A hacked Facebook account is frightening because the hacker usually moves fast: changes your password, swaps the email, then messages your friends asking for money or posts things that damage your reputation. Speed matters. Here is the exact order to work in.
Step 1 — Try the normal reset first (2 minutes)
Go to facebook.com/login/identify, enter your phone number or email, and request a code. If the hacker has not yet changed your contact details, you are back in within minutes. Change the password immediately and skip to the "lock it down" section.
Step 2 — If your email or phone was changed
Facebook sends a security email to your old address the moment contact details change. Search your inbox (and spam) for "Facebook" — the email contains a link that says "If you didn't do this, let us know" or "secure your account". That link reverts the change even after the hacker has taken over. This works for about 48 hours after the change, so do it today.
Step 3 — Use the hacked-account tool
Go to facebook.com/hacked. Choose "Someone else got into my account", then follow the prompts. Facebook will ask you to identify friends in photos, provide an old password, or upload an ID. Use a device and network you have logged in from before — Facebook trusts your usual phone and home Wi-Fi more than a friend's laptop.
Step 4 — Report from a friend's account if all else fails
Ask a friend to open your profile → the three dots → Find support or report → "Something else" → "Recover this account". A report from an established account is taken seriously and often unlocks the ID-verification route.
Step 5 — Warn your friends immediately
While you work on recovery, post on WhatsApp or ask a friend to post publicly: "Nishnath's Facebook is hacked — do not send money or click links from it." In Sri Lanka the most common scam after a hack is a message asking for a "quick Rs. 5,000 reload" or an eZ Cash transfer. A warning stops that dead.
Lock it down so it never happens again
- Two-factor authentication — Settings → Security and login → Two-factor authentication. Use an authenticator app (Google Authenticator or Microsoft Authenticator), not SMS. SIM-swap attacks on Dialog and Mobitel numbers are real.
- Unique password — the hack almost always came from a password you also used on some other site that got breached. Use a password manager (Bitwarden is free) and a different password everywhere.
- Check active sessions — Security and login → "Where you're logged in" → log out of everything you do not recognise.
- Review connected apps — Settings → Apps and websites. Remove quizzes and games; many "which celebrity are you" apps exist purely to harvest access.
- Set up trusted contacts / recovery codes — download the backup codes and keep them somewhere safe. They get you in even if your phone is lost.
How they got in (so you recognise it next time)
Almost every hacked account I have helped recover fell to one of three things: a fake "Your page violated community standards, verify here" message, a login page that looked like Facebook but was not, or a reused password from an old leaked database. None of them were sophisticated. Slow down before clicking anything that asks you to log in "urgently".
If you have been locked out for days and the tools above keep looping, I can walk you through the ID-verification path over WhatsApp — it is part of my IT support service.
Need help with this?
I do this for a living — for businesses in Sri Lanka and clients worldwide. Tell me what you are dealing with.
Comments (0)
// no comments yet — start the conversation
Leave a comment
Comments appear after moderation.