## What if this is a Messenger-only account?

Some people use Messenger through an account setup that does not match the usual Facebook-login instructions. Meta's [Messenger account Help section](https://www.facebook.com/help/messenger-app/165294433944588) lists options to use Messenger without a Facebook account. If that describes your account, use the account-management or recovery options shown for **your** Messenger sign-in. Do not create a new Facebook profile and assume it will regain access to old conversations. We cannot verify which recovery choices will appear for every region and account type.

The same safety rule still applies: open the app or Meta Help yourself, protect the email or phone used for login, and do not share a code in response to a message. If the sign-in method is unclear, first identify the account you normally use before changing unrelated credentials.

## Warn people who received suspicious messages

If your account sent links, requests for money, or requests for codes without your permission, contact the affected people through a channel you already trust. Keep the warning short: say that your Messenger account may have been accessed, identify the approximate time or message, and ask them not to use the link or send money or codes. If a contact clicked a link or entered a password, they should secure **their own** affected account using that service's official recovery tools.

Do not post screenshots that reveal another person's private conversation, recovery code, or contact details. If someone has sent money or shared payment details, they should contact their payment provider using its official channel. You can also ask recipients to use Messenger's report options for a suspicious conversation. This warning helps people avoid a second scam while your account status is being resolved; it does not itself recover the account.

If instead you found a second profile pretending to be you, report that profile using [Meta's Messenger impersonation instructions](https://www.facebook.com/help/messenger-app/1770700349678682/). Tell contacts which account is yours through a separate trusted channel. Securing your real account is still sensible, but a password reset on your real account will not remove a different person's fake profile.

## Check other accounts that could be affected

If you reused the same password for your email or another service, change those passwords through the services' own websites and enable their available sign-in protections. Prioritize the email account linked to Facebook: losing control of that inbox can affect your ability to receive recovery messages. If you entered your password on a page reached from a suspicious message, also check the device for unfamiliar apps and extensions before signing in again. Meta's [security guidance](https://www.meta.com/safety/topics/safety-basics/tools/security/) and its [scam-prevention guidance](https://www.meta.com/safety/topics/safety-basics/tools/avoid/) explain why shared credentials and deceptive links raise risk.

If you manage a Facebook Page or use Facebook Login on another service, review those separately once your personal account is secure. Do not assume every connected account was compromised, but do not ignore unexplained activity in them. Use the affected service's own support route for access problems that Meta's Facebook recovery flow does not cover.

## After access is restored

Review contact details, sessions, two-factor settings, connected apps, messages, and posts again. A completed password reset is one part of the check, not a promise that all unauthorized changes have been reversed. Let affected contacts know when you have regained access so they can distinguish a later genuine message from the earlier suspicious one.

Keep a record of the changes you found and the steps you took without storing passwords or codes in an exposed document. If you notice new unauthorized changes, use [Meta's recovery page](https://www.facebook.com/hacked) again. If the trouble was an impersonator, monitor the report's status through Meta's own interface where available. There is no guaranteed recovery time or universal sequence of screens for every account.
