My Facebook business Page has been hacked

If a business Page has been taken and there is an advertising account attached to it with a card on file, treat this as an active financial compromise and deal with it today. This is not the same as a personal account being taken. In most of these cases the attacker is not interested in your Page at all, they are interested in spending your advertising budget, and they begin within hours. The bill lands in your name.

Last checked: 15 August 2026. Every official Facebook, Instagram and Australian government link on this page was opened and confirmed working on that date. If you find one that no longer works, please tell us and we will fix it, because a dead link on a page like this is worse than no page at all.

Ring your bank now, before you read the rest of this page. If a card is on the advertising account, money is very probably going out this minute. Stopping the card is the one action that ends the spending immediately and does not depend on Meta answering anything. Use the number on the back of the card or in your banking app, never a number from a search result.

Why this is different from a personal account

A personal account is usually stolen to message the person's friends. A business Page is stolen for the advertising account behind it, which is a working payment method that somebody else can point at their own adverts. Spending can run into thousands within a day or two, and because the account is yours, the invoices are yours.

The second difference is better news. Business accounts have a genuine support route with real people, which personal accounts do not.

The official page for this situation:

Open the Meta Business Help Centre

https://www.facebook.com/business/help

The support route for Pages, Business Manager and advertising accounts. Keep any case reference you are given.

Secure the personal account first

This is the step people get the wrong way round. A Page has no password of its own. It is controlled by personal Facebook profiles that hold roles on it, so if an administrator's personal account is still compromised, you can be removed from your own Page again an hour after getting it back.

Recover and secure that personal account first, using the Facebook recovery steps, and only then deal with the Page.

Try this first, on the right device. Start the recovery on a phone, tablet or computer you have logged in from before, using the same internet connection you normally use at home. Facebook and Instagram recognise a device they have seen before, and they will often let you straight back in with far fewer questions. Facebook says this itself at the start of its recovery form: if you can, begin on the device you usually use. Doing the whole thing on a borrowed computer is the single most common reason a recovery stalls.

Check for the access that gets left behind

  • People with Page access you do not recognise, in Page settings. Remove them.
  • Partner businesses added to your Business Manager. This is a favourite route because it survives a password change and almost nobody looks at it.
  • Additional administrators on the Business Manager itself, which is a level above the Page and is easy to forget.
  • Payment methods that are not yours, sometimes added so the attacker can keep spending after you stop your own card.
  • Connected apps and integrations that were granted access while they were in.

Write down what was spent

Before anything gets tidied up, screenshot the advertising charges, the dates and the amounts, and note when you first noticed. Your bank will ask, Meta will ask, and a dispute is far easier with the record captured at the time than reconstructed a fortnight later.

If money has actually gone, ring your bank first. Before the account, before the reporting, before anything on this page. Banks can sometimes stop or recall a payment if they hear about it quickly, and that window is measured in hours. Use the number on the back of your card or in your banking app, never a number from a search result. Then report it to Scamwatch and to ReportCyber, and if you would like a real person to talk it through with, IDCARE is a small business line on 1800 595 170, Monday to Friday, 7am to 7pm AEST.

The people who will offer to help

Business owners are targeted hard here, because the loss is bigger and the panic is sharper. Everything below means walk away.

  • Anyone offering a phone number. There is no Meta support line. A number is the clearest single sign you are being scammed.
  • Paid recovery agents. Services that promise to get your account back for a fee. They have no access Meta does not give you for free, and the usual outcome is that you pay and nothing happens.
  • Anyone who messages you offering to help after you post that you have been hacked, especially on Instagram. Watching for those posts is exactly how they find people.
  • Anyone asking for an upfront fee, a gift card, a voucher or a cryptocurrency payment. No legitimate service is paid this way.
  • Anyone asking for your password or your two factor code. No real Meta process ever asks a person for these. Sharing the code is how the second theft happens.
  • Anyone asking to remote control your computer to fix it for you, unless it is somebody you already know and trust.
  • A friend asking you to receive a code for them. That friend has already been taken over, and the code is for your account.

Related pages on this site

Frequently asked questions

Someone hacked my Facebook Page and is running ads. What do I do first?

Ring your bank and stop the card attached to the advertising account, before anything else. That is the only step that ends the spending immediately and it does not depend on Meta responding. Then secure the personal account the Page hangs off, remove any unknown people and partner businesses from the Page and Business Manager, and report it through the Meta Business Help Centre.

Can I get the advertising money back?

Sometimes, and it is worth pursuing on two fronts at once. Meta does review unauthorised spending on compromised accounts, and your bank may be able to dispute the charges as fraudulent, particularly if you report quickly. Screenshot the charges, the dates and the amounts before anything is cleaned up, and get a report reference from ReportCyber to support the dispute.

Why did they remove me as admin of my own Page?

Because it stops you undoing what they are doing. Page roles are held by personal profiles, so once an attacker controls an administrator's personal account they can demote or remove everyone else. This is exactly why the personal account has to be secured first, otherwise you get your Page back and lose it again the same afternoon. Check every administrator, not only your own account, because one unsecured colleague is enough.

Is there a phone number for Facebook business support?

Not a public one you can find by searching, and any number you do find that way is a scam. Business support runs through the Meta Business Help Centre, which is a real route with real people, unlike personal accounts. Start there from a page you reached yourself at facebook.com, rather than from a search result or an advertisement. Numbers advertised as Meta business support are placed there to catch worried business owners.

How did they get in?

Usually through an administrator's personal account, by way of a reused password or a convincing fake message about a policy violation or a copyright complaint. Those messages are designed for exactly this, because they frighten a business owner into logging in through a link. Check every administrator's personal account, not just your own, before you consider it closed. Ask each of them directly whether they clicked anything unusual recently, rather than assuming they would have mentioned it.