Facebook Ad Account Hacked? Emergency Steps

Your Facebook ad account is hacked and burning budget? Halt the rogue spend, evict unauthorized admins, recover via facebook.com/hacked, and dispute the charges.

Updated May 2027 · Likit Sae Lee, CTO

Facebook Ad Account Hacked? Emergency Steps
Quick answer

If your Facebook ad account is hacked and burning budget, work in order: pause every active campaign and cap the account spending limit if you still have access, revoke any admins and partners you do not recognize in Meta Business settings, then recover the account at facebook.com/hacked. Report the fraudulent charges to Meta before you call your bank, since a surprise chargeback can get the account restricted, then lock everything down with two-factor authentication and login alerts. This is an attacker takeover, not a Meta-initiated disable, so the job is to eject the intruder and secure access, not to appeal a policy decision. Speed matters: US consumers reported losing $794 million to scams that began on Facebook in 2025, and a hijacked ad account can drain a card in a single weekend.

You open Ads Manager and the numbers are wrong: campaigns you never built, a spend graph climbing while you slept, an admin you do not recognize sitting in your business settings. A hijacked ad account can empty a card in hours, and every minute it stays open costs money. This is a rescue operation with a clear order of moves: stop the bleeding first, evict the attacker second, recover access third, then claw back the charges and lock the door behind you.

Hacked or disabled? Diagnose it before you touch anything

Two very different disasters both end with your ads stopping and your stomach dropping, and the fastest way to waste the hours that matter is to treat one like the other. A hack is an outside intruder in your account. A disable is Meta itself pulling the plug. The signals are distinct, and so are the fixes.

A takeover shows itself in activity you did not create. Campaigns appear that you never built, often promoting sketchy products, crypto, or counterfeit goods in a language you do not sell in. The spend graph climbs overnight. A new admin sits in your business settings. Your login email or phone number quietly changed. You get a login-alert email from a city you have never visited. None of that comes with an official Meta notice, because Meta did not do it: a person did.

A Meta-initiated disable looks the opposite. There is a notice. Your Account Quality dashboard flags a specific policy, a red banner explains that the account is restricted or disabled, and there is usually an appeal or request-review button. Meta acted deliberately, told you why, and gave you a path to contest it.

SignalHacked (attacker takeover)Disabled (Meta-initiated)
Who actedAn outside intruderMeta's enforcement system
How you find outStrange activity, a login alert, a drained cardAn official notice and an Account Quality flag
What changedNew admins, unfamiliar campaigns, altered email or paymentAds stopped, a policy reason, an appeal button
The right first moveSecure access and evict the intruderRead the violation and appeal it
The wrong moveWaiting to appeal (there is nothing to appeal)Resetting passwords and assuming a hack

The reason to slot yourself into the right column before acting is that the emergency below is written for the left one. The scale of that column is sobering. US consumers reported losing $2.1 billion to social media scams in 2025, an eightfold jump since 2020, and more of that money vanished into scams that began on Facebook than on any other platform, $794 million in a single year, according to the US Federal Trade Commission. Nearly 30% of everyone who reported a scam loss said it started on social media. Meta estimates that roughly 4% of its more than three billion monthly users are fake accounts, the ecosystem the takeovers feed. Business ad accounts are prized because they come with a saved payment method and a spending history that lets fraud run before anyone reacts. If your column is the left one, keep reading. If it is the right one, the fix for a disabled ad account is an appeal, not a password reset.

It also helps to know how you likely got here, because the entry point tells you what to double-check during cleanup. Most business-account takeovers do not start with a genius breaking encryption. They start with a message. A common play is a fake policy warning, an email or Business Suite notice claiming your Page violated a rule and will be removed unless you verify within 24 hours, linking to a login page that harvests your password. Others arrive as a malicious file from a supposed brand-deal partner, or a fake copyright complaint. Because these can spoof or ride legitimate-looking Meta domains, the urgency and the login prompt are the tells, not the sender name. If any of that rings a bell, assume the credentials you entered are burned and reset every account that shared that password, not just Facebook.

The first five minutes: pause spend and cap the account

If you still have access, your first job is not to investigate. It is to stop the money. Every minute the attacker's campaigns run, they bill your card, and you can reconstruct what happened later. Triage first, forensics second.

Start at the campaign level in Ads Manager and turn everything off. Select all active campaigns and toggle them off in one move rather than opening them one by one. The attacker may have built several, sometimes with innocuous names to blend in, so a blanket pause is safer than a targeted one. But pausing campaigns is only half the seal, because an intruder who still has access can simply switch them back on or spin up new ones while you are removing them.

The stronger circuit breaker is the account spending limit. This is a single hard cap on the whole ad account: once total spend since you set it reaches the limit, Meta stops delivering every ad in the account, regardless of how many campaigns exist or who created them. Set it to a token amount, a few dollars, and you have throttled the entire account with one setting instead of chasing individual campaigns an attacker can recreate faster than you can pause them.

Then deal with the payment method. If you can, remove the compromised card or, if an outstanding balance blocks removal, at least know that the spending limit is already holding the line. A worked example shows why the order matters. Say the intruder duplicates your setup into four campaigns at a $250 daily budget each. That is $1,000 a day, and because Meta can pace a daily budget up to 25% over on a high-opportunity day, a single day can bill closer to $1,250. Left running from Friday night until you notice on Monday, that is roughly $3,750 gone. An account spending limit of $50 would have capped the damage at $50 no matter how many campaigns were built. Hunting down four campaigns takes minutes you may not have; setting one limit takes seconds.

Evict the intruder: revoke rogue admins and partners

With spend capped, the attacker is still inside. Now you lock them out. Access to a business account hides in three places, and you have to check all of them, because removing a rogue admin from one list while leaving their partner link or API token intact just leaves a second door open.

Open Meta Business settings and work through them in turn. Under People, look for any individual you do not recognize, and pay closest attention to anyone holding an admin or full-control role, since that is the access an attacker wants. Under Partners, check for any business or agency you did not add, because a partner link grants another organization standing access to your assets. Under System Users, look for automated accounts and access tokens, the kind of API access that can keep running quietly long after a human login is cut off. Remove anything unfamiliar from each list.

Two practical warnings. First, you need an equal or higher role to remove someone, so if the intruder made themselves an admin, you have to still be an admin yourself to eject them; if they demoted or removed you, jump to the recovery section below. Second, removal is permanent and there is no undo, so confirm each person is genuinely an intruder and not a teammate or contractor before you click.

Removing their access is not the same as ending their session. Change your password to a strong, unique one immediately, then use the security setting that shows where you are logged in and log out of every active session. That kills any live login the attacker is holding, so a stolen cookie or an open tab cannot walk straight back in. If your account email or recovery phone was changed, reset those too, and secure the email inbox itself with its own new password and 2FA, because an inbox the attacker controls lets them reset everything you just fixed.

While you are in the settings, check the assets themselves, not just the people list. Confirm your Pages still show you as the owner and that no new Page was added to the portfolio to launder ad spend. Look at the connected payment methods for any card or PayPal that is not yours, since attackers sometimes attach their own funding source to keep spending after your card fails, and detach anything unfamiliar. Review any pixels or datasets for unexpected sharing, because access to a pixel lets an intruder run conversion campaigns on your reputation. Ten minutes spent auditing the assets closes the side doors that a password reset alone leaves wide open.

Locked out? Recover through facebook.com/hacked and Business Support

Sometimes the attacker moves faster than you and you cannot get in at all, or they demoted you out of your own business. This is what the recovery flows are built for.

Go to facebook.com/hacked. Meta's dedicated flow walks you through securing the account: it helps you reset the password, reviews recent login activity so you can spot the intrusion, and steps you through reversing the changes an attacker commonly makes. If the standard route fails, Meta's Account Recovery Hub covers Facebook, Instagram, and Threads and offers alternative identity-based recovery when you no longer have the usual login details. Be ready to verify who you are; Meta may ask for identity confirmation before it hands access back, which is friction that also protects you from someone else claiming your account.

Recover in the right sequence. Secure your email account before anything else, because password resets flow through your inbox, and an attacker who still controls it can quietly undo each fix as you make it. Once the email is yours again, reset the Facebook password, log out of all sessions, and re-check the People, Partners, and System Users lists, since an intruder often re-adds themselves during a scramble.

A personal profile and a business portfolio recover differently. If the compromise reached a business portfolio, with its Pages, ad accounts, and pixels, use Meta Business Support to open a case rather than relying on the personal-profile flow alone. Business assets carry a separate, often slower recovery track, so start it early and keep every reference number and email in one place, because a takeover case can involve several rounds of back-and-forth before access is fully restored.

Dispute the fraudulent charges without getting your account frozen

Once access is yours and the spend is stopped, attention turns to the money already taken. Here the intuitive move, calling your bank to reverse the charges, is the one that can cost you the account, so slow down and do it in the right order.

Report the unauthorized charges to Meta first. Meta provides a process for reporting an unrecognized charge on your bank statement, and running the dispute through Meta keeps your ad account in good standing while it is reviewed. Before you file, assemble your evidence: a screenshot of the bank or card statement showing the date, amount, and the Meta or Facebook billing descriptor, a short factual summary of what happened, and any supporting Meta emails, such as login alerts or new-campaign notifications, that show the activity was not yours. Clean evidence gathered up front turns a slow dispute into a faster one.

Understand the chargeback trap before you reach for it. When you dispute a charge directly with your bank, the bank claws the money back from Meta, and Meta can treat that as a payment-terms violation and restrict or disable the ad account in response. For a business that lives on Meta ads, losing the account can hurt more than the fraudulent spend did. So use Meta's own dispute channel as the front door and keep the bank chargeback as a genuine last resort, after Meta's process has stalled.

There is one clear exception. If the card number itself was stolen and is being charged beyond Meta, that is straightforward payment fraud, and you should contact your bank to freeze and replace the card no matter what. The distinction is whether the problem is confined to your Meta account (report to Meta first) or your card is loose in the wild (call the bank). When in doubt, replacing a compromised card is cheap insurance against the next surprise charge.

Harden the account so the door stays shut

Recovery buys you back the account. Hardening keeps it. Most takeovers are not sophisticated break-ins; they are a reused password, a convincing phishing message, or an admin role handed out and forgotten. Close those gaps and you remove the openings attackers actually use.

Two-factor authentication is the single highest-leverage step. Microsoft's research found that multi-factor authentication blocks over 99.9% of automated account-compromise attacks, the password-spray attempts that make up the bulk of the threat. In a business portfolio you can go further than enabling it on your own login: Meta lets you require two-factor authentication for the whole portfolio, with enforcement set to no one, admins only, or everyone. Set it to everyone. A single teammate without 2FA is the weak link the whole team gets breached through.

Then layer the rest:

  • Turn on login alerts. Meta can notify you the moment your account is accessed from a device or browser it does not recognize, which turns a silent takeover into an alert you can act on in minutes.
  • Apply least privilege. Give each person the lowest role that lets them do their job, and keep the number of admins as small as possible. Because Meta Business Manager roles carry different powers, an editor cannot add new partners or change billing while an admin can. Fewer admins means fewer keys to the account.
  • Prune access on a schedule. Remove ex-employees and former agencies the day they leave, and review your People, Partners, and System Users lists quarterly. Stale access is a standing invitation, and old API tokens are the quietest way in.
  • Separate personal and business assets. Do not run a business portfolio off a single personal login that also holds admin over everything. If that one profile is phished, the attacker inherits the lot. Compartmentalize so a breach of one asset does not cascade into all of them.
  • Use strong, unique passwords and a password manager. Reused passwords are how one leaked breach becomes a Facebook takeover. A unique password per service, stored in a manager, kills credential-stuffing outright.

None of these is exotic, and that is the point. The attackers rely on the boring gaps being left open. 2FA is not a force field against a targeted phishing attack that tricks you into approving a login yourself, which is exactly how many business accounts fall, so pair it with alerts and a habit of distrusting any message that pushes you to log in or verify urgently.

Your recovery timeline, in order

Under pressure, sequence beats effort. Doing the right things in the wrong order, disputing charges before capping spend, or resetting your Facebook password before securing your email, can undo the work as fast as you do it. Here is the whole rescue as one ordered checklist.

WhenDo this
Minutes 0-5Pause all active campaigns and set a low account spending limit as a hard cap
Minutes 5-15Remove unfamiliar people, partners, and system users; change your password; log out of all sessions
Minutes 15-30Secure your email inbox with a new password and 2FA; if locked out, start facebook.com/hacked or Business Support
Same dayGather charge evidence and report the fraudulent spend to Meta; freeze the card only if it is being used beyond Meta
This weekRequire 2FA for everyone, enable login alerts, trim admin roles, and audit all access

Work top to bottom. If you get stuck on a step, the ones above it have already limited the damage, which is the whole reason spend capping and access removal come before everything else.

Staying secure after the fire is out

The days after a takeover are when good habits stick, because the fear is fresh. Use them. Watch your Account Quality dashboard and billing for a couple of weeks, since re-compromise attempts are common when an attacker knows the account was worth taking once. Confirm that the payment method, business email, and admin list all still show only what you expect, and re-check them if anything feels off.

Build a small recovery kit while it is on your mind. Keep a second trusted admin so one locked-out account never means a locked-out business. Save your 2FA backup codes somewhere offline. Note down the Meta support case reference and the email addresses tied to the account, so next time you are not reconstructing basics mid-crisis. A takeover is far cheaper to survive the second time when the first one taught you where your gaps were.

The reassuring part is that almost everything an attacker does to a business account is reversible if you move in order and move fast. Stop the spend, evict the intruder, recover the access, dispute the charges through Meta, and shut the door with 2FA and alerts. Do that, and a bad morning becomes a story you tell new hires about why everyone turns on two-factor authentication before they ever run a Facebook ad, rather than the week your business ground to a halt.

By the numbers

$2.1 billion
US consumer losses to social media scams in 2025
FTC, 2025
$794 million
Losses to scams that began on Facebook in 2025
FTC, 2025
Nearly 30%
Scam-loss reports that started on social media
FTC, 2025
8x
Growth in social media scam losses since 2020
FTC, 2026
Over 99.9%
Automated account-compromise attacks blocked by MFA
Microsoft, 2019
~4%
Share of Facebook monthly active users that are fake
Meta, 2025

Frequently asked questions

My Facebook ad account is hacked and spending money. What do I do first?

Move in this order while you still have access. Pause every active campaign, then set a low account spending limit (for example a few dollars) as a hard circuit breaker that caps the whole account no matter how many campaigns the attacker created. Next, open Meta Business settings and remove any people, partners, or system users you do not recognize, starting with anyone holding an admin or full-control role. Only then work on recovery and disputing charges. Capping spend first matters because a hijacked account can bill thousands over a weekend before anyone notices.

How do I remove an unauthorized admin from my Facebook Business account?

Go to Meta Business settings, open the People section, and check Partners and System Users too, because access can hide in any of the three. Select the unfamiliar user and remove them. You need an equal or higher role to remove someone, so if the attacker gave themselves admin you must still be an admin to eject them. After removing access, change your password and log out of all active sessions so their current login dies. Removal is permanent and there is no undo, so confirm you are removing the intruder and not a legitimate teammate.

Can I get a refund for unauthorized Facebook ad charges?

Often yes, but report the charges to Meta first rather than going straight to your bank. Meta has a form for reporting an unrecognized charge on your bank statement, and running the dispute through Meta keeps your ad account in good standing. Gather evidence before you file: a screenshot of the charge showing the date, amount, and billing descriptor, plus any Meta emails about suspicious logins or new campaigns. If your card number itself was stolen and used elsewhere, that is card fraud and belongs with your bank.

How is a hacked ad account different from a disabled one?

They are opposite problems with opposite fixes. A hack is an outside intruder taking over your account, shown by unfamiliar campaigns, new admins, changed email or payment details, and logins from places you have never been. A disable is Meta itself stopping your account for a policy or payment issue, shown by an official notice, an Account Quality flag, and usually an appeal or request-review button. If you were hacked, you secure access and evict the attacker. If you were disabled, you read the stated violation and appeal it. Treating one like the other wastes the hours that matter most.

What if the hacker locked me out or made themselves the only admin?

Start at facebook.com/hacked, which walks you through securing the account, resetting the password, and reviewing recent logins, and use Meta's Account Recovery Hub if you cannot get in the normal way. Secure your email account first, because an attacker who controls your inbox can undo every password reset you attempt. If a whole business portfolio was taken over, use Meta Business Support to open a case, since business assets have a separate recovery path from a personal profile. Have your identity verification ready, as Meta may ask you to confirm who you are.

Should I dispute the charge with my bank or with Meta?

Report it to Meta first. A chargeback filed directly with your bank can be read as a payment-terms violation and get the ad account restricted or disabled, which is a painful outcome for a business that runs on Meta ads. Use Meta's unrecognized-charge process as the first channel and keep the bank as a backstop. The exception is genuine card theft: if the stolen card is being used beyond Meta, contact your bank to freeze and replace the card regardless.

How do I stop this from happening again?

Turn on two-factor authentication and require it for everyone in your business portfolio, not just admins. Enable login alerts so you hear about a new-device sign-in immediately. Apply least privilege: give people the lowest role that lets them do their job, keep the number of admins tiny, and remove ex-employees and former agencies the day they leave. Separate personal and business assets so a compromise of one does not hand over the other, and audit your People, Partners, and System Users list on a schedule.

Does two-factor authentication really stop account takeovers?

It stops the vast majority. Microsoft's research found that multi-factor authentication blocks over 99.9% of automated account-compromise attacks, the kind that spray stolen passwords across millions of accounts. It is not a force field against a targeted phishing attack that tricks you into approving a login or handing over a code, which is how many business accounts fall. So pair 2FA with login alerts, a password manager, and healthy suspicion of any message asking you to log in or verify, and you close most of the door the attackers use.

Sources

Keep exploring

Turn ad research into winning ads

Research the ads that work, generate the creative on-brand, and launch to Meta, all in one tool.

7-day free trial · No credit card required