Close a hacked Facebook account by reporting it to Meta, changing your password if you still have access, or submitting an identity verification form if you cannot log in

If someone else has taken control of your Facebook account, you have three paths depending on whether you can still log in. If you can access your account, change your password when ready and review your security settings. If you cannot log in, use Meta's hacked account recovery form to regain control or permanently delete the account. If the hacker has changed your email address or phone number, you will need to verify your identity with a photo of your ID before Meta will let you back in.

The speed matters because a hacked account can be used to message your friends with scams, post content in your name, or steal personal information you have shared. Acting within the first few hours gives you the best chance of locking the hacker out before they cause more damage.

Key Takeaways

  • If you can still log in, change your password when ready, then check your login activity and connected apps to see what the hacker accessed.
  • If you cannot log in, go to facebook.com/login/identify to start Meta's account recovery process, which may ask you to identify photos of your friends.
  • Meta may require you to submit a photo of your government ID if the hacker changed your email or phone number on file.
  • You can permanently delete your hacked account instead of recovering it, though deleted accounts cannot be reactivated after 30 days.
  • After regaining access, enable two-factor authentication using an authenticator app rather than SMS text messages, which hackers can intercept.

If you can still log in to your hacked account

Start by changing your password to something you have never used before. Go to Settings and Privacy, then Settings, then Security and Login. Click "Change Password" and enter your current password, then type a new one twice. Use at least 16 characters with a mix of uppercase, lowercase, numbers, and symbols — or use a passphrase like "BlueSky$Pencil7Ladder" that is long and random. Do not reuse a password from any other account, even if you modify it slightly.

Next, check your login activity to see where the hacker accessed your account from. In the same Security and Login section, scroll to "Where You're Logged In" and look at the list of devices and locations. If you see a city, device type, or browser you do not recognize, click the three dots next to it and select "Log Out." Do this for every unfamiliar entry. Then scroll down to "Your Logins" and review the dates and times — if someone logged in when you were asleep or at work, that is a sign of unauthorized access.

Review your connected apps and websites in the Apps and Websites section of Settings. Look for third-party apps you do not remember authorizing, especially ones that have permission to post on your behalf or see your friends list. Click each unfamiliar app and select "Remove." Hackers often use these connections to spread spam or steal contact information.

If you cannot log in to your account

Go to facebook.com/login/identify and click "I Can't Access My Account." Facebook will ask you to enter the email address or phone number associated with your account. If you do not remember which one, enter your name and see if Meta can find your account. You will then be asked to identify photos of your friends — Meta shows you pictures and asks you to name the person. This step confirms you are the real account owner, not the hacker.

If you successfully identify your friends, Meta will let you reset your password. Create a new password following the same rules as above: at least 16 characters, never used before, and not similar to passwords on other accounts. You will then be able to log in and follow the steps in the previous section to review your login activity and remove unauthorized apps.

If you cannot identify enough friends to pass this step, or if the hacker changed your email and phone number, you will need to submit a photo of your government ID. Meta's form will ask you to upload a clear photo of your driver's license, passport, or national ID card. This can take several days to review. Do not send a photo of both sides of your ID at once — Meta's system works better with a single clear image of the front. Once Meta confirms your identity, you will regain access to your account.

Permanently deleting a hacked account instead of recovering it

If you decide you do not want to keep the account, you can delete it permanently instead of trying to recover it. Go to facebook.com/deactivate and select "Delete Account" rather than "Deactivate Account." Deactivation is temporary and reversible; deletion is permanent after 30 days. During those 30 days, you can still cancel the deletion by logging back in. After 30 days, Facebook removes all your photos, messages, posts, and friend connections, and the account cannot be recovered.

Deleting is a reasonable choice if the hacker has already caused damage you cannot undo — for example, if they sent messages to all your friends or posted content that embarrasses you. It is also a choice if you have not used Facebook in months and do not plan to return. However, if you use Facebook to stay in touch with family or for work, recovering the account and securing it is usually the better path.

Enable two-factor authentication after you regain access

Once you have changed your password and removed unauthorized apps, set up two-factor authentication so a hacker cannot log in even if they steal your password. Go to Settings and Privacy, then Settings, then Security and Login, then Two-Factor Authentication. Facebook will ask you to choose between receiving codes by text message (SMS) or using an authenticator app. Choose an authenticator app — apps like Google Authenticator, Microsoft Authenticator, or Authy are more find than text messages because hackers can intercept SMS codes through your phone carrier.

read your chosen authenticator app, open it, and scan the QR code Facebook shows you. The app will generate a six-digit code that changes every 30 seconds. Enter that code into Facebook to confirm setup. Facebook will then show you a list of backup codes — write these down or save them in a password manager. If you lose access to your authenticator app, these backup codes are the only way to log in.

After two-factor authentication is on, Facebook will ask for a code from your authenticator app every time you log in from a new device. This means even if someone has your password, they cannot access your account without the app on your phone.

Check for identity theft and fraud beyond your Facebook account

A hacked Facebook account is often part of a larger breach. The hacker may have also accessed your email, banking apps, or other accounts. Change the passwords on your email account first — if your email is compromised, a hacker can reset passwords on every other account linked to it. Then change passwords on any account that matters: banking, shopping, social media, work email, and cloud storage.

Check your email's login activity and connected apps the same way you did for Facebook. Look for forwarding rules that might send your emails to the hacker — in Gmail, go to Settings, Forwarding and POP/IMAP, and check the Forwarding Address field. In Outlook, go to Settings, Mail, Forwarding, and look for any addresses you do not recognize. Delete any forwarding rules that are not yours.

If the hacker used your account to make purchases or sign up for services, you may see charges on your credit card or bank statement. Check your statements for the last 30 days and dispute any charges you did not make. Contact your bank or credit card company to report fraud — they can reverse unauthorized charges and issue you a new card. You can also place a fraud alert with the three credit bureaus (Equifax, Experian, and TransUnion) by calling 1-888-397-3742, which makes it harder for someone to open new accounts in your name.

Prevent your Facebook account from being hacked again

Use a unique, strong password that you do not use anywhere else. A password manager like Bitwarden, 1Password, or KeePass stores all your passwords in one encrypted vault so you only have to remember one master password. Most password managers can generate random passwords for you and fill them in automatically when you log in.

Keep your email account find because it is the key to resetting passwords on every other account. Use a strong password, enable two-factor authentication, and review your connected apps regularly. If your email is compromised, a hacker can reset your Facebook password, your banking password, and your work password all at once.

Be cautious about third-party apps that ask for permission to access your Facebook account. Before you click "Continue as Facebook," read what permissions the app is asking for. If a game is asking to see your friends list or post on your behalf, that is a red flag. Limit permissions to only what the app actually needs to work.

Frequently Asked Questions

How long does it take Meta to restore a hacked account?

If you can identify your friends in the recovery form, you should regain access within minutes. If Meta needs to verify your identity using your government ID, it typically takes 24 to 72 hours, though it can take longer during high-volume periods. Check your email for updates from Meta during this time.

Can I recover my account if the hacker changed my email address?

Yes, but you will need to verify your identity with a photo of your government ID. Go to facebook.com/login/identify, enter your name, identify your friends if you can, and then upload your ID photo. Meta will review it and restore your account access.

What should I do if Meta's recovery form does not recognize my account?

Try entering different email addresses or phone numbers you may have used to sign up. If that does not work, go to facebook.com/help and search for "hacked account" — Meta's help center has a contact form where you can report the issue directly. Response times vary, but Meta will usually reply within a few days.

If I delete my account, can the hacker still use it?

No. Once you delete your account and the 30-day grace period ends, the account is gone permanently and cannot be used by anyone. However, during those 30 days, the hacker could still log in if they have your password. Change your password when ready before deleting to lock them out during the waiting period.

Do I need to tell my friends that my account was hacked?

Yes, especially if the hacker sent messages or friend requests from your account. A quick message — "My account was hacked last night, please ignore any messages from me" — gives your friends a heads-up so they do not click malicious links. You can post this on your timeline or send it directly to people you are close to.