Facebook Ad Account Hacked: Damage Control & Recovery
Takeovers are industrialized: compromise, violent 24–72 hour spending spree, burned policy standing. Here's the first hour minute-by-minute, the human doors attackers actually use, the four-front recovery, and the boring hardening list that would have prevented all of it.

First hour, in order: contain → evict → audit → document.
Contain: pause every campaign, pull payment methods. Evict: change admin passwords, log out all sessions, force 2FA. Audit: remove unknown users, stale partners, suspicious apps. Document: screenshot everything before fixing.
Report via Meta’s compromised-account flow (facebook.com/hacked) and dispute fraudulent charges in writing — documented fraud is commonly refunded. The slow damage is policy strikes earned in your name: appeal them as a documented compromise, then run post-breach weeks like a warm-up.
Harden after: 2FA everywhere, least-privilege roles, quarterly partner audits and spend alerts.
- First hour, in order: contain (pause campaigns, pull cards), evict (password, logout-everywhere, 2FA), audit (users, partners, apps), document everything.
- Most breaches enter through people: phishing 'policy' emails, stolen sessions, shared logins, stale agency access.
- Report through Meta's compromised-account flow and dispute fraudulent charges in writing — refunds are common.
- The slowest damage isn't money — it's policy strikes the hacker earned in your name.
- Hardening that works: 2FA on every admin, least-privilege roles, quarterly partner audits, spend alerts.
- Your data layer (pixel, audiences, creative) survives — the account is the casualty, not the business.
- A dedicated rep turns 'ticket in a queue' into 'phone call' — the recovery difference measured in days.
2:14am, someone else's campaign
The discovery is usually banal: a spend notification you don’t recognize, a campaign named in a language you don’t run ads in, a teammate asking why they’ve been logged out.
Inside the account, the pattern is always the same — new campaigns pushing counterfeit goods or crypto pages at maximum budget, a payment method you’ve never seen (declined, usually; yours worked fine), an unfamiliar admin added at 2:14am, and sometimes your own access quietly demoted.
Ad account takeovers are industrialized: automated crews compromise access, spend violently for 24–72 hours, and burn the account’s policy standing on the way out.
Two facts to hold onto while your pulse settles. The money is usually recoverable — Meta refunds documented fraudulent spend more often than not. The slower problem is everything else: strikes and restrictions the hacker earned in your name, trust damage that outlives the eviction, and days of delivery lost mid-quarter. Which is why the response is a checklist, not a mood. Set a timer; the first hour matters.
The first hour, minute by minute

Contain, evict, audit — in that order, with screenshots before every fix.
0–15 minutes — contain the bleeding. Pause every active campaign, including yours (you'll relaunch; right now delivery is the enemy). Remove or freeze payment methods — and if your card is exposed, call the bank's fraud line in parallel. Don't delete the hacker's campaigns yet: they're evidence, and you'll want screenshots with timestamps for the disputes.
15–40 minutes — evict the intruder. Change the password of every account with admin access — the compromise is usually a person’s Facebook login, not “the ad account”.
Then the step everyone skips: log out all sessions (Settings → Security → Where you’re logged in) — a password change without session revocation leaves a hijacked cookie happily authenticated. Turn on two-factor authentication for every admin, app-based or hardware, not SMS if you can help it.
If you can’t get back in at all, go straight to facebook.com/hacked — Meta’s compromised-account flow — before anything else.
Why did changing my password not stop the hacker?
Because stolen session cookies stay authenticated after a password change. You must also log out all sessions (Security settings → Where you’re logged in) — the step that actually evicts a hijacked session.
40–60 minutes — audit and document.
- Business settings → People — remove anyone you don’t recognize, demote anyone who doesn’t need admin.
- Partners — any agency or BM connection you don’t actively use gets cut today.
- Connected apps and integrations — revoke anything unfamiliar; malicious “ads tools” are a real entry vector.
And throughout: screenshot everything before you fix it — the fake campaigns, the added users, the billing entries. Your disputes and appeals will be exactly as strong as your documentation.
How they actually got in
Attackers don't hack Facebook — they borrow a door someone left open.
Notice what’s missing: exotic exploits. Ad account takeovers almost always walk through a human door — the phishing email dressed as a policy violation notice (“Your account will be disabled — appeal here”) remains the workhorse, because it weaponizes the exact anxiety every advertiser carries.
Session theft via browser malware and shady extensions runs second; shared team logins and forgotten agency partner-access fill out the field. The diagnosis matters because the fix does: if you don’t close the door they used, the second visit is a week away.

The classic breach signature: alien campaigns, an unknown admin, a strange card — and your access demoted.
Reporting and the money war
Recovery runs on four clocks at once — start all four the same day.
Work all four fronts the same day:
- Access — the compromised-account flow plus, if you have one, your rep. This is where a partner relationship collapses days into hours.
- Money — dispute the fraudulent charges through billing support in writing, with screenshots and timestamps attached; be factual and specific: “Campaigns X, Y created [time] by unauthorized user [email]; $N spent.”
- Policy fallout — appeal every strike the hacker’s ads earned, explicitly framing them as the product of a documented compromise.
- Cards — replaced same-day via your bank, independent of Meta’s timeline.
Will Meta refund fraudulent ad spend?
Commonly, yes — when the compromise is documented. Dispute through billing support in writing with timestamps and screenshots: which campaigns, created when, by which unauthorized user, spending how much. Precision wins disputes.
The aftermath nobody warns you about
Eviction is the fast part. What lingers: the account’s trust standing took the hit for everything the hacker ran — counterfeit ads, banned categories, violent spend spikes — and Meta’s systems don’t fully distinguish “you” from “whoever controlled your account”.
Expect twitchier review, conservative delivery, and possibly a restriction to appeal even after access returns, per the recovery patterns in our banned-account guide. Run the weeks after a breach like a warm-up: clean creative, gentle spend, batched changes, pristine billing.
The consolation is structural: your data layer survives. Pixel history lives at the business level, custom audiences rebuild from their sources, creative learnings live in your testing log. Worst case — an unrecoverable account — you're rebuilding delivery, not the business.
When it's the whole Business Manager
A worse variant deserves its own paragraphs: the attacker didn’t just enter an ad account — they took the Business Manager, demoted every legitimate admin, and now own the container your pages, pixels and accounts live in.
The playbook shifts: your personal login recovery (facebook.com/hacked) comes first, because BM access hangs off personal identities; then Meta’s business-support path for disputed BM ownership, where business verification documents become your trump card — the registered entity on file outranks whoever holds the stolen session.
This is where having completed verification long before the incident quietly saves the company.
While ownership is disputed, act on the assumption of delay: notify your bank, warn any connected partners (their assets share the container), and stand up interim delivery elsewhere if revenue depends on it. BM disputes resolve on document time, not urgency time — the operators who survive them comfortably are the ones whose ownership paperwork, two-admin structure and partner hygiene were boring and correct months earlier.
Hardening: the boring list that works

Six controls close the doors that matter — none of them cost money, all of them cost discipline.
- 2FA on every admin, no exceptions — one unprotected login is the whole perimeter.
- Least privilege — admin is not the default role; most teammates need Advertiser or Analyst, and the blast radius of a phished Analyst is a fraction of a phished Admin.
- Quarterly partner audits — every agency, freelancer and BM connection reviewed; stale access removed, per the ownership hygiene in our Business Manager guide.
- Phishing literacy as a habit — Meta never asks for your password via email link; every “policy violation — appeal here” email gets verified inside Business Manager, never through the link.
- Spend alerts set aggressively, so a violent spree pages you in minutes.
- Two separated admins — different people, different devices — so one compromised human can’t be a single point of failure in either direction.
The 48-hour communication script
Breaches are also a communications event, and saying the right things early prevents second-order damage:
- Your bank — “unauthorized charges from Meta Platforms on 2026” triggers their fraud protocol independent of Meta’s.
- Your team — a same-day note naming the phishing pattern that likely landed, with the standing rule reaffirmed: no logins through email links, ever. Breaches recur in clusters because the same lure hits every inbox.
- Clients or stakeholders (if you run accounts for others) — proactive, factual, ahead of any spend anomaly they might spot themselves. “Contained, disputed, timeline attached” reads like competence; discovered silence reads like cover-up.
And future-you: a one-page incident note — entry vector, timeline, what the fix cost — filed next to the testing log. Companies that write the note stop repeating the incident; companies that just exhale usually meet the same door again within a year.
The infrastructure difference
Everything above works on any account. What differs is the machinery behind it: on self-serve, a hacked advertiser is a ticket in the same queue as everyone else’s rejected boosted post — days of silence while fraudulent strikes calcify.
Through an agency account relationship, the same breach is a same-day escalation with a named human, documented business standing that makes “this wasn’t us” credible, and — if the account itself is beyond saving — replacement continuity instead of a from-zero rebuild. Security is your job either way; the recovery speed is an infrastructure choice.

The doors are human, the fixes are discipline — and recovery speed is an infrastructure choice.
Frequently asked questions
What do I do first if my Facebook ad account is hacked?+
How do hackers get into ad accounts?+
How do I report a hacked account to Meta?+
My account got restricted because of the hacker's ads — now what?+
Do I lose my pixel and audiences after a hack?+
How do I prevent my ad account from being hacked?+
Should every teammate be an admin in Business Manager?+
Is recovery faster on an agency ad account?+
What if the hacker took over my entire Business Manager?+
When it goes wrong, have a human to call
Managed infrastructure comes with a named rep, same-day escalation and replacement continuity — so a breach costs you a bad morning, not a quarter. Operated on BM2500 infrastructure.