Start your 3-day free trial
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.


If you are searching for how to tell if your Facebook was hacked, remember this first: the most dangerous case is not suddenly being locked out. It is someone taking control while you still assume Facebook is just glitching. The first things to check are login alerts, profile changes, unfamiliar devices, strange messages, and security settings that were changed without you.[1][2][3][4]
Put simply: if you see a change you did not make, do not start by blaming a bug. Treat it as a possible account takeover.
Use the digital privacy guide as the wider checklist: it connects this issue to accounts, devices, identifiers, and data-broker exposure.
Key Takeaways
- Being locked out is only the most obvious sign, not the only sign.[1][3]
- If your email, phone number, password, or profile photo changed, the attacker may be trying to remove your control.[1][5]
- The most useful check is
Where you're logged in, where you can review devices and locations.[2][3]- Log out unfamiliar devices, change your password, enable MFA, and warn contacts before repeatedly trying random login attempts.[1][2][6]
- Email is often the start of account recovery, so check your email security too.[5][6]
This is the classic sign. If you know your password but cannot get in, do not assume you remembered it wrong. Meta notes that attackers may quickly change the email, phone number, or password and lock you out.[1]
Password reset emails, login codes, and unfamiliar login alerts that you did not trigger should raise the risk level immediately. They mean someone may already be testing your recovery or verification path.[3][4]
Profile photo, name, bio, linked email, phone number, and two-factor settings all matter. If any changed without you, do not ignore it. These changes often make it harder for you to recover the account.[1][5]
Unknown Messenger messages often mean the account is being used to scam your contacts. Common messages ask for money, send event links, request codes, or push people toward phishing pages.
If you are also trying to spot fake-looking login pages, see How to recognize and prevent phishing attacks.
Hacked accounts are often used for spam posts, investment scams, fake donation links, or suspicious ads. The longer it goes unnoticed, the more likely contacts are to trust the posts because they seem to come from you.
This is one of the strongest checks. Meta’s Where you're logged in and recent login pages show device type, time, and approximate location. If you see a device you do not recognize, act.[2][3]
Many people find out because a friend asks, “Did you mean to send this link?” If more than one contact reports it, it is probably not a misclick.
Some takeovers are not just about spam. If your Facebook is connected to Instagram, Meta Business, a payment method, or an ad account, the attacker may try to expand the damage through those links.
Meta’s high-value step is to open Accounts Center, then Password and security, and review Where you're logged in. Look for:
Review linked email, phone number, password update time, and two-factor settings. If the recovery path was changed, you have moved from “something odd happened” to account takeover.
Sometimes the “Facebook security alert” itself is a phishing email. Do not click its link directly. Open Facebook yourself or use the official recovery page.[1][5]
Meta recommends facebook.com/hacked. If possible, use a device you have used to log in before; it often helps the recovery flow.[1]
Remove all sessions you do not recognize from the login activity page. Changing the password without clearing sessions is often not enough.[2]
If that password was reused on email, social platforms, or other sites, change those too. The FTC warns that hacked accounts often lead attackers to try your other accounts as well.[5]
MFA is not magic, but it makes “password equals access” much harder. CISA recommends enabling MFA for email, social media, and financial accounts.[6]
This stops the spread. Many second-order losses happen when friends trust a strange link because it appears to come from you.
Facebook recovery often ends at your email account. If the attacker controls your email first, they may keep beating you to every recovery step.
That is why your email should be treated like a master key. If you are unsure whether it is exposed, read How to protect your email: 7 settings that matter more than changing addresses.
These steps are not flashy, but they stop many common account takeovers.
Many people frame the issue as “Facebook is broken.” The real danger is:
So when you suspect a takeover, check recovery paths before repeatedly trying passwords.
No. Some attackers stay quiet at first, sending messages, viewing contacts, or preparing to change security settings.[1][3]
Yes if it was not you. If the device, location, or time looks wrong, check session records immediately.[3][4]
It may. Strange chat history often means someone controlled the account at least briefly.
Not always. If unfamiliar sessions remain active, your email is compromised, or MFA is off, risk remains.[2][5][6]
Password reset, alerts, and account recovery often depend on email. If email is compromised, social accounts are much harder to recover.[5][6]
Yes. Even after changing the password, MFA raises the barrier against another takeover.[6]
Disclaimer
This article is for general digital-safety education only. It does not guarantee platform appeal outcomes, legal remedies, or account recovery. Actual results vary by account status, linked information, and region settings.
This guide comes from AethoVPN; VPN routing does not carry out the checks required for how to tell if your Facebook was hacked.
Sources
Sources checked 8 May 2026.
Related Articles:
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.